One of the latest Security Stories we received covers a nonprofit WordPress multisite with around 40 websites.
The recovery uncovered more than 6,000 infected files, around 1,000 questionable admin accounts, abandoned plugins, outdated software, and no backups.
Cleaning the files was only the start. The work expanded into access control, plugin cleanup, server changes, monitoring, DNS, and other infrastructure.
“I have over 50 years of experience in the software industry, and I am fully retired at this point – except for taking care of the organization’s needs.”
For those who’ve handled incidents like this: what usually takes the most time after the initial malware is removed?
You can read the full story here: https://melapress.com/security-stories/what-it-took-to-recover-a-compromised-40-site-wordpress-network/
Source: r/Melapress · by /u/lana-miro