Wordfence Research and News

Blog icon
Category: General Security

A Big Week for Security: Upgrade Jetpack to 4.0.4, Upgrade WordPress Core to 4.5.3.

It’s been a busy week for WordPress security. Jetpack has released a major security update with version 4.0.4 this week that fixes three vulnerabilities: a vulnerability that allowed an attacker to perform unauthorized changes to the “post by email” settings a cross site scripting (XSS) vulnerability in the Jetpack ‘Likes’ module a vulnerability that made submitted ...

8 Reasons Why You Should Choose Wordfence to Clean Your Hacked Site

At Wordfence we know you have a choice between site cleaning vendors.

Major Vulnerability in Freshdesk – Results from a recent Wordfence Red Team Exercise

Wordfence recently conducted a red team exercise on our own network.

Panama Papers: Email Hackable via WordPress, Docs Hackable via Drupal

The Mossack Fonseca (MF) data breach, aka Panama Papers, is the largest data breach to journalists in history and includes over 4.8 million emails.

Mossack Fonseca Breach – WordPress Revolution Slider Plugin Possible Cause

Update: We have written a follow-up post on how an attacker may have moved laterally on the network from WordPress into the email server.

How Attackers Gain Access to WordPress Sites

On this blog we write a lot about different vulnerabilities that could lead to site compromise.

Get Rid of Data to Help Secure It

Last week I spent some time chatting with Mike Dahn who is the co-founder of the BSides information security conferences globally. 

The Crypto Wars – How We Arrived at Apple vs United States

This week our team is in San Francisco attending the RSA 2016 Security conference.

Scary Data – Trends in Malware, Phishing, Site Cleaning and Bad Networks

At Wordfence we have great visibility into the size and scale of the threat facing the WordPress community.

WordPress-Delivered Ransomware and Hacked Linux Distributions

In a rather unfortunate turn of events earlier this month, the Hollywood Presbyterian Medical Center was infected with ransomware.