Tag: security

  • WPWeekly Episode 163 – Interview With Andrea Middleton of WordCamp Central

    WPWeekly Episode 163 – Interview With Andrea Middleton of WordCamp Central

    In this episode, Marcus Couch and I are joined by Andrea Middleton who manages WordCamp Central. She tells us what it means to be a “dot organizer” within Automattic and what her day to day duties are managing WordCamp Central. We discuss whether the WordCamp Guidelines allow for differentiation between WordCamps. Middleton explains the various…

  • Ryan Hellyer’s AWS Nightmare: Leaked Access Keys Result in a $6,000 Bill Overnight

    Ryan Hellyer’s AWS Nightmare: Leaked Access Keys Result in a $6,000 Bill Overnight

    WordPress developer Ryan Hellyer had always wanted to open source his website. As a strong supporter of open source software and an avid plugin developer, he enjoys sharing his code and learning from others. This desire led him to put his site up on GitHub one evening, not knowing that he would wake to find…

  • iThemes Confirms it Stored Customer Passwords in Clear-Text

    iThemes Confirms it Stored Customer Passwords in Clear-Text

    The CEO of iThemes, Cory Miller, published a second update concerning the security breach that occurred on Tuesday. After news of the breach, customers were left wondering whether or not their passwords were stored in clear-text. The latest update confirms that passwords were in fact stored in clear-text and affected approximately 60,000 customers. There is…

  • iThemes Suffers Security Breach, Customers Urged To Reset Passwords

    iThemes Suffers Security Breach, Customers Urged To Reset Passwords

    iThemes published details on a security breach that took place earlier today. According to the announcement, after noticing suspicious activity, they noticed a signification attack on their membership database. iThemes urges all customers to reset their passwords immediately. To protect accounts from any unauthorized access, iThemes has temporarily reset all user passwords. To regain access…

  • iThemes Security Now Has Brute Force Login Protection

    iThemes Security Now Has Brute Force Login Protection

    iThemes announced Brute Force Login Protection has been added to the latest version of iThemes Security. The new feature enables users to protect their sites either locally or by activating a network wide setting. Local brute force protection looks only at attempts to access your site and bans users per the lockout rules specified locally.…

  • Founder Of ManageWP Publishes Open Letter on Security to The WordPress Community

    Founder Of ManageWP Publishes Open Letter on Security to The WordPress Community

    The founder of ManageWP, Vladimir Prelovac, has published an open letter addressed to the WordPress community on the topic of security. In the letter, he cites the third-party ecosystem surrounding WordPress is not only its biggest strength, but also its biggest weakness. He suggests a three-point plan to help mitigate security issues in themes and…

  • WPWeekly Episode 161 – The CTO Of CrowdFavorite, Chris Lema

    WPWeekly Episode 161 – The CTO Of CrowdFavorite, Chris Lema

    Marcus Couch and I are joined by CrowdFavorite CTO, Chris Lema. We talk about his new position and what the joint-venture partnership means for both CrowdFavorite and iThemes. Lema explains what the word enterprise means for WordPress products and near the end of the show, gives us his prediction on what will happen in the…

  • WPWeekly Episode 160 – The Founder Of BruteProtect, Sam Hotchkiss

    WPWeekly Episode 160 – The Founder Of BruteProtect, Sam Hotchkiss

    In this weeks show, Marcus Couch and I are joined by the founder of BruteProtect, Sam Hotchkiss. We learn the circumstances which lead to the birth of BruteProtect and how it operates. Hotchkiss explains the details of the acquisition with Automattic and how it will be rolled into Jetpack. While some people are not happy…

  • WPWeekly Episode 157 – Jeffro Tells His Story

    WPWeekly Episode 157 – Jeffro Tells His Story

    The past 156 episodes of WordPress Weekly are filled with stories of people who are doing exciting things with WordPress. For this episode, I decided to try something a little different. I handed the show over to Marcus Couch, who interviewed me. In the show, I describe how I became interested in computers and the…

  • WordPress 3.9.2 Fixes Security Vulnerabilities, Users Strongly Encouraged To Update

    WordPress 3.9.2 Fixes Security Vulnerabilities, Users Strongly Encouraged To Update

    WordPress users are strongly encouraged to update their sites to 3.9.2 as it’s a security focused release. According to the announcement, 3.9.2 fixes a possible denial of service issue in PHP’s XML processing. The bug was first reported by Nir Goldshlager of the Salesforce.com Product Security Team and was fixed by Michael Adams and Andrew…

  • Serious Bug Discovered In The All In One WordPress Security and Firewall Plugin

    Serious Bug Discovered In The All In One WordPress Security and Firewall Plugin

    Pippin Willamson, creator of the AffliateWP plugin, has discovered a serious bug within the All In One WordPress Security and Firewall plugin. According to a forum thread created by Williamson, All In One WordPress Security and Firewall automatically detects option ids with fwp as malicious and deletes them. Known WP Pharma Hack Entry: fwp and…

  • WordPress JSON REST API Plugin 1.1.1 Security Release: Update Recommended

    WordPress JSON REST API Plugin 1.1.1 Security Release: Update Recommended

    The JSON REST API plugin for WordPress released a security update over the weekend. Version 1.1.1 includes a fix for a vulnerability wherein the JSONP support built-in to the API could be used to serve up arbitrary Flash SWF files. This technique has been known to be used in the past to abuse JSON endpoints…

  • Critical Security Update For WPTouch, Users Should Update Immediately

    Critical Security Update For WPTouch, Users Should Update Immediately

    First reported by Sucuri, the WPTouch plugin has a dangerous security vulnerability and users are encouraged to update immediately. WPTouch is used to quickly add mobile support to websites and has over 5 million downloads making it one of the most popular plugins in the WordPress plugin directory.   According to Sucuri, WPTouch incorrectly uses…