Wordfence Research and News

Blog icon
Category: Research

This Week’s Top 20 Attacked Themes and Who is Attacking Them

Today we’re publishing statistics on the attacks we are seeing on themes across the WordPress ecosystem.

Profile of a Russian Attack IP

At Wordfence we track attacks across all our customer sites, both free and paid to learn more about attacker tactics, techniques and procedures (TTP’s).

Major Vulnerability in Freshdesk – Results from a recent Wordfence Red Team Exercise

Wordfence recently conducted a red team exercise on our own network.

What Hackers Do With Compromised WordPress Sites

We often talk to site owners who are surprised that their sites are targeted by attackers.

Announcing a new Firewall, a Threat Defense Feed and a New Approach

This morning at 9am Pacific time we rolled out a new kind of firewall to over 1 Million active WordPress websites.

How Attackers Gain Access to WordPress Sites

On this blog we write a lot about different vulnerabilities that could lead to site compromise.

Hacked Sites Suffer Long Term Search Ranking Penalties

During our research into what the WordPress community knows about hacked websites, we discovered that there is very little data available on the subject.

6 Million Password Attacks in 16 Hours and How to Block Them

Last week in the President’s cyber security op-ed in the Wall Street Journal he implored Americans to move beyond simple passwords and to enable two factor authentication or cellphone sign-in.

The Forbes Hack and How Your Visitors are Targets Too

I spent a few days last week in Washington DC chatting to new and old friends in aerospace, many well known cybersecurity vendors and folks in the intelligence community.

WordPress Security: Vulnerabilities in BulletProof Security .51 and Notes on Responsible Disclosure

Multiple vulnerabilities exist in BulletProof Security version .51 and earlier including an XSS, SQL injection and SSRF vulnerability.