SecuritySupply chain compromise uses poisoned API, no files changedAttackers planted rogue admins and webshells on WordPress sites via a poisoned data feed, not file changes.7 hours ago