01

A Core File Has Been Silently Altered

What a modified WordPress core file actually means, and what to do about it.

02

Admin Login From an Unusual Location

Why this alert is really about a new device/IP combo, not geography.

03

wp-includes/version.php Was Modified

Why this one file is a favorite target for hiding a compromise.

04

What Is an "Attack Chain"?

Why related alerts sometimes get grouped into one incident instead of three.

05

My Site Has a Rogue Cron Job

How attackers use scheduled tasks to keep access, and how to spot one.

06

Outbound Request to an Unknown Domain

What unrecognized outbound traffic usually means and how to investigate it.

07

Privilege Drift

Why a role or capability change on an account gets flagged for review.

08

XML-RPC Brute Force

Why xmlrpc.php is a favorite brute-force target, and how it gets rate-limited.

09

Dormant Admin Account

Why an inactive administrator account is still a real, standing risk.

10

How to Read a CVE Without a Security Background

The four things that actually matter in a vulnerability report.