Massive botnet chews through 20,000 WordPress sites
If you have a WordPress site, it would be advisable to check your audit logs for any suspicious activity. Check your password security and be sure to turn on multi-factor authentication (MFA or 2FA). After a massive botnet attack 20,000 WordPress sites were hacked by brute-forcing administrator usernames and passwords.
The botnet, which WordPress security company Wordfence discovered last week, infects sites using a feature known as XML-RPC. This is an interface that lets one piece of software make requests to another by sending it remote procedure calls (RPCs) written in the extensible markup language (XML).