WP-SHELLSTORM: open server exposed WordPress and Joomla attacks

Colleagues, a cybersecurity update.
An open server belonging to a hacker group exposed the inner workings of WP-SHELLSTORM. This was not a sophisticated 0-day, but large-scale abuse of public vulnerabilities against WordPress and Joomla.
What matters:
• target lists included up to 1.4 million entries, but that does not equal the number of compromises;
• the main impact was on outdated plugins and components, including Breeze and JCE;
• separate campaigns also affected enterprise systems via Nacos.
Why it matters: patch hygiene and monitoring for web shell indicators are often more important than sensational headlines.
Today, I would check patches, password rotation, and [kworker]-style processes first. What do you check first?
#cybersecurity #WordPress #Joomla #ThreatIntel

