Backdoor
6 articles tagged Backdoor, newest first.

A Backdoor Hides in Joomla's Scheduled Tasks Table
Joomla has run its own scheduler since 4.1. A task planted in that table has to look legitimate to run at all, which is why the task list never gives it away.

Five New Checks for WordPress Hacks a File Scan Cannot See
WP-Cron events, wp_options rows, drop-ins, hidden administrators and impostor plugins. Five new mySites.guru checks for the half of a hack that is not a file.

Impostor Files: How to find every file in a core folder that core never shipped
Joomla 5.4.7 ships exactly one file directly in /administrator/. Impostor Files lists everything else sitting in folders the CMS itself owns.

Reinfected? Check Every Crontab, Not Just Yours
Your cPanel cron jobs look clean but the site reinfects anyway. The cron rebuilding the malware is hiding in a crontab your account can't see. Here is where.

Hacked Yesterday, Exploited Today: Why One Cleanup Is Never the End
The first hack plants a dormant dropper. The real damage comes in the second wave, days or weeks later. Here is why monitoring beats one-shot cleanup.

The WordPress Plugin You Trusted Was Sold to an Attacker
A buyer acquired 31 WordPress plugins, planted a backdoor in August 2025, and activated it in April 2026. Here is what happened and how to check your sites.