Blog Posts

December WordPress Bug-Hunting Challenge

Published on December 5, 2022

We are beyond excited to celebrate the winter holidays and the launch of the Patchstack Alliance Discord community with a special WordPress bug-hunting event taking place throughout December 2022. In December, we released a public leaderboard and profiles for the top security researchers who contribute to making WordPress and the open-source web more secure. You […]

Read more →

Patchstack Weekly #50: When Hacks Come Back

Published on December 5, 2022

Welcome to the Patchstack Weekly Security Update, Episode 50! This update is for week 49 of 2022. This week’s knowledge share is about the lingering problems that can happen after a compromise. This is related to the recent news of LastPass reporting a secondary incident months after an initial break-in. I will discuss this negative […]

Read more →

Patching an Arbitrary Plugin Disablement Bug in the “webmaster-tools-verification” Plugin

Published on November 29, 2022

Welcome to Patchstack’s “Last Patch”. This is a short series of blog posts where we will be discussing and patching unpatched security bugs in open-source projects. With an initial focus on plugins found in the WordPress.org plugin repository This post will review the webmaster-tools-verification plugin. This plugin was first created in 2009 and is extremely simple […]

Read more →

Patchstack Weekly #49: Hunting Open-Source Security Bugs with SAST.

Published on November 21, 2022

Welcome to the Patchstack Weekly Security Update, Episode 49! This update is for week 47 of 2022. This week’s knowledge share will be all about how to find bugs in code – security bugs that is. I will share techniques I use for basic static code analysis and provide examples of what to look out […]

Read more →

Patching Remote Code Execution in the ‘member-hero’ Plugin

Published on November 15, 2022

Welcome to Patchstack’s “Last Patch”. This is a short series of blog posts where we will be discussing and patching unpatched security bugs in open-source projects. With an initial focus on plugins found in the WordPress.org plugin repository Today I will be discussing how to address an unauthenticated remote code execution vulnerability in the member-hero plugin. […]

Read more →

Patching an Arbitrary File Download Vulnerability in wsm-downloader

Published on November 8, 2022

Welcome to Patchstack’s “Last Patch”. This is a short series of blog posts where we will be discussing and patching unpatched security bugs in open source projects. With an initial focus on plugins found in the WordPress.org plugin repository The troubling truth is some open source projects do not receive patches when security bugs are […]

Read more →

Patchstack Weekly #47: What Is Type Juggling in PHP?

Published on November 7, 2022

Welcome to the Patchstack Weekly Security Update, Episode 47! This update is for week 45 of 2022. This week’s knowledge share is about the PHP world’s smallest security bug. I say smallest because it is one character long. You may wonder, how could one character cause so much chaos? Stick around for this week’s knowledge […]

Read more →
Previous Page 23 of 40 (398 total posts) Next