❕ Fake Browser Updates Targeting WordPress Admins
New malware campaign discovered 7 January 2026.
How it works:
Malicious plugin "Modern Recent Posts" gets installed → Shows fake "Critical Java Update Required" pop-up ONLY to admins in wp-admin → Click "UPDATE NOW" → Downloads malware
Why it's dangerous:
❌ Targeted attack: Regular visitors don't see it - only admins
❌ Social engineering: "Severely outdated", "Prevent security breaches"
❌ Self-updating backdoor: Can update remotely via
?upd=1 parameter❌ Self-destruction: Deletes itself and reinstalls to hide tracks
What gets compromised:
→ WordPress environment (backdoor installed)
→ Admin's local machine (malware download)
→ Site control (full admin access)
How to protect:
✅ Never click browser update prompts inside wp-admin
✅ Real updates come from OS/browser, not websites
✅ Audit installed plugins regularly
✅ Use security scanning (malware detection)
✅ Monitor for suspicious plugins
Red flags:
→ Plugins you didn't install
→ Update prompts inside WordPress admin
→ Urgent security warnings on admin pages
→ Generic plugin names ("Modern Recent Posts")
Real browser updates never happen inside wp-admin.
#wordpress #security #malware #webhostmost