A Core File Has Been Silently Altered
What a modified WordPress core file actually means, and what to do about it.
Admin Login From an Unusual Location
Why this alert is really about a new device/IP combo, not geography.
wp-includes/version.php Was Modified
Why this one file is a favorite target for hiding a compromise.
What Is an "Attack Chain"?
Why related alerts sometimes get grouped into one incident instead of three.
My Site Has a Rogue Cron Job
How attackers use scheduled tasks to keep access, and how to spot one.
Outbound Request to an Unknown Domain
What unrecognized outbound traffic usually means and how to investigate it.
Privilege Drift
Why a role or capability change on an account gets flagged for review.
XML-RPC Brute Force
Why xmlrpc.php is a favorite brute-force target, and how it gets rate-limited.
Dormant Admin Account
Why an inactive administrator account is still a real, standing risk.
How to Read a CVE Without a Security Background
The four things that actually matter in a vulnerability report.