<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Website Security on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/website-security/</link><description>Recent content in Website Security on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 07 Oct 2026 11:12:26 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/website-security/index.xml" rel="self" type="application/rss+xml"/><item><title>WordPress Backdoor Rebuilds Itself Seconds After You Delete It and Takes Its Orders From Ethereum</title><link>https://hackingpassion.com/wordpress-sc-backdoor-rebuilds-itself/</link><pubDate>Wed, 07 Oct 2026 11:12:26 +0200</pubDate><guid>https://hackingpassion.com/wordpress-sc-backdoor-rebuilds-itself/</guid><description>&lt;p>A WordPress backdoor was deleted and came back &lt;strong>within seconds&lt;/strong>. Deleted again, back again. It lived in &lt;strong>at least 8 places&lt;/strong>, the server&amp;rsquo;s memory too, and had &lt;strong>a hidden admin that could log in without a password&lt;/strong>.&lt;/p>
&lt;p>That is what the cleanup team at &lt;strong>Sucuri&lt;/strong> ran into on a site they were called in to fix. They removed the malware carefully, file by file, and the same backdoor kept returning within seconds of each removal. Their analyst &lt;strong>Gabriel Barbosa&lt;/strong> published the full breakdown on &lt;strong>30 September&lt;/strong>. The researchers call the family &lt;strong>SC&lt;/strong>, after the &amp;ldquo;SC_&amp;rdquo; markers they found in the injected code.&lt;/p></description></item></channel></rss>