Elektrine lite

← Feed

Bastian Buck

bstnbuck@infosec.exchange

<p>IT-Security Consultant - Malware Analyst - Network Security</p>

Posts

  • View post

    A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; #CVE-2026-63030), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing… If you haven&#39;t already, update your Wordpress (preferably yesterday…) and also enable automatic updates for themes and plug-ins! I found several PHP backdoors/webshells (see @abuse_ch@ioc.exchange Malware Bazaar...