The WPSetup Attack: New Campaign Targets Fresh WordPress Installs

Attackers scan for the following URL: /wp-admin/setup-config.php This is the setup URL that new installations of WordPress use. If the attacker finds that URL and it contains a setup page, it indicates that someone has recently installed WordPress on their server but has not yet configured it. At this point, it is very easy for an attacker to take over …