LIVE · cybersecurity feed
Live wire
Cisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEV
breach

Most WordPress pros still lack a breach recovery plan

Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and administrators. Across the whole group, fewer than three in ten have a breach recovery plan. A recovery plan settles in advance

zeroday.news ·

A recent survey of 319 WordPress professionals indicates that a significant majority lack a defined breach recovery plan, despite most having experienced at least one security incident. The survey, conducted by Melapress, a developer of WordPress security plugins, included agency staff, developers, designers, site owners, and administrators who build and manage WordPress sites professionally. Fewer than 30% of these professionals reported having a breach recovery plan in place.

A breach recovery plan typically outlines responsibilities for incident response, identifies the location of clean backups, and specifies communication protocols for notifying affected parties. Without such a plan, critical decisions regarding incident handling are often made ad hoc during an active security event.

For those who had experienced an incident and described its impact, downtime was the most frequently reported consequence, affecting 68.4% of respondents. The most common method of discovering an incident was through external observation, where a visitor, customer, colleague, or administrator noticed unusual site behavior. By the time such anomalies are detected, the incident may already be causing significant disruption.

Other detection methods included logging tools, which were the most effective monitoring control for catching incidents, as well as alerts from hosting providers and malware scanners. The timing of discovery appears to correlate with the severity of the impact. Incidents identified via a search engine warning, for instance, resulted in lost search rankings for 46% of those affected, a stark contrast to the 14.5% of incidents discovered through other means. This suggests that incidents severe enough to trigger search engine warnings have likely progressed further by the time they are found. One e-commerce site owner reported discovering a hack through Google Search Console due to a dramatic drop in traffic, noting that their search rankings never fully recovered.

Experts recommend developing and testing a recovery plan proactively. Key components include defining who is responsible for isolating compromised systems, restoring the site, and communicating with customers. It is also crucial to verify backups through restoration attempts, as an untested backup remains an assumption until proven functional. Melapress emphasizes the importance of training for all personnel, including content editors and administrators, whose actions can impact a site's security posture. Site owners should also ensure they know who receives security alerts, even when security management is outsourced to an agency or freelancer.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hardcoded MCP credentials found in public GitHub files

Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The company analyzed around 82,000 configuration files and found that 12% of credential slots contained a hardcoded credential literal,

breach

98% of fraudulent hires have company credentials by the time they’re caught

A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO of HYPR. “Human intuition is not a security control. Sceptics might po

ai

The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era

AI-driven threats are outpacing traditional audits. Discover how continuous monitoring, automated evidence collection, and risk-based remediation help security teams close compliance gaps and maintain audit readiness as environments change daily.

vulnerability

AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom

Plugin4Shell attack affects all the major coding agents, researchers say

malware

New RatHat Android malware uses AI to automate device control

A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]

vulnerabilityhigh

Cisco alerts customers to second actively exploited zero-day in as many days

The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025. The post Cisco alerts customers to second actively exploited zero-day in as many days appeared first on CyberScoop.