Welcoming FlyWP to the Patchstack gang! 💚 Mitigation rules are now available to FlyWP users within their dashboards, making secury easier - one step at a time. Welcome aboard! https://lnkd.in/eQkPRmkE
Patchstack
Computer and Network Security
Parnu, Province / State 7,543 followers
Patchstack helps web developers to easily secure web apps from third-party component vulnerabilities.
About us
Patchstack is the leader in open source software vulnerability intelligence, covering the entire lifecycle from detection to mitigation.
- Website
-
https://patchstack.com
External link for Patchstack
- Industry
- Computer and Network Security
- Company size
- 11-50 employees
- Headquarters
- Parnu, Province / State
- Type
- Privately Held
- Founded
- 2021
- Specialties
- Website Security, Website Monitoring, Web Application Security, Web Application Monitoring, Cyber Security, Cyber Security Platform, Web Security Platform, and Website Security Platform
Employees at Patchstack
Locations
-
Primary
Get directions
Akadeemia 1, Forwardspace
1
Parnu, Province / State 80011, EE
Updates
-
"Why should I pay you 5,000... 10,000... 15,000 euros for a website when AI can build it?" Like most service providers these days, Sander Aavik from vDisain gets this question more frequently as of late. His team's response is the best response we've heard: They offer to build the AI version right there on the call... "You can tell me if that's what you want. If so, we can put it up for a fraction of the cost." Then the questions start. And after a real discovery conversation, most clients realize the cheap version isn't what they actually need. If your only value is assembly, you're increasingly at risk. But if the value you bring to the table is knowing what to build and why, you become the trusted partner to execute for your clients.
-
Yesterday, another WordPress core vulnerability dropped - the risk on this one is lower, we felt it's important to write about what it means for website owners. below👇 This vulnerability requires at least an 'Author' account, so it can't be used in the usual automated mass-scale attacks - but websites with a lot of guest writer or member accounts have a risk of targeted attacks. https://lnkd.in/d-mJ6AxX
-
Patchstack reposted this
⚡ Another week, another Remote Code Execution patched in WordPress core. This time, luckily, it requires Author privileges. Time to update! https://lnkd.in/dT8hzpCM
-
⚡ After the recent AI-assisted Remote Code Execution discovery, WordPress core just patched another 12 vulnerabilities. Patchstack users protected at disclosure. More details in our advisory. https://lnkd.in/dEy-jtD8
-
Patchstack reposted this
In the beginning of June, all WordPress websites stopped receiving updates for the first 24 hours for plugins that have released a new version. Everybody can see that the new version is available at the plugin repository, read through the code changes and see the changelog (e.g "important security fix - update now"). You could even install it to a fresh WordPress install, but on existing WordPress websites - updating was not possible. The goal of this change was to fight against supply chain attacks. Real issue that needs solving, however the implementation is highly questionable. We looked into how many supply chain attacks were stopped (or at least the blast radius reduced) vs how many security updates were kept behind a delay while the new version and the security patch in it was disclosed. By tracking the entire WordPress SVN and the WordPress updates API. We found evidence to 1 supply chain attack where updates were hold back that reduced blast radius. At the same time, 81 releases which patched a CVE were made public while at the same time being blocked to distribute the update to websites. Hackers have always launched attacks as fast as they could to hit as many websites as possible that had not yet been updated. In the WordPress ecosystem, last year it took an average of 5 hours for attacks to go start after a vulnerability was disclosed. Week ago, WordPress core vulnerability was actively exploited in 90 minutes. However, with that new WordPress supply chain protection (delayed yet disclosed updates) hackers can finally chill a bit - hopefully they will use this time to self-reflect. https://lnkd.in/dkhn2jVH
-
Patchstack reposted this
On July 13 at 08:41:24 UTC, Patchstack published 66 CVEs in a single second. 22 landed in the second before it and 61 in the second after: 149 CVEs across 136 distinct products in three seconds. That is the largest single second anyone can verify in the CVE record, and more than double the old high of 31.
-
-
What secure WordPress hosting actually covers in 2026, what it does not, and how to close the plugin vulnerability gap. HostList.io and Gautam Khorana discussed it all, and we were happy to provide a technical review. 👇 https://lnkd.in/dhn9DRtf
-
From multiplayer games and the Estonian Defense League to running Patchstack, our CEO and co-founder, Oliver Sild, shared his insights with European Business Review. 👇 https://lnkd.in/d-sekt4s
-
Front row seat: - 65,000+ exploitation attempts blocked - Traditional WAFs failed to stop the exploit requests - Attackers started attempting to exploit ~90 minutes after 7.0.2 was released Here's what else our team found: https://lnkd.in/dEx7DYTR