Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

SMB Cyber Intelligence Brief: WordPress sites under active attack + KEV warning for Langflow

What small and medium-sized businesses should look out for today.

High Tuesday 21 July 2026, 18:44 UK time
Today’s look-out: Website compromise and ransomware follow-on from internet-facing tools (WordPress / Langflow)

What to look out for today

Two widely-used internet-facing technologies are in the spotlight today:

  • WordPress sites: reports of active exploitation of critical WordPress Core issues being used to install webshells and malicious plugins.
  • Langflow servers: being used as an entry point in attacks linked to ransomware activity targeting AI/model-related files.

CISA has also added the WordPress and Langflow issues to its Known Exploited Vulnerabilities catalogue, which is a strong signal that real-world attacks are happening.

Why this matters to smaller businesses

  • Your website is a business system: a compromised WordPress site can be used to steal customer enquiries, redirect payments, inject fake ‘support’ messages, or damage reputation.
  • Managed hosting/MSP dependency: many SMEs assume their supplier is handling updates and monitoring—today is a good day to confirm.
  • Ransomware isn’t just “big company” risk: attackers often start with an exposed server and then look for credentials, backups, and shared storage.

Warning signs

  • WordPress admin users you don’t recognise, or admin accounts created overnight.
  • New or changed plugins/themes you didn’t approve, or plugins asking for unusual permissions.
  • Website starts redirecting visitors, showing unexpected pop-ups, or your homepage/content changes without explanation.
  • Sudden spikes in server CPU usage, outbound traffic, or lots of failed logins in hosting logs.
  • For teams using Langflow/AI tooling: unusual encryption activity, missing model files/datasets, or unexpected processes consuming disk/CPU.

How attackers may exploit the situation

  • Website takeover: attackers exploit weaknesses to place a persistent webshell or install a malicious plugin, then keep access even after superficial clean-up.
  • Credential capture: compromise is used to steal WordPress/admin/FTP credentials, then reused to access hosting panels, email, or other services.
  • Follow-on disruption: once inside a server, attackers may pivot to shared storage and backups, setting up ransomware or data theft.

What to do today

  • Confirm ownership: identify who is responsible for WordPress Core updates (internal, web agency, host, MSP) and get confirmation they’ve checked today.
  • Review admin access: remove unknown WordPress admins, enforce strong passwords, and enable MFA where available.
  • Check for persistence: ask for a quick review for unexpected plugins, new admin accounts, and suspicious files/changes.
  • Backups reality-check: confirm you have recent, restorable backups (and that they’re not only stored on the same server).
  • Staff awareness (light touch): remind staff to report any ‘website is down / re-enter password / payment page changed’ messages immediately.

Ask your IT provider

  • Do we run WordPress anywhere (including microsites/landing pages) and who patches Core?
  • Have you checked our WordPress sites for unknown admin users, new plugins, or webshell indicators today?
  • Do we host or expose Langflow (or similar AI workflow tools) to the internet? If yes, what monitoring and access controls are in place?
  • If our website is compromised, what’s the agreed containment plan (take offline, restore, credential resets, customer comms)?

Patch watch - only one short paragraph, and only if relevant

CISA has flagged the WordPress Core and Langflow issues as known to be exploited in the wild. For SMEs, the key is less about reading technical advisories and more about ensuring your web/Microsoft/hosting supplier has a fast, routine update process plus post-update checks (admin accounts, plugins, unusual file changes) for internet-facing systems.

One action today

Get same-day written confirmation from whoever manages your website/hosting that your WordPress Core is up to date and they have checked for unknown admin accounts and unexpected plugins/files.

Related Actions On Cyber resource

CTA: Actions On Cyber “Website & WordPress safety checklist” (maintenance, access control, backup and recovery quick checks)

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.