Sucuri researchers have detected a number of cases where hackers have hidden malware within the mu-plugins directory of WordPress, which auto-loads without activation. WordPress site administrators will typically find it tough to prevent the malware from executing, making the mu-plugins directory an ideal place for backdoors. It’s a method that permits attackers to redirect, control and manipulate websites without raising any alarms.

HHS layoffs could imperil medical device cybersecurity, Democrats say
Democrats and witnesses at a House hearing have warned that layoffs at the Department of Health and Human Services (HHS) could jeopardise oversight of medical