🦜 Sucuri Blog
@blog.sucuri.net@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
Learn about website security, software vulnerabilities, how to protect WordPress, and malware infections from our team of security researchers.
Your feed and you don't want it here? Just
e-mail the birb.
What is online gambling spam and what can I do about it?
https://blog.sucuri.net/2026/04/what-is-online-gambling-spam-and-what-can-i-do-about-it.html
Published: April 28, 2026 19:12
Online gambling spam thrives on dreams of easy money and high stakes. Beating the house at an exotic casino. Splitting sevens. Going all in on the flop. A baccarat dealer calling La grande! For most people, though, the reality falls far short of Monte…
My Website Is Hosting a Phishing Page – Now What?
https://blog.sucuri.net/2026/04/my-website-is-hosting-a-phishing-page-now-what.html
Published: April 25, 2026 03:24
Most phishing advice is written for the person staring at a suspicious email. This guide is for the other kind of victim: The website owner whose legitimate site has been quietly turned into the attacker’s weapon.
You didn’t send the message or build the…
WordPress DDoS Protection: How to Keep Your Site Online
https://blog.sucuri.net/2026/04/wordpress-ddos-protection-how-to-keep-your-site-online.html
Published: April 23, 2026 22:23
WordPress powers over 40% of the web, which makes it one of the most attractive targets for Distributed Denial of Service (DDoS) attacks. If your site goes down for an hour, you lose revenue, search rankings, and visitor trust. If it goes down repeatedly,…
Joomla SEO Spam Injector: Obfuscated PHP Backdoor Hijacking Site Visitors
https://blog.sucuri.net/2026/04/joomla-seo-spam-injector-obfuscated-php-backdoor-hijacking-site-visitors.html
Published: April 16, 2026 18:45
Overview
During a recent malware cleanup investigation, we encountered a compromised Joomla website where the site owner reported a strange issue. Their website displayed a large number of suspicious product links that had nothing to do with their…
Vulnerability & Patch Roundup — March 2026
https://blog.sucuri.net/2026/04/vulnerability-patch-roundup-march-2026.html
Published: April 1, 2026 20:54
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises.
To help educate website owners…
How to Fix “Not Secure” Warnings and SSL Issues in WordPress (8 Steps)
https://blog.sucuri.net/2026/03/how-to-fix-not-secure-warnings-and-ssl-issues-in-wordpress-8-steps.html
Published: March 31, 2026 16:13
If you own a WordPress website and ever encountered the “Not Secure” warning, you might have worried that visitors would perceive your site as spam or fraudulent. Not only does this warning impact user trust, but it can also create technical search issues…
The Security Risks of Using Nulled WordPress Plugins
https://blog.sucuri.net/2026/03/the-security-risks-of-using-nulled-wordpress-plugins.html
Published: March 30, 2026 21:10
Every year, thousands of WordPress sites get compromised, and a surprising number of those infections trace back to a single decision: installing a nulled plugin.
Nulled plugins promise premium features for little or no money. The problem is that the…
Web Shells: Types, Mitigation & Removal
https://blog.sucuri.net/2026/03/web-shells.html
Published: March 26, 2026 19:00
Web shells are malicious scripts that give attackers persistent access to compromised web servers, enabling them to execute commands and control the server remotely. These scripts exploit vulnerabilities like SQL injection, remote file inclusion (RFI), and…
Vulnerability & Patch Roundup — February 2026
https://blog.sucuri.net/2026/02/vulnerability-patch-roundup-february-2026.html
Published: February 28, 2026 19:30
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises.
To help educate website owners…
Beyond Login Screens: Why Access Control Matters
https://blog.sucuri.net/2026/02/beyond-login-screens-why-access-control-matters.html
Published: February 7, 2026 03:01
As breach costs go up and attackers focus on common web features like dashboards, admin panels, customer portals, and APIs, weak access control quickly leads to lost data, broken trust, and costly incidents. The worst part is that many failures are not…
Vulnerability & Patch Roundup — January 2026
https://blog.sucuri.net/2026/01/vulnerability-patch-roundup-january-2026.html
Published: February 1, 2026 01:12
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises.
To help educate website owners…