Practical AI, webdev, and software signals for builders.
Latest useful updates from the open web: tools, releases, changelogs, WordPress, automation, AI coding, and small software signals worth noticing.
Updated from public feeds and lightly curated for practical builders. No hype feed. No voting. Just signals worth checking.
It is a small public signal board for Old Stack Journal. Items come from public feeds and sources, then get lightly curated so readers can spot useful AI, webdev, WordPress, tooling, automation, and software updates without wading through a noisy social feed.
Security signals.
Showing visible Radar cards in this category for the selected date range.
Wordfence Bug Bounty Program Monthly Report – June 2026
In June 2026, the Wordfence Bug Bounty Program received 1066 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem. These submissions are reviewed, triaged, and…
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)
Last week, there were 358 vulnerabilities disclosed in 243 WordPress Plugins and 4 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 184 Vulnerability Researchers that contributed to WordPress Security…
Read original →Your Vulnerability Backlog Is No Longer Technical Debt, It’s an Attack Surface
A growing vulnerability backlog is more than technical debt: it is an attack surface. Learn why outdated risk assumptions, automated attackers, and chained findings demand a new approach.
Read original →PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core
WordPress has released security updates for a critical unauthenticated path traversal vulnerability that can lead to local PHP file inclusion and, on affected server and theme configurations, remote code execution. Site owners should update WordPress Core…
Read original →Inside a Malicious, Stealthy WordPress Must Use Plugin
The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. TThe malware was installed as a must-use plugin with several self-healing mechanisms in place in order to survive removal…
Read original →So I asked my agent instead…
Ask your Evo tenant about models, MCP servers, and skills across your AI estate, from the client you already work in.
Read original →Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
Wordfence Argus found a critical CVSS 9.8 vulnerability in libheif, a library many servers use to process HEIC images. We demonstrated protected-file disclosure and code execution on one exact WordPress deployment. Exploitation is target-specific, but HEIF…
Read original →100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible. The post 100,000 WordPress…
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)
Last week, there were disclosed in that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your…
Read original →Boost Engagement with Free Passkeys by Wordfence
Wordfence 9 introduces passkeys, and passkeys provide a huge friction reduction because your user no longer has to remember their password or retrieve it from a password manager and copy/paste. The post Boost Engagement with Free…
Read original →The AI Hurricane Is Here
AI is accelerating software creation and cyberattacks alike. Leaders must secure agents and code at inception, enforce controls at runtime, and validate defenses independently.
Read original →Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated…
Read original →Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin
On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both…
Read original →Wordfence Bug Bounty Program Monthly Report – May 2026
In May 2026, the Wordfence Bug Bounty Program received 1095 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem. These submissions are reviewed, triaged, and…
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (August 31, 2026 to September 6, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure…
Read original →Is prevention essentially a solved problem?
Prevention in agent-generated code is architecturally solved—but choosing controls that protect security without slowing development remains the challenge.
Read original →Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin
On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload…
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure…
Read original →Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin
On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload…
Read original →Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms
On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity Forms, a WordPress plugin estimated to have more than one million active installations. This high-severity…
Read original →5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin
On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active installations. The post 5 Million WordPress…
Read original →Wordfence Argus: Moving Beyond Human Research Capability
When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to ask it to write a blog post to explain it to you, you know you’re on…
Read original →Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin
On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in WPMU DEV Dashboard, a WordPress plugin with an estimated 350,000 active installations. This vulnerability makes it possible for unauthenticated attackers to gain…
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026)
Last week, there were 240 vulnerabilities disclosed in 184 WordPress Plugins and 17 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 105 Vulnerability Researchers that contributed to WordPress Security…
Read original →Why Your AI Application Is Exposed Snyk
AI applications can pass security scans yet remain exploitable through chained attacks across models, tools, data, and business workflows. Learn how DAST, AI pentesting, and red teaming work together to expose end-to-end risk.
Read original →Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales
A year ago we wrote that we'd put AI to work across the whole company, turning everyone on the team into a capable AI operator so our defenders could stay ahead of the threat actors attacking…
Read original →400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin
On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in TranslatePress, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for unauthenticated attackers to obtain an…
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (August 10, 2026 to August 16, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure…
Read original →100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin
On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in Pods, a WordPress plugin with more than 100,000 active installations. This vulnerability allows unauthenticated attackers to escalate their privileges to administrator…
Read original →Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin
On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an estimated 6,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to…
Read original →Remediation Agents, Demystified: Why Fixing Beats Finding
See how Snyk’s Remediation Agent uses security intelligence, breakability analysis, and validation to turn vulnerabilities into mergeable pull requests.
Read original →Benchmarking Secure-and-Functional Remediation and How Snyk Agent Fix Lifts Frontier-Model Fix Rates by over 14%
A benchmark of secure, functional vulnerability fixes across JavaScript, Java, and Python shows Snyk Intelligence helps frontier models break past a 72–75% performance plateau.
Read original →600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin
On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms, a WordPress plugin with more than 600,000 active installations. The post 600,000 WordPress Sites Affected by Arbitrary File…
Read original →40,000 WordPress Sites affected by Authentication Bypass Vulnerability in User Profile Builder WordPress Plugin
On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in User Profile Builder, a WordPress plugin with more than 40,000 active installations. This vulnerability makes it possible for unauthenticated attackers to log…
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (August 3, 2026 to August 9, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure…
Read original →The Agent Baseline: 35 controls, but where should you start?
The Agent Baseline defines 35 controls across six security outcomes—but the right starting point depends on how your organization uses agents. Learn how to sequence controls for coding, internal, and production agents.
Read original →