Practical AI, webdev, and software signals for builders.
Latest useful updates from the open web: tools, releases, changelogs, WordPress, automation, AI coding, and small software signals worth noticing.
Updated from public feeds and lightly curated for practical builders. No hype feed. No voting. Just signals worth checking.
It is a small public signal board for Old Stack Journal. Items come from public feeds and sources, then get lightly curated so readers can spot useful AI, webdev, WordPress, tooling, automation, and software updates without wading through a noisy social feed.
Security signals.
Showing visible Radar cards in this category for the selected date range.
Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS
A real Evo Continuous Offensive Security assessment uncovered 33 confirmed vulnerabilities in a multi-tenant enterprise SaaS, including tenant-wide compromise and critical authorization flaws.
Read original →PSA: Supply Chain Compromise in BdThemes Ecosystem via Poisoned API Response
The Wordfence Threat Intelligence Team was notified on August 7th, 2026 of a supply chain compromise affecting BdThemes, a WordPress plugin vendor whose plugins are available in the official WordPress plugins directory. Currently, all the affected…
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure…
Read original →Continuous Offensive Security & AI Pentesting: 20 FAQs
Get answers to 20 common questions about continuous offensive security, AI penetration testing, DAST, and AI red teaming.
Read original →Stop The Sprawl Snyk Secrets Now Generally Available
Snyk Secrets is now generally available, bringing contextual ML detection, secure-at-commit prevention, and unified secrets governance to the Snyk AI Security Platform.
Read original →Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks
keyv 6.0.0 and ten related npm releases shipped install-time malware. See affected versions, hashes, detection steps, and safe remediation order.
Read original →Evo Continuous Offensive Security Is Here Pentesting Grade Coverage For The 350 Days A Year You Aren't Testing
Snyk Evo Continuous Offensive Security brings autonomous, AI-powered pentesting to the 350 days between traditional tests, uncovering exploitable flaws attackers can find first.
Read original →AI Model Risk Intelligence Know Which Models You Can Trust Before You Deploy
AI model risk depends on how a model is deployed. Learn how Evo combines adversarial testing, attack impact, and deployment context to help teams compare models and enforce policy.
Read original →A First Look at Evo Agentic AppSec: Agentic Remediation and Malicious Code Defense
Explore Snyk’s first Agentic AppSec capabilities: an autonomous Remediation Agent that fixes vulnerabilities and Malicious Code Defense that blocks risky packages before they ship.
Read original →Wordfence Bug Bounty Program Monthly Report – April 2026
In April 2026, the Wordfence Bug Bounty Program received 1288 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem. These submissions are reviewed, triaged, and…
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (July 20, 2026 to July 26, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure…
Read original →The Attacker Never Sleeps, Neither Can Your Testing
AI is accelerating software development and giving attackers machine-speed capabilities. Security teams must continuously test AI-built code, govern agents, and independently validate every finding.
Read original →Secure at Inception: Announcing the Snyk Studio Integration for Snowflake Cortex Code
Snyk Studio integrates with Snowflake Cortex Code to scan AI-generated code, dependencies, and containers for vulnerabilities during development.
Read original →WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by unauthenticated attackers to create an administrator account and then execute code through normal…
Read original →Stadium Summer: The Snyk Connect Fan Zone Tour
Snyk’s Fan Zone tour brought AI security workshops, networking, and friendly competition to 8 cities and 3 virtual sessions. Attendees built skills, shared ideas, and leveled up together.
Read original →Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical Authentication Bypass backdoor in Advanced Responsive Video Embedder, a WordPress plugin with approximately 20,000 active installations, less than two hours after…
Read original →The Generator Can't Be the Validator: What OpenAI's Hugging Face Incident Proves About AI Security
OpenAI’s Hugging Face incident is a wake-up call: AI systems can escape their own test harnesses, and vendors can’t be the only ones validating safety.
Read original →What Is AI Pentesting and How Does It Works?
AI pentesting uses reasoning-capable models to continuously find and validate the flaws scanners miss, especially broken authorization and business-logic abuse.
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)
Last week, there were disclosed in WordPress Core, and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in…
Read original →A New Threat Landscape Meets A New Kind of Defender
PRISM, our autonomous AI researcher, is now our #1 vulnerability researcher. A look at AI's new threat landscape — and the new kind of defender it demands. The post A New Threat Landscape Meets A New…
Read original →wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade
wp2shell is a critical unauthenticated RCE chain in WordPress Core, patched July 17, 2026. See who's affected, the exploitation timeline, and what to do now. The post wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE…
Read original →PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain
On July 17, 2026, the WordPress Security Team released updates to WordPress core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the…
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure…
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (June 29, 2026 to July 5, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure…
Read original →Symlinks Are Still Scary (And Yes, You Can Commit Them to Git)
A harmless-looking symlink in a Git repo can redirect a tool into reading or writing anywhere on your machine. That old trick is now showing up in AI coding assistants, with nasty results.
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (June 22, 2026 to June 28, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure…
Read original →Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice?
Snyk VulnBench JS 1.0: 300 repeated scans show LLM security findings vary by run, while SAST and models catch different vulnerability gaps.
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (June 15, 2026 to June 21, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure…
Read original →NVD in the AI Era: The Case for Multi-Source Vulnerability Intelligence
NIST’s shift to risk-based enrichment makes one thing clear: modern security teams need more than a single public source. In the AI era, trusted vulnerability intelligence depends on multiple signals, human validation, and clear context.
Read original →A Note to Our Customers and Partners
A note to our customers and partners about Snyk's AI transformation and organizational changes.
Read original →When a vendor's breach becomes yours: lessons from the Klue incident
A forgotten credential at vendor Klue let attackers reach customers' Salesforce data. How modern SaaS breaches cascade, and the keys you should audit.
Read original →Announcing Agentic Development Security (ADS)
Announcing Snyk Agentic Development Security, a new Evo solution that helps organizations securely adopt AI-driven development with visibility, governance, and control.
Read original →The New Security Control Point: Governing AI Agents Inside the Execution Loop
AI agents introduce security risk through the actions they take, not just the code they produce. Learn how agent behavior governance helps teams observe, steer, and block risky actions in real time.
Read original →What nearly 10,000 developer environments reveal about agentic development risk
AI coding agents are adding a new layer to the software supply chain. Learn what Snyk found in nearly 10,000 developer environments and how to secure the tools, instructions, and permissions behind agentic development.
Read original →Wordfence Intelligence Weekly WordPress Vulnerability Report (June 8, 2026 to June 14, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure…
Read original →Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin
On May 13th, 2026, we received a submission for a critical Unauthenticated Arbitrary File Deletion vulnerability in Avada Builder, a premium WordPress plugin with an estimated 1,000,000 active installations. This vulnerability makes it possible for unauthenticated…
Read original →