Dutch-led action against SocGholish-linked infrastructure and 14,971 infected WordPress sites points to a deeper fight over the web delivery layer that attackers rely on.
A malware campaign known as Lorem Ipsum has shifted delivery methods, turning compromised WordPress sites into the first step of a social-engineering chain.
A vulnerability linked to Everest Forms has been tied to remote code execution on WordPress sites, and the technical record points to a classic danger zone: user input reaching executable PHP.