Wordfence Research and News

Blog icon

Cryptomining Supply Chain Attack Hits Government Websites

In the past 24 hours, Security researcher Scott Helme discovered that a third party accessibility plugin called ‘Browsealoud’ had their servers compromised.

WordPress Update Breaks Future Auto-Updates. Manually Update Now!

[Update at 10:50am PST: Based on the comments we’ve received below, it sounds like this problem only affects certain sites. 

Breaking: Aggressive WordPress Brute Force Attack Campaign Started Today, 3am UTC

A massive distributed brute force attack campaign targeting WordPress sites started this morning at 3am Universal Time, 7pm Pacific Time.

Wordfence Is Now Defiant

Today we are announcing that our company name is changing to Defiant Inc.

Vulnerabilities in Formidable Forms, Duplicator and Yoast SEO Plugins

Vulnerabilities have been reported in the Formidable Forms, Duplicator and Yoast SEO WordPress plugins.

Your Site Reputation Makes You a Target

I’ve mentioned Troy Hunt a few times on this blog. He’s one of the good guys in our industry and runs a website called haveibeenpwned.com.

WordPress Plugin Banned for Crypto Mining

The WordPress plugin repository recently removed a plugin known as “Animated Weather Widget by weatherfor.us.” We dug a little deeper, and it appears that the plugin was removed for including JavaScript code that would mine cryptocurrency using the CPU resources of site visitors.

Ask Wordfence Episode 3: Should You Hide Your WordPress Login Page?

In today’s episode of Ask Wordfence, I answer a common question we receive from customers: Should I hide my WordPress login page?

New Attacker Scanning for SSH Private Keys on Websites

Wordfence is seeing a significant spike in SSH private key scanning activity.

PSA: Severe Vulnerability in All Wi-Fi Devices

This is a public service announcement (PSA) from the Wordfence team regarding a security issue that has a wide impact.