VMTech
Discuss a project

WP-SHELLSTORM: open server exposed WordPress and Joomla attacks

WP-SHELLSTORM: open server exposed WordPress and Joomla attacks

Colleagues, a cybersecurity update.

An open server belonging to a hacker group exposed the inner workings of WP-SHELLSTORM. This was not a sophisticated 0-day, but large-scale abuse of public vulnerabilities against WordPress and Joomla.

What matters:
• target lists included up to 1.4 million entries, but that does not equal the number of compromises;
• the main impact was on outdated plugins and components, including Breeze and JCE;
• separate campaigns also affected enterprise systems via Nacos.

Why it matters: patch hygiene and monitoring for web shell indicators are often more important than sensational headlines.

Today, I would check patches, password rotation, and [kworker]-style processes first. What do you check first?

#cybersecurity #WordPress #Joomla #ThreatIntel

Open analytics
On the site 10 views
min read 1 10.07.2026
On Instagram 5 views
On Instagram 1 reach
Instagram

WP-SHELLSTORM: open server exposed WordPress and Joomla attacks

Open the post on Instagram ↗