NextEdge Alliance / Service status
Incident report / INC-2026-09-06Active security incident

Security incident timeline

The site owner reports that the website remains infected. The incident is open, and a safe recovery has not been confirmed.

Updated 06 Sep 2026 · 12:31 UTCPriority UrgentSource Site owner

Incident timeline

UTC

A complete record of the incident, latest first. Search by event or filter by evidence source. All times are UTC; undated snapshots have no confirmed event time.

16 events · Latest first
  1. Owner report
    Malicious code reported; incident remains open

    The site owner reports that the website is still infected with malicious code. Recovery is not confirmed. This owner report supersedes the earlier recovery-verification status; the code, entry point, and extent of infection have not been independently verified. The exact time of the finding was not supplied.

  2. Live observation
    Recovery verification update published

    The initial status update records a fresh homepage check returning HTTP 200 with Elementor CSS, JavaScript, and page markup present. This differs from the earlier report. The check does not verify asset execution, all six pages, forms, videos, or email delivery.

  3. Report timestamp
    Original incident report prepared

    The supplied HTML report carries an 11:00 UTC update stamp and describes the incident as active. That stamp establishes the report’s stated preparation time, not when a public status page became available.

  4. Reported observation
    Earlier verification reports degraded pages

    Both supplied HTML files contain the same report: six published pages reportedly returned HTTP 200 with no plugin asset references, missing layouts, and degraded interactive elements. These are historical observations attributed to the report, not independently repeated checks at that time.

  5. Time unconfirmed
    No active plugins in the supplied snapshot

    The active_plugins option is an empty serialized array. The exact export time and the time at which the list became empty are not established. This snapshot must not be read as the current live plugin state.

  6. Database evidence
    Recovery-mode email timestamp recorded

    WordPress records its last recovery-mode email timestamp at this time. This is a recorded recovery signal, not a verified outage start or proof of email delivery. The precise fatal error and affected plugin or theme have not been identified.

  7. Database evidence
    Backup archive reference recorded

    The export references a site archive whose filename encodes this timestamp. The archive itself was not supplied or restore-tested; its completeness and suitability for recovery remain unverified.

  8. Report history
    Recent page-builder editing reported

    The supplied report describes edits to the Privacy Policy and Footer in Elementor. Editing records provide historical context but do not independently prove that all visitor-facing features worked at that time.

  9. Database evidence
    Migration extension deactivation recorded

    The recorded entry is specifically All-in-One WP Migration Unlimited Extension. This timestamp should not be generalized to every migration plugin or every inactive plugin.

  10. Database evidence
    Perfmatters deactivation recorded

    The same option records a separate timestamp for Perfmatters, 40 seconds after FluentSMTP. No causal connection to the September 6 incident has been established.

  11. Database evidence
    FluentSMTP deactivation recorded

    The recently_activated option contains this deactivation timestamp for FluentSMTP. The export does not establish whether email delivery subsequently failed or whether the plugin was reactivated later.

  12. Database evidence
    Security scan action created

    The exported Action Scheduler log records creation of the defender/async_scan action. It records a start at 15:10:20 and completion at 15:15:18. Completion of this action does not establish that the site was free of security issues.

  13. Database evidence
    Scheduler migration completes

    The database export records the action_scheduler/migration_hook action as complete, with its last attempt at this time. This confirms the scheduler action completed, not that every part of the site migration succeeded.

  14. Report history
    Migration activity reported

    The report describes migration to nea.cloud.mosiur.com using All-in-One WP Migration. The available evidence does not establish migration as the cause of the later incident.

  15. Report history
    Website content developed

    The supplied report describes development of About, Platform, and Invitation pages, alongside media uploads. These activities predate the disruption.

  16. Report history
    Original site setup

    The supplied report dates the original WordPress installation to this period. This is background context, not an incident trigger.

Evidence boundary. The exact infection start, entry point, and restoration time remain unknown. Historical HTTP 200 responses and plugin assets do not prove security recovery.

Latest update

Unresolved

Infection remains, according to the site owner

“site is still infected with malicious codes”

The owner’s latest report supersedes the earlier recovery-verification status. The previous appearance of Elementor assets does not establish that the site is clean.

The malicious code, entry point, and extent of infection have not been independently verified. No resolution ETA has been confirmed.

Visitor impact

Treat the affected website as untrusted while the reported infection remains unresolved. Avoid submitting sensitive information or downloading files from it until recovery is confirmed.

Earlier reports described broken layouts and interactive features on these pages. Their current individual status has not been reverified.

HomeAboutPlatformInvitationTerms of UsePrivacy Policy