WordPress2026-09-13 02:56:54Matt Mullenweg regains control of Automattic within 48 hours as board confirms he remains CEOMatt Mullenweg, the WordPress founder and chief executive of Automattic, returned to power less than 48 hours after the company’s board voted to place him on leave. On Sept. 11, Mullenweg told staff in Automattic’s internal Slack that the board had reached a consensus and that he had regained control of the company. A day later, an Automattic spokesperson confirmed by email that Mullenweg remains chairman and CEO and has the board’s full support. The reversal came after the board voted on Sept. 9 to put him on paid leave and named chief financial officer Mark Davies as interim CEO. Mullenweg later said directors had acted behind his back and described the move as the fifth “coup” he had faced. The company still has not explained why the board removed him in the first place. Mullenweg also suggested on Reddit and X that Silver Lake was involved in an effort to “destroy” his life, though the report said there is no independent evidence supporting that claim. Questions also remain around Davies’ status and possible board changes, including an unconfirmed report that former Automattic director and current Bluesky CEO Toni Schneider has stepped down from the board.230
Check Point R2026-08-20 16:38:52Check Point says StopAndProtect used nearly 2,000 hacked WordPress sites to spread malwareCheck Point Research said the StopAndProtect ransomware operation used nearly 2,000 compromised WordPress websites to distribute malware, steal data, monitor victims and deploy ransomware. The campaign was discovered in mid-May and had compromised more than 6,000 unique IP addresses as of July 24, according to the researchers. The United States accounted for 1,852 of those IPs, while Russia and India each had 630. The report said the hacked websites were also used to host malware, send commands, and store stolen files, screenshots and activity logs. Researchers said the attackers relied on fake CAPTCHA prompts to trick Windows users into running PowerShell commands. That process was used to steal credentials and cryptocurrency wallet seed phrases, and the malware was able to spread through networks and USB devices. Check Point Research said it collected more than 31,000 screenshots and over 700 compressed data archives during its investigation. The researchers also said the attackers may have accidentally infected themselves.1220
WordPress2026-08-20 16:33:38Nearly 2,000 Hacked WordPress Sites Used as Malware and Ransomware InfrastructureNearly 2,000 compromised WordPress sites were used as part of a broader cybercriminal operation that distributed malware, stole files, monitored victims, and deployed ransomware, according to a report from Check Point Research published Tuesday. The firm said it first identified the StopAndProtect ransomware family in mid-May and later linked it to a larger toolkit-driven campaign rather than a single malware strain. Researchers said the operation targeted Windows users through fake CAPTCHA prompts on hacked websites, tricking victims into running a PowerShell command that installed malware capable of stealing credentials, harvesting cryptocurrency wallet seed phrases, spreading through networks and USB drives, locking screens, and dropping ransomware. Check Point said operational security failures by the attackers exposed internal files, infection logs, screenshots from victim machines, and source code used to manage compromised websites at scale. By July 24, the campaign had affected more than 6,000 unique IP addresses, including 1,852 in the United States and 630 each in Russia and India. The researchers also collected more than 31,000 screenshots and over 700 archives containing stolen documents, passwords, and crypto wallet files.1220
WordPress2026-07-23 22:50:16Hacker Backdoors 30 WordPress Plugins, Uses Ethereum Smart Contract to Evade Domain BlockingA report by security researcher Austin Ginder says a buyer inserted backdoor code into WordPress plugins after an acquisition, left it dormant for 243 days, and used an Ethereum smart contract to update C2 infrastructure. WordPress.org later removed more than 30 plugins in one day.520