The break is not the initial intrusion. The real risk is that a planted webshell can keep a site usable as a commodity asset, so a cleanup that only removes the obvious malware can leave the operator with access they can reuse or sell again. That shifts the problem from one-time compromise to repeat monetization of the same site.
Researchers exposed a WP-SHELLSTORM server and found tools, logs, target lists, and evidence tied to 25,195 validated compromises. The operation targeted outdated WordPress and Joomla plugins, with the biggest activity around the Breeze cache plugin and Joomla's JCE editor.
The exposed material shows a webshell access-brokering model, not just mass exploitation. That means defenders have to think about surviving footholds and reused access, because a site that looks cleaned can still be part of the market if the backdoor or stolen entry point remains.