Wordfence

Wordfence Security News

News EN ↓ 13 episodes

Wordfence Security News is a weekly cybersecurity news podcast covering the top news stories from the world of WordPress security and the broader cybersecurity threat landscape. Hosted by cybersecurity expert and Wordfence researcher Alex Thomas.

Author

Wordfence

Category

News

Podcast website

www.wordfence.com

Latest episode

Jul 9, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Uncanny Automator Backdoor, Splunk Exploited & AI Key Theft | Wordfence Security News #13 09.07.2026

Uncanny Automator Backdoor, Splunk Exploited & AI Key Theft This week in Wordfence Security News (Week of June 23, 2026): • Uncanny Automator Pro Backdoored Through Update Server • Splunk Enterprise Flaw Exploited in the Wild • Fortinet Sandbox Flaws Targeted as FortiBleed Hits Firewalls • LiteLLM Flaw Puts AI Gateway Keys at Risk • Malicious JetBrains Plugins Stole AI API Keys Timestamps: 00:...

WordPress Plugin Supply Chain Attacks, Ivanti CVSS 10 & phpBB Hijacks | Wordfence Security News #12 26.06.2026

WordPress Supply Chain Attacks, Ivanti Root Flaw, and phpBB Account Takeovers This week in Wordfence Security News (Week of June 15, 2026): ShapedPlugin's paid pro plugins were backdoored via the vendor's update system, stealing passwords and 2FA secrets OptinMonster, TrustPulse, and PushEngage served a tampered CDN script that targeted logged-in admins Oracle PeopleSoft zero-day exploited by Shin...

Kirki & UpdraftPlus Exploits, Miasma Supply Chain Worm & 3 Zero-Days | Wordfence Security News #11 18.06.2026

Kirki & UpdraftPlus Exploited, Miasma Supply Chain Worm & 3 Zero-Days | Wordfence Security News #11 In this episode of Wordfence Security News: Kirki's password reset endpoint lets unauthenticated attackers redirect admin reset links to any inbox, enabling full account takeover. UpdraftPlus UpdraftCentral auth bypass allows unauthenticated attackers to install plugins and achieve remote co...

Wordfence Security News #10 - WPMaps Pro Exploited, Palo Alto VPN Bug, and AI Agent-Driven Intrusion 10.06.2026

Wordfence Security News #10 - WPMaps Pro Exploited, Palo Alto VPN Bug, and AI Agent-Driven Intrusion This week in Wordfence Security News (Week of June 1, 2026): WP Maps Pro flaw lets unauthenticated attackers forge admin accounts; exploitation began May 19th, before public disclosure. Palo Alto PAN-OS GlobalProtect authentication bypass under active attack; CISA added it to KEV with a June 1st fe...

WooCommerce RCE | Drupal SQLi | Ghost CMS Clickfix Attack | Wordfence Security News | May 25, 2026 04.06.2026

WooCommerce RCE active exploitation, Drupal SQL injection attacks, Microsoft Defender zero-days, Ghost CMS ClickFix campaign, TrapDoor supply chain, Nimbus Manticore backdoor. This week in Wordfence Security News (Week of May 25, 2025): WooCommerce Custom Product Add-ons Pro RCE flaw (CVE-2026-4001) is under active attack, with exploit attempts spiking May 23-27 against the 21,000-install plugin....

Burst Statistics Bypass Threatens 200,000 WordPress Sites | Microsoft Exchange Zero-Day Under Active Exploitation | Critical Cisco SD-WAN Controller Flaw Exploited | Shai-Hulud Worm Source Code Open-Sourced | Wordfence Security News | Week of May 18, 2026 22.05.2026

This week in Wordfence Security News (Week of May 18, 2026): Burst Statistics plugin auth bypass lets unauthenticated attackers impersonate admins; Wordfence blocked 88,000+ requests across 376 sites. Microsoft Exchange OWA zero-day XSS flaw under active exploitation with no permanent patch; CISA deadline set for May 29th. Cisco Catalyst SD-WAN auth bypass exploited by UAT-8616; CISA gave federal...

Google Identifies First AI-Developed Zero-Day | Gravity SMTP Mass Exploitation Leaks API Keys | Palo Alto Firewall Flaw Exploited by State Actors | TanStack Release Pipeline Hijacked | Wordfence Security News | Week of May 11, 2026 16.05.2026

This week in Wordfence Security News (Week of May 11, 2026): Active mass exploitation of an information disclosure vulnerability in Gravity SMTP exposes API keys and mail service credentials, with the Wordfence firewall blocking nearly 788,000 exploit attempts across more than 77,000 unique WordPress sites A critical authentication bypass in cPanel and WHM is now under active exploitation, allowin...

Breeze Cache Mass Exploitation in 24 Hours | Bitwarden CLI Supply Chain Attack | ADT Confirmed in ShinyHunters Breach | Pack2TheRoot 12-Year-Old PackageKit Privilege Escalation (CVE-2026-41651) | Wordfence Security News | Week of April 27, 2026 04.05.2026

This week in Wordfence Security News (Week of Apr 27, 2026): A critical unauthenticated arbitrary file upload vulnerability in BreezeCache, a caching plugin with over 400,000 active installations, went from disclosure to mass exploitation in under 24 hours with over 22,000 exploit attempts blocked across nearly 5,000 sites Attackers published a malicious version of the Bitwarden CLI package on NPM...

WordPress 30+ Plugin Supply Chain Attack | Wordfence Security News | Week of April 13, 2026 17.04.2026

This week in Wordfence Security News (Week of Apr 13, 2026): Over 30 WordPress plugins purchased on the Flippa marketplace were turned into backdoors that sat dormant for eight months before activating to inject SEO spam into wp-config.php, visible only to Googlebot Smart Slider 3 Pro's update infrastructure was compromised, pushing a weaponized build through the official update channel for approx...

50,000 Site Ninja Forms File Upload Vulnerability | Anthropic Project Glasswing | Fortinet Zero Day | Wordfence Security News | April 6 2026 10.04.2026

This week in Wordfence Security News (Week of Apr 6, 2026): An arbitrary file upload vulnerability in Ninja Forms File Upload puts 50,000+ WordPress sites at risk A Fortinet zero-day actively exploited in the wild A CERT-EU report reveals a European Commission cloud breach tied to a Trivy supply chain attack — with Cisco source code stolen in the fallout Anthropic announces Project Glasswing Germa...

MW WP Form 200K Sites at Risk | Axios Hack | Cisco Breach | Wordfence Security News | March 30, 2026 03.04.2026

This week in Wordfence Security News (Week of Mar 30, 2026):  Over 200,000 WordPress sites at risk from an unauthenticated arbitrary file move vulnerability in the MW WP Form plugin, allowing full site takeover Massive spike in exploitation attempts targeting the Kali Forms RCE vulnerability, with activity increasing over 60x week-over-week A major supply chain attack compromises the widely used A...

Iran-Linked Hackers Breach FBI Director's Email | Wordfence Security News| Week of March 23, 2026 27.03.2026

This week in Wordfence Security News (Week of Mar 23, 2026):  Same-day exploitation of a critical RCE vulnerability in the Kali Forms plugin, attackers can achieve full admin takeover with a single request Ongoing mass exploitation of the s2Member plugin targeting password reset functionality Breaking News: Iran-linked hackers claim breach of FBI Director Kash Patel’s personal email A critical Cis...

30,000 Sites at Risk, Cisco Zero-Day & Stryker Attack | Wordfence Security News | Week of Mar 9, 2026 13.03.2026

This week in Wordfence Security News (Week of Mar 9, 2026):  A critical auth bypass in Tutor LMS Pro exposes 30,000+ WordPress sites — attackers can hijack admin accounts via a Google sign-in flaw An unauthenticated SQL injection in Ally (400K+ sites) Microsoft Patch Tuesday with ~80 fixes including AI-related exploits A max-severity Cisco SD-WAN zero-day exploited since 2023 Iran-linked group Han...

Listen to the Wordfence Security News podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.