Sucuri researchers have detected a number of cases where hackers have hidden malware within the mu-plugins directory of WordPress, which auto-loads without activation. WordPress site administrators will typically find it tough to prevent the malware from executing, making the mu-plugins directory an ideal place for backdoors. It’s a method that permits attackers to redirect, control and manipulate websites without raising any alarms.

Bugcrowd’s new MSP program looks to transform pen testing for small businesses
Bugcrowd has introduced a service to assist Managed Service Providers (MSPs) in enhancing their penetration testing capabilities, with a specific emphasis on aiding small businesses.