{"ok":true,"trend":{"id":699559,"platform":"mastodon","region":"global","key":"🤖 sucuri dissects a wordpress backdoor (\"sc\") that rebuilds itself after cleanup: persistence via files, db entries, and","title":"🤖 Sucuri dissects a WordPress backdoor (\"SC\") that rebuilds itself after cleanup: persistence via files, DB entries, and","url":"https://infosec.exchange/@cloud/117369585335905327","first_seen":"2026-10-02T06:01:48.864241Z","last_seen":"2026-10-02T06:01:48.864241Z","last_rank":11,"peak_rank":11,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.78734375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"Security firm Sucuri has analyzed a WordPress backdoor, dubbed \"SC\", that restores itself after administrators clean infected sites. The malware persists through injected files, database entries, and shared memory, making removal difficult. Sucuri links it to exploit attempts targeting the wpForo forum plugin, with fewer than 20 incidents observed since July 3. WordPress site owners are being urged to check for signs of infection.","why":"The malware's ability to rebuild itself after cleanup alarms site administrators and highlights ongoing WordPress plugin exploitation.","tone":"neutral","entities":["Sucuri","WordPress","SC backdoor","wpForo"],"summarized_at":"2026-10-02T06:03:04.332004Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":927},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Sucuri details self-rebuilding WordPress backdoor tied to wpForo attacks","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-02T06:01:48.864241Z","rank":11,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@cloud/117369585335905327","author":"cloud@infosec.exchange","title":null,"snippet":"🤖 Sucuri dissects a WordPress backdoor (\"SC\") that rebuilds itself after cleanup: persistence via files, DB entries, and shared memory. Tied to wpForo exploit attempts (fewer than 20 seen since July 3). 🔗 https:// thehackernews.com/2026/10/word…","posted_at":"2026-10-02T05:09:04Z","likes":1}],"elsewhere":[],"window":"7d"}}