home.social

#securityhardening — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityhardening, aggregated by home.social.

  1. If your WordPress malware keeps returning hours after you clean it, the infection probably is not in WordPress at all. I have seen this exact pattern — clean wp-config.php, it comes back, clean again, still back. A forensic case study shows how a webmail log file became a root-level backdoor, sitting entirely below WordPress where no security plugin can reach it.

    #WordPress #SecurityHardening #Malware #WebSecurity

    wpguy.uk/blog/why-cleaning-wor

  2. 74% of hacked WordPress sites were running outdated plugins at the time of breach. In my experience, most WordPress compromises are not clever attacks — they are automated scanners finding the weakest door. I have written up the five most common entry points I see in 2025 and what to do before the scanner finds you.

    #WordPress #WordPressSecurity #SecurityHardening #WebSecurity

    wpguy.uk/blog/why-wordpress-si

  3. A critical authentication bypass in the Burst Statistics plugin scored 9.8 on the CVSS scale — meaning attackers could take full admin control of a WordPress site with zero credentials. Over 200,000 sites were exposed. If you are running this plugin, my advice is simple: update it now.

    #WordPress #WordPressSecurity #SecurityHardening #WebSecurity #CyberSecurity

    wpguy.uk/200000-wordpress-site

  4. Cybersecurity is not a game, not a CTF, not a playground.

    It is an ongoing conflict where every exploit has real consequences.

    If you think this is a hobby, you risk your own life and those who rely on you.

    #cyberwar #securityhardening #opsensecurity #digitaldefense

  5. Implemented a first set of feedback and additions to the nginx hardening guide: linux-audit.com/web/nginx-secu

    Also implemented colored 'tags' to indicate how each measure might help, along adding the rationale to several steps.

    What other security measures did you implement?

    #nginx #linux #securityhardening

  6. awesome-security-hardening:
    A collection of awesome security hardening guides, best practices, checklists, benchmarks, tools and other resources.
    github.com/decalage2/awesome-s

    This is work in progress: please contribute by sending your suggestions here, or by creating issue tickets or pull requests.
    #SecurityHardening #infosec #cybersecurity