Your WordPress News Dashboard

Page 6 of 8

Episode 105: The Hottest Trend in WordPress - Wordfence Blog

An analysis of WordPress-related search trends found that interest in WooCommerce related results dominated during 2020. We discuss recent vulnerabilities discovered by our threat intelligence team in Ninja Forms, affecting over 1 million sites. WordPress issues a statement that pirated… Continue Reading →

Episode 104: Cryptography Demystified - Wordfence Blog

This week, the Wordfence team discusses cryptography in depth, including the basics, a brief history, hashing, and the Crypto Wars. We also go over current news, including 2 new findings by the Wordfence Threat Intelligence team, a new milestone for… Continue Reading →

Episode 103: Wordfence Innovates with Machine Learning and Security for Schools - Wordfence Blog

Wordfence opens the K-12 site audit and site cleaning service for publicly funded state schools worldwide. Machine learning is now a big part of our malware identification process, which will speed new malware signatures to deployment for WordPress sites protected… Continue Reading →

Episode 102: Disruption Presents Opportunity - Wordfence Blog

After a disruptive year in 2020, there are new challenges in 2021, but also immense opportunities in numerous fields. In a deep and wide-ranging conversation, Mark Maunder and Kathy Zant discuss artificial intelligence, whether or not we’re living in simulation,… Continue Reading →

Episode 101: Supporting Remote Students with Free Site Audits & Cleanings - Wordfence Blog

Wordfence announces a new program offering free site cleaning and site audits to public schools in the United States. We talk about why we’re offering this program and how to help schools take advantage of it. We also talk about… Continue Reading →

Episode 100: How to Lose 6 Figures the Easy Way - Wordfence Blog

The recent SolarWinds attack was incredibly sophisticated. What happens when that level of sophistication targets a homebuyer during one of the largest transactions of their lifetime? On this episode, we tell the story of an extremely difficult-to-detect spearphishing attack that… Continue Reading →

Episode 99: SolarWinds Supply Chain Attack Affects Government and Fortune 500 Businesses - Wordfence Blog

Earlier this week, we learned that SolarWinds, the largest provider of network management tools for government and enterprise organizations fell victim to a supply chain attack. This attack affected their Orion network management system. Reportedly, 18,000 enterprise and government customers… Continue Reading →

Episode 98: How Application Passwords Work in WordPress 5.6 - Wordfence Blog

WordPress 5.6 was released this week with a new feature called application passwords. In this episode we talk about how application passwords work, where to find them in your WordPress installation, and why Wordfence decided to turn these off by… Continue Reading →

Episode 97: The Future of WordPress with PHP 8 and WordPress 5.6 - Wordfence Blog

With WordPress 5.6’s imminent release and the recent release of PHP 8, we talk about the rapid changes affecting the future of WordPress with new security features and new functionality available to both WordPress users and developers. We also review… Continue Reading →

Episode 96: Hosting Provider Failures and Incident Response Preparedness - Wordfence Blog

Two hosting providers experienced outages this week. GoDaddy had a brief outage affecting numerous systems on Tuesday, November 17. Managed.com had an extensive outage due to ransomware that affected all systems. We discuss what types of incident response preparations site… Continue Reading →

Episode 95: Critical Privilege Escalation Vulnerabilities Affect Over 100K WordPress Sites - Wordfence Blog

Three critical privilege escalation vulnerabilities in the Ultimate Member plugin put over 100,000 sites at risk. We also talk about the Page Experience metric to be added as a ranking signal for Google search in May 2021 and what this… Continue Reading →

Episode 94: Hosting Provider Exposed 63 Million Customer Records - Wordfence Blog

A hosting provider exposed over 63 million customer records via an open elastic search database containing verbose logs with plain-text username/password credentials for numerous WordPress, Magento and other sites. We also talk about the security updates in WordPress 5.5.2/5.5.3 and… Continue Reading →

Episode 93: Nitro Documents on the Dark Web and Botnets Targeting Older Vulnerabilities - Wordfence Blog

We cover a couple of breaking stories this week, including the emergency release of WordPress 5.5.3 on Friday, October 30. In preparation for this, a number of sites autoupdated to version 5.5.3-alpha. We also look at the the defacement of… Continue Reading →

Episode 92: WordPress Forced Security Autoupdate Protects Sites from Loginizer Vulnerability - Wordfence Blog

An easily exploitable SQL injection vulnerability was discovered in the Loginizer plugin installed on over one million WordPress sites, causing the WordPress team to force an update to sites using the vulnerable version. The Justice Department is filing antitrust suit… Continue Reading →

Episode 91: How Hackers Can Use CSRF Vulnerabilities and Spearphishing to Wreak Havoc on WordPress - Wordfence Blog

On this week’s episode of Think Like a Hacker, we chat about the cross-site request forgery (CSRF) vulnerability found in the Child Theme Creator by Orbisius and how attackers could use a vulnerability like this with spearphishing to wreak havoc,… Continue Reading →

Episode 90: WPBakery Plugin Vulnerability Exposes Over 4 Million Sites - Wordfence Blog

A vulnerability discovered by the Wordfence Threat Intelligence team in the WPBakery plugin exposes over 4 million sites. High severity vulnerabilities were discovered in the Post Grid and Team Showcase plugins. The online avatar service Gravatar, has been exposed to… Continue Reading →

Episode 89: Shopify Rogue Employees, Medium and Twitter Vulnerabilities, and Hackers Hiding Out in Corporate Networks - Wordfence Blog

Shopify reports that two rogue employees stole data from 200 merchants on their platform. A security researcher found a vulnerability in the Medium Partner Program could have allowed an attacker to steal writers’ earnings. Symantec reports that a state-sponsored hacking… Continue Reading →

Episode 88: XCloner Vulnerabilities, LokiBot Malware, & a 14 Year Old Nets a $25K Bug Bounty - Wordfence Blog

Our Threat Intelligence team discovered several vulnerabilities present in XCloner Backup and Restore, a WordPress plugin installed on over 30,000 sites. These vulnerabilities could have allowed an attacker to modify arbitrary files, including PHP files. The US government Cybersecurity and… Continue Reading →

Episode 87: Vulnerabilities Affect Discount Rules for WooCommerce Plugin, ModSecurity & Windows - Wordfence Blog

Vulnerabilities were recently patched in the Discount Rules for WooCommerce plugin installed on over 40,000 WordPress sites. Developers from OWASP Core Rule Set said ModSecurity v3 is exposed to denial of service exploits, though the maintainers of ModSecurity reject that… Continue Reading →

Episode 86: War of the Hackers - Wordfence Blog

Millions of attacks have been targeting the recent File Manager plugin zero-day vulnerability discovered last week. Two attackers are vying for control over sites compromised through the vulnerability. A security researcher has revealed that specially crafted Windows 10 themes can… Continue Reading →

Episode 85: 0Day in File Manager Plugin and WordPress 5.5.1 Fixes Broken Sites - Wordfence Blog

Over 700,000 WordPress users were affected by a zero-day vulnerability in the File Manager plugin, and the WordPress 5.5.1 release fixed millions of sites affected by deprecation of jQuery Migrate. SendGrid is under siege from spammers using hacked accounts, and… Continue Reading →

Episode 84: Google Chrome Plans to Implement Insecure Form Warnings - Wordfence Blog

The Google Chrome web browser has a high-severity vulnerability that could be used to execute arbitrary code, which has been fixed in Chrome version 85. Google also announced that Chrome 86 will alert users if a form submission is using… Continue Reading →

Episode 83: 100,000 Sites Impacted by Vulnerabilities in Advanced Access Manager - Wordfence Blog

The Wordfence Threat Intelligence team discovered vulnerabilities in the Advanced Access Manager plugin installed on over 100,000 WordPress sites. A high severity authorization bypass could lead to privilege escalation and site takeover. Critical vulnerabilities found in the Quiz and Survey… Continue Reading →

Episode 82: Important Changes in the WordPress 5.5 Update - Wordfence Blog

WordPress 5.5 was released on August 11 with a number of important updates, including a new feature allowing auto-updates of themes and plugins as well as changes to the block editor. The popular Astra theme was suspended from the repository… Continue Reading →

Episode 81: Critical Vulnerability Exposes over 700,000 Sites Using Divi, Extra, and Divi Builder - Wordfence Blog

Our Threat Intelligence team disclosed numerous vulnerabilities this week, including a critical vulnerability in the Divi and Extra themes as well as the Divi Builder plugin. In total, this vulnerability affected over 700,000 sites. A vulnerability found in The Official… Continue Reading →

Episode 80: Critical File Upload Vulnerability in wpDiscuz Plugin - Wordfence Blog

In this week’s news, our Threat Intelligence team discovered a vulnerability in the wpDiscuz plugin, affecting over 80,000 WordPress sites. A blind SQL injection attack affected analytics service Waydev, exposing OAuth tokens for GitHub repositories for software companies, leading to… Continue Reading →

Episode 79: High Profile Twitter Accounts Compromised in Coordinated Attack - Wordfence Blog

A number of high profile Twitter accounts including those of Elon Musk, Apple, Uber, Bill Gates, Joe Biden and others were compromised as a part of a coordinated bitcoin scam attack. The attack lasted a few hours and netted the… Continue Reading →

Episode 78: Targeted Phishing Bypassing Security Checks and a new DDoS Record - Wordfence Blog

This week, we look at some targeted phishing attacks that are bypassing Microsoft Outlook’s protective filters, and phishing campaigns using calendar invitations to target unsuspecting recipients. We also look at some successful bitcoin scams and a new record for a… Continue Reading →

Episode 77: WordPress 5.4.2 Released, Fake Ransomware Bitcoin Scams - Wordfence Blog

This week, we look at the WP 5.4.2 release and a ransomware bitcoin scam targeting site owners with a “You’ve Been Hacked” email. We also look at an FBI warning about online banking app malware, the Verizon data breach report… Continue Reading →

Episode 76: Ongoing Attacks on WP Growing in Volume Plus Numerous Plugin Vulnerabilities - Wordfence Blog

On this week’s Think Like a Hacker podcast, we cover an active attack campaign targeting WordPress sites and numerous plugin vulnerabilities. This active attack campaign has been ongoing and has outpaced all other attacks on WordPress vulnerabilities. Our threat intelligence… Continue Reading →

« Older posts Newer posts »

© 2025 WP News Desk — Powered by WordPress and WP RSS Aggregator | Hosted by WP Engine

Up ↑