• Home
  • Pages
    • Knowledge Base
    • About Us
    • Our Process
    • Services
    • FAQ
    • Contact
  • Blog
  • Pricing
  • Home
  • Pages
    • Knowledge Base
    • About Us
    • Our Process
    • Services
    • FAQ
    • Contact
  • Blog
  • Pricing
  • Home
  • Pages
    • Knowledge Base
    • About Us
    • Our Process
    • Services
    • FAQ
    • Contact
  • Blog
  • Pricing
12 Jan

92% of Attackers Are Invisible to Your Server’s Default Defense

by Thomas J. Raef
in Recent hacking news
Comments

    92% of Attackers Are Invisible to Your Server's Default Defense How threshold-based security tools like Fail2ban and Imunify360 miss the vast majority of malicious traffic January 2026     The Promise   Fail2ban and Imunify360 are staples...

Read More
12 Jan

Why User-Agent Blocking Doesn’t Work: We Caught One IP Pretending to Be 4 Different Bots

by Thomas J. Raef
in Recent hacking news
Comments

Why User-Agent Blocking Doesn't Work: We Caught One IP Pretending to Be 4 Different Bots January 2026   We recently caught a single IP address pretending to be four different legitimate bots—all in...

Read More
05 Jan

The Hidden Cost of Compromised Customers

by Thomas J. Raef
in Recent hacking news, Trends
Comments

The Hidden Cost of Compromised Customers   Why Hosting Companies Are Losing the Abuse Battle — And How to Flip the Script   January 2026   Every hosting company has an abuse queue. And every abuse...

Read More
29 Nov

16.29 Million Access Logs Analyzed: What We Learned About Global WordPress Attacks

by Thomas J. Raef
in Recent hacking news
Comments

16.29 Million Access Logs Analyzed: What We Learned About Global WordPress Attacks November 29, 2025   Over the past 11 days, our global threat detection infrastructure has been running hot—processing 16.29 million access...

Read More
25 Mar

Our Insight into the Sign1 Malware

by Thomas J. Raef
in Recent hacking news
Comments

First, I'd like to compliment Sucuri on a fine, detailed analysis of the Sign1 Malware.   Kathy Zant has also analyzed this on her YouTube channel.   A quick recap first, in the unlikely...

Read More
14 Mar

Hackers still using old tactics

by Thomas J. Raef
in Recent hacking news
Comments

Sometimes, while determining root cause of a website infection, we see many new methods. However, recently we've been seeing the same old tactics hackers have been using for years.   A recent...

Read More
03 Jan

The Real Attack Vector Responsible for 60% of Hacked WordPress Sites in 2023

by Thomas J. Raef
in Recent hacking news
Comments

Introduction  WordPress Security is full of myths that have no basis in reality or data. A particularly pervasive one is the unsubstantiated claim that “95% of WordPress hacks are due to outdated...

Read More
06 Dec

Could Your WordPress Security Plugin be Lying?

by Thomas J. Raef
in Recent hacking news
Comments

Many people have received notifications from their cloud server provider indicating their server's IP address has been reported as attacking other websites.   We Watch Your Website's services have been used frequently...

Read More
04 Oct

WordPress Sites Attacked via Management Consoles

by Thomas J. Raef
in Recent hacking news
Comments

In the past 30 days we’ve seen a new attack vector on WordPress websites - management consoles.   First, a disclaimer. The infections discussed here are NOT the result of faulty programming...

Read More
14 Jul

How We Identified Nearly 150K Hacked WordPress Sites in 60 Days

by Thomas J. Raef
in Recent hacking news
Comments

Almost 60K infected sites had installed a WordPress security plugin with a malware scanner.   This report is intended to answer questions and add context to our recently announced discovery of tens...

Read More
22 Jan

One way hackers hack WordPress sites

by Thomas J. Raef
in Recent hacking news
Comments

Okay, WordPress people, check this out by Brian Krebs:   https://krebsonsecurity.com/2022/01/crime-shop-sells-hacked-logins-to-other-crime-shops/   What's important to note is this:   "One example is Genesis Market, where customers can search for stolen credentials and authentication cookies from a...

Read More
01 Nov

hi victim – latest spam tricks

by Thomas J. Raef
in Recent hacking news
Comments

Latest SPAM tricks In your work, is there anything that would stop you from reaching your goals?   Probably not.   Hackers, or cyber criminals as some call them, are the same way. Their income...

Read More
18 May

Avada WordPress Theme – Please Update Immediately

by Thomas J. Raef
in Recent hacking news
Comments

We just received a notification: We are getting in touch to let you know about a stored XSS and a CSRF vulnerability in the Avada WordPress Theme versions prior to 5.1.5...

Read More
11 Apr

Root cause analysis on /wp-base-seo/wp-seo-main.php

by Thomas J. Raef
in Recent hacking news
Comments

I had been preparing this write-up for over a week now, but I see that SiteLock beat me to the punch in their blog. As some of you know, we specialize...

Read More
20 Feb

Infected javascript files

by Thomas J. Raef
in Recent hacking news
Comments

There seems to be a renewed infection of websites based on WordPress, Joomla and other popular website platforms, with some malicious javascript that has been around for awhile. The code referred...

Read More
29 Dec

Hackers looking for infected WordPress websites

by Thomas J. Raef
in Recent hacking news
Comments

Investigating some interesting entries in log files from our customers, we see that hackers apparently are still looking for infected WordPress websites. First we see this: (IP address blanked to protect the infected) -...

Read More
28 Dec

FTP vs SFTP – the real truth about website security

by Thomas J. Raef
in Recent hacking news
Comments

I get real tired of people reading something online and then thinking it's the real truth. Of course, this blog post falls into that category too, but I will explain. Over...

Read More

Latest Posts

  • 92% of Attackers Are Invisible to Your Server’s Default Defense January 12, 2026
  • Why User-Agent Blocking Doesn’t Work: We Caught One IP Pretending to Be 4 Different Bots January 12, 2026
  • The Hidden Cost of Compromised Customers January 5, 2026
  • 16.29 Million Access Logs Analyzed: What We Learned About Global WordPress Attacks November 29, 2025
  • Our Insight into the Sign1 Malware March 25, 2024
  • Hackers still using old tactics March 14, 2024

Latest Tweets

Couldn't connect with Twitter

    No posts were found.