After many suggestions, we decide to setup a blog to better communicate with our users. Expect updates from http://sucuri.net and some security-related posts from us.
You May Also Like
Obfuscation Techniques in MARIJUANA Shell “Bypass”
- December 4, 2020
Attackers are always trying to come up with new ways to evade detection from the wide range of security controls available for web applications. This…
Attackers Abuse Poorly Regulated Top-Level Domains in Ongoing Redirect Campaign
- February 18, 2022
One of the more common infections that we see are site-wide redirects to spam and scam sites, achieved by attackers exploiting newly found vulnerabilities in…
WPScan Intro: How to Scan for WordPress Vulnerabilities
- May 7, 2021
In this post, we look at how to use WPScan. The tool provides you a better understanding of your WordPress website and its vulnerabilities. Be…
7 Things You Should Monitor in WordPress Activity Logs
- July 8, 2019
WordPress activity logs can be helpful when troubleshooting or trying to identify a hack. In this article, you’ll learn about the seven things you should…
Massive Google Colaboratory Abuse: Gambling and Subscription Scam
- July 18, 2023
This investigation started with a small and quite simple piece of PHP malware found on a hacked website. We located the following PHP code, responsible…
Meet the Victims of Online Scams
- May 28, 2020
Imagine a lonely person who’s looking for romantic companionship, so they turn to the internet. Picture someone who’s terribly anxious for news about an online…
How to Add Security to Your Client’s Websites
- February 5, 2018
Website security has crossed the mind of nearly every website owner. However, as a website security company, we know that most webmasters come to us…
Formidable Forms / Shortcodes Ultimate Exploits In The Wild
- November 24, 2017
On Monday, November 20th, we were notified about a vulnerability that poses a serious security risk when the Shortcodes Ultimate and Formidable Forms plugins are…
Cloudflare[.]solutions Keylogger Returns on New Domains
- January 24, 2018
A few months ago, we covered two injections related to the “cloudflare.solutions” malware: a CoinHive cryptominer hidden within fake Google Analytics and jQuery, and the…
JavaScript Malware Switches to Server-Side Redirects & DNS TXT Records as TDS
- Last Updated: June 5, 2024
Last August we documented a malware campaign that was injecting malicious JavaScript code into compromised WordPress sites to redirect site visitors to VexTrio domains. The…










2 comments
“/>
“/>
[click here](javascript:alert(document.domain))
Comments are closed.