⚡ After the recent AI-assisted Remote Code Execution discovery, WordPress core just patched another 12 vulnerabilities. Patchstack users protected at disclosure. More details in our advisory. https://lnkd.in/dEy-jtD8
Patchstack
Computer and Network Security
Parnu, Province / State 7,450 followers
Patchstack helps web developers to easily secure web apps from third-party component vulnerabilities.
About us
Patchstack is the leader in open source software vulnerability intelligence, covering the entire lifecycle from detection to mitigation.
- Website
-
https://patchstack.com
External link for Patchstack
- Industry
- Computer and Network Security
- Company size
- 11-50 employees
- Headquarters
- Parnu, Province / State
- Type
- Privately Held
- Founded
- 2021
- Specialties
- Website Security, Website Monitoring, Web Application Security, Web Application Monitoring, Cyber Security, Cyber Security Platform, Web Security Platform, and Website Security Platform
Locations
-
Primary
Get directions
Akadeemia 1, Forwardspace
1
Parnu, Province / State 80011, EE
Employees at Patchstack
Updates
-
Patchstack reposted this
In the beginning of June, all WordPress websites stopped receiving updates for the first 24 hours for plugins that have released a new version. Everybody can see that the new version is available at the plugin repository, read through the code changes and see the changelog (e.g "important security fix - update now"). You could even install it to a fresh WordPress install, but on existing WordPress websites - updating was not possible. The goal of this change was to fight against supply chain attacks. Real issue that needs solving, however the implementation is highly questionable. We looked into how many supply chain attacks were stopped (or at least the blast radius reduced) vs how many security updates were kept behind a delay while the new version and the security patch in it was disclosed. By tracking the entire WordPress SVN and the WordPress updates API. We found evidence to 1 supply chain attack where updates were hold back that reduced blast radius. At the same time, 81 releases which patched a CVE were made public while at the same time being blocked to distribute the update to websites. Hackers have always launched attacks as fast as they could to hit as many websites as possible that had not yet been updated. In the WordPress ecosystem, last year it took an average of 5 hours for attacks to go start after a vulnerability was disclosed. Week ago, WordPress core vulnerability was actively exploited in 90 minutes. However, with that new WordPress supply chain protection (delayed yet disclosed updates) hackers can finally chill a bit - hopefully they will use this time to self-reflect. https://lnkd.in/dkhn2jVH
-
Patchstack reposted this
On July 13 at 08:41:24 UTC, Patchstack published 66 CVEs in a single second. 22 landed in the second before it and 61 in the second after: 149 CVEs across 136 distinct products in three seconds. That is the largest single second anyone can verify in the CVE record, and more than double the old high of 31.
-
-
What secure WordPress hosting actually covers in 2026, what it does not, and how to close the plugin vulnerability gap. HostList.io and Gautam Khorana discussed it all, and we were happy to provide a technical review. 👇 https://lnkd.in/dhn9DRtf
-
From multiplayer games and the Estonian Defense League to running Patchstack, our CEO and co-founder, Oliver Sild, shared his insights with European Business Review. 👇 https://lnkd.in/d-sekt4s
-
Front row seat: - 65,000+ exploitation attempts blocked - Traditional WAFs failed to stop the exploit requests - Attackers started attempting to exploit ~90 minutes after 7.0.2 was released Here's what else our team found: https://lnkd.in/dEx7DYTR
-
❗️❗️❗️
If you have any websites running on WordPress make sure it’s updated to the version 7.0.2 which was released last night (yes friday night..). It patches a security vulnerability that allows anyone who just knows the URL of the website to create an admin account. It’s as bad as it gets. We at Patchstack deployed mitigation rule for it the moment it was disclosed last night and already see it actively exploited. This is not “I’ll take a look tomorrow”, this is urgent!
-
-
It's amazing to see our partners like Servebolt demystifying security for the end user. Here's what you need to know: 👇
Website security has reached a point where adding another tool at the perimeter is no longer enough. That realization became the starting point for The State of Web Security 2026 whitepaper, where Servebolt CTO Andrew Killen explains how a growing number of compromised customer sites made one thing clear: modern attacks cannot be addressed by simply bolting another product onto the existing stack. We needed to understand where attacks happen, which layers they target, and how those layers can work together without compromising performance. The whitepaper grew from that investigation and from a shared exchange of knowledge with Monarx and Patchstack. Conversations with Aaron Campbell and Mart Virkus brought together three different perspectives on the same problem: hosting infrastructure, application vulnerabilities, and runtime threat detection. The result is a joint view of the web security landscape in 2026, combining real-world platform data, operational experience, and the technologies already protecting Servebolt customers in production. Swipe through the key findings, then download the full whitepaper to explore why layered defense is now the only architecture that works. ⬇️ https://lnkd.in/ewAJ-GPV With research and insights from Patchstackand Monarx.
-
"When your security tool pays for itself in time saved alone, you know you made the right call." Sander Aavik from vDisain puts it best: 1. Less time removing malware (more money to do billable work) 2. More value delivered to clients. Just the time spent removing malware manually after a site is infected costs significantly more in hours than the subscription itself (not even considering the damage done by the malware, lost revenue, etc.). Automated security = less firefighting, happier agency, and happier clients.