WordPress Security Presentation by Tony Perez

Tomorrow I will be flying to my hometown (Miami) to give a Website Security presentation to a bunch of enthusiastic online professionals at an event called WordCamp. If you're not familiar with these events, they are global events put together by the
Read More

UNICAMP – Used to Host Phishing Pages

cielo-phishing

We just discovered that UNICAMP (Universidade Estadual de Campinas), a renowned Brazilian University, has had their infrastructure compromised and it is being used to host phishing link which are then being used email spear phishing campaigns. In
Read More

Comment SPAM Bad Neighborhood Analysis (2013-Mar)

We track and block a lot of comment SPAM via our WordPress plugin and our CloudProxy WAF. One thing we noticed is that the majority of the SPAM we detect come from the same "bad neighbors" (IP ranges that are known for sending a lot of SPAM). We
Read More

Virtual Hardening with Sucuri CloudProxy

If you read our blog you know that we are really open to providing insight into malware infections, remediation and hardening tips. The goal is to help educate website owners where and when we can. Unfortunately, that education only goes so far. We
Read More

Virtual Patching for Websites with Sucuri CloudProxy

Sucuri Cloud Proxy

All software has bugs, and some bugs can lead to security vulnerabilities. Vulnerabilities can be extremely dangerous when your software is running over the web, allowing anyone to reach and try to attack it. That's why patching and keeping web
Read More

2012 Web Malware Trends Report Summary

Sucuri Malware TLD Distribution 2013

Sucuri is a website security company focused on the detection and remediation of web malware. In 2012, via our SiteCheck scanner, we scanned 9,953,729 unique domains. This small report is based on the data we were able to compile from that platform
Read More

Payday Loan Spam affecting Thousands of Sites

SPAM seo push

One of the most important metrics used by search engines to rank a site is the number of link backs that it has. The more links a site has for a specific keyword, the higher it will rank when someone searches for it. So if a site has a lot of links
Read More

Drupal Core Vulnerability Released – Denial of Service – Advisory SA-CORE-2013-002

As if the week wasn't exciting enough, Drupal has released a core vulnerability that leaves it susceptible to Denial of Service attacks. Metadata for this vulnerability is: Advisory ID: DRUPAL-SA-CORE-2013-002 Project: Drupal core Version:
Read More

Linux Based SSHD Rootkit Floating The Interwebs

For the past couple of days we have been a lot of discussion on a number of forums about a potential kernel rootkit making its rounds on the net. Interesting enough when we wrote about the case it wasn't being picked up by anyone, today however it's
Read More

cPanel Inc. Server Compromised

It's unclear on the specifics, but it appears the following letter is going out to cPanel users that have submitted a ticket in the last 6 months: From: no-reply@cpanel.net Sent: Friday, February 22, 2013 12:48 AM To: *********** Subject:
Read More