Sucuri Blog Learn about website security, software vulnerabilities, how to protect WordPress, and malware infections from our team of security researchers.
- Malvertising Campaign Hides in Plain Sight on WordPress Websitesby Puja Srivastava on October 4, 2025 at 1:37 am
Recently, one of our customers noticed suspicious JavaScript loading across their WordPress website. Visitors were being served third-party scripts that the site owner never installed. After investigation, we discovered the infection originated from a malicious modification in the active themeās functions.php file. This injected PHP code silently fetched external JavaScript from attacker-controlled domains and inserted it into the siteās front-end. Behind the Breach We found a suspicious script loading on the clientās website. Continue reading Malvertising Campaign Hides in Plain Sight on WordPress Websites at Sucuri Blog.
- Vulnerability & Patch Roundup ā September 2025by Sucuri Malware Research Team on September 30, 2025 at 9:31 pm
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educate website owners about potential threats to their environments, weāve compiled a list of important security updates and vulnerability patches for the WordPress ecosystem this past month. The vulnerabilities listed below are virtually patched by the Sucuri Firewall and existing clients are protected. Continue reading Vulnerability & Patch Roundup ā September 2025 at Sucuri Blog.
- Enhancing File Transfer Security with SSH Key Authenticationby Kyle Knight on September 30, 2025 at 2:20 am
Attackers scan for TCP 22 and 2222 around the clock. When they find an open port, they launch credential-stuffing lists harvested from previous leaks, brute-force scripts, and even malware that hunts for hard-coded passwords in deployment repositories. Verizonās 2025 Data Breach Investigations Report (DBIR) continues to show stolen credentials as a leading initial access vector because many organizations still rely on simple passwords for SSH and SFTP. Once an outsider lands shell access or write permission to an upload directory, web-facing code and client data follow quickly. Continue reading Enhancing File Transfer Security with SSH Key Authentication at Sucuri Blog.
- Troubleshooting WordPress: How to Fix the White Screen of Death (WSoD)by Rianna MacLeod on September 25, 2025 at 4:11 pm
Navigating to your WordPress site only to be met with the White Screen of Death (WSoD) can be a daunting experience. This error denies access to your site for both administrators and visitors, disrupting your websiteās performance and user experience. Despite its prevalence, this common WordPress problem has a number of straightforward solutions. In this post, weāll cover what the WordPress white screen error is, outline the most common reasons for this issue, and detail the steps you can take to resolve it. Continue reading Troubleshooting WordPress: How to Fix the White Screen of Death (WSoD) at Sucuri Blog.
- Hidden WordPress Backdoors Creating Admin Accountsby Puja Srivastava on September 24, 2025 at 2:59 am
During a recent cleanup of a compromised WordPress website, we discovered two different malicious files designed to silently manipulate administrator accounts. Attackers often inject such backdoors to maintain persistent access to a site, even if their other malware is detected and removed. These files were disguised to look like regular WordPress components, but their functionality told a different story. What did we find? We found two highly suspicious files that immediately caught our attention. Continue reading Hidden WordPress Backdoors Creating Admin Accounts at Sucuri Blog.
- Understanding Spamhaus and Its Role in Email Securityby Kyle Knight on September 20, 2025 at 12:32 am
In an era when email remains one of the most important forms of communication for business, commerce, and personal use, ensuring that emails reach their intended recipients (and donāt end up in spam, or worse, aiding cybercrime) is more important than ever. One of the often ābehindātheāscenesā organizations helping to defend email systems is Spamhaus. In this post, weāll explain what Spamhaus is, how it works, why it matters, and what best practices companies should follow to stay out of blacklists and protect deliverability. Continue reading Understanding Spamhaus and Its Role in Email Security at Sucuri Blog.
- Choosing the Best CMS for Your Needsby Kyle Knight on September 13, 2025 at 12:28 am
Knowing which is the right CMS is key when launching a new site. Websites are no longer just online brochures; theyāre where businesses sell products, protect private information, chat with customers, and build their entire online brand. A good CMS gives you flexibility, room to grow, and strong security, so you can easily manage your content and adapt as your online presence gets bigger. Picking the wrong one can cause a lot of headaches, slowing down your growth and messing with user experience. Continue reading Choosing the Best CMS for Your Needs at Sucuri Blog.
- How to Fix the āDeceptive Site Aheadā Warningby Rianna MacLeod on September 10, 2025 at 7:00 pm
Did you just try to access your site and encounter a Deceptive Site Ahead warning? This error message occurs when the browser believes your website is unsafe and experiencing security issues ā and it can seriously affect your traffic and reputation. When this warning appears on your site, youāll want to address it as soon as possible to ensure that your site (and visitors) are protected from phishing and other social engineering attacks. Continue reading How to Fix the āDeceptive Site Aheadā Warning at Sucuri Blog.
- Vulnerability & Patch Roundup ā August 2025by Sucuri Malware Research Team on September 1, 2025 at 12:22 am
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educate website owners about potential threats to their environments, weāve compiled a list of important security updates and vulnerability patches for the WordPress ecosystem this past month. The vulnerabilities listed below are virtually patched by the Sucuri Firewall and existing clients are protected. Continue reading Vulnerability & Patch Roundup ā August 2025 at Sucuri Blog.
- What is Phishing?by Juliana Lewis on August 26, 2025 at 4:52 pm
Phishing is a serious threat to any industry. We have seen this topic appear in the newsĀ more each day. You might have already received a fraudulent email from what seemed to be your bank or even seen the hacking that took place during the 2016 US presidential election. But what do you know about phishing? What is Phishing? Phishing is the fraudulent attempt to obtain sensitive information like login information or other personal identification information (PII), which is any data that could potentially identify a specific individual, such as: usernames, passwords, credit card details, SSN (Social Security Number), bank account information, email, phone number, secret question answers Even partial information can increase the chances of success to subsequent social engineering attacks. Continue reading What is Phishing? at Sucuri Blog.
- Locking Down the WordPress Login Pageby Kyle Knight on August 22, 2025 at 10:24 pm
Due to its flexibility, ease of use, and massive plugin ecosystem, WordPress is a favorite among bloggers, developers, and businesses alike. Given its popularity, attackers do not waste time guessing where sensitive assets live. By default, on every WordPress site the front door is conveniently labeled /wpālogin.php or /wpāadmin/. On even a modest site, server logs can often reveal hundreds of failed logins coming from residential proxies and botnets that rotate addresses. Continue reading Locking Down the WordPress Login Page at Sucuri Blog.