Does the “Increased Attack Rate” threaten you?

Does the “Increased Attack Rate” threaten you?

Times are serious (but not hopeless).

Indeed, we are facing a global increase in the attack rate, code-named “Increased Attack Rate”.

“What is this all about now?” you might ask.

(And you’d be right: in IT, it seems we can’t get 5 minutes of peace…)

The basic idea is simple: cyber pirates, or hackers, are constantly launching large-scale automated attack series (and it’s been worse since the democratization of AI. What were they thinking?). Their goal is to find new vulnerabilities in websites.

(Why? Mystery and a bit of a joke! Seriously, not everyone has industrial secrets to exploit or for which ransomware would be worth it… It seems some people are just malicious. On that philosophical note, I invite you to read on, as it’s highly likely to concern you:)

However, WordPress sites represent a significant portion of websites worldwide (is yours one of them?), which means hackers are refining their strategies to exploit the weaknesses of this type of platform.

Specifically, we are experiencing 3 types of attacks:

  1. Attacks known as “brute force”. This is the main one, the most concerning. Hackers can test hundreds of login combinations at once, via an “http” type of access. Their primary goal is to attack our servers’ CPU resources. (This means that… and for you, this means that…)
  1. A massive scan to find a vulnerability in one of the installed extensions and themes used. Recently, significant vulnerabilities were identified in Elementor Pro and All-in-One WP Migration, hence the need for regular updates.
  1. Automated requests aimed at guessing passwords for administrator accounts. Hence, similarly, the need to regularly change your passwords and ensure they are as complex as possible. Of course, the username also is important: at least avoid the most common one: “Admin”. (Do you remember the Louvre’s security password? “Louvre”. How many IT professionals despaired of humanity that day…)

In summary, these attacks primarily aim to slow down our infrastructure, but also to inject malicious scripts and degrade the website via a commonly called “sieve” extension (do you get the picture? So, no need to tell you what that entails).

Fortunately, at CybSyn, we have a slogan that’s not to be sniffed at:

Our priority: your security

(and that of our servers)!

That’s why the Boss and the rest of the team are currently following an action plan specifically designed for this purpose.

It’s a secret, but it essentially involves “in-house” settings, mainly at the firewall level, and you won’t get the details because they’re too technical for this newsletter (if you’re truly curious AND knowledgeable on the subject, write to us).

Furthermore, every week, we do our utmost to update all your extensions, themes, and WordPress.

So, we promise you swing, software, and weapons against malicious hackers.