Wordfence Research and News

Blog icon
Category: Podcasts
Think Like a Hacker Episode 115

Episode 115: Update Your Mac: Gatekeeper Bypass Vulnerability Exploited in the Wild

Apple patches a gatekeeper bypass vulnerability that has been exploited in the wild on MacOS.
Think Like a Hacker Ep 114

Episode 114: Trifecta of Compromises Affect Enterprise Systems

Attacks on unpatched SolarWinds systems continue. We’re now learning of a supply chain attack that started in late January 2021 affecting 29,000 customers of Codecov, as well as a zero-day under active attack affecting customers of PulseSecure VPN.
Think Like a Hacker 113

Episode 113: An Unprecedented FBI Operation Removes Webshells from Infected Exchange Servers

An FBI initiative began remotely removing webshells from infected Microsoft Exchange servers.
Think Like A Hacker Episode 112

Episode 112: Wix Takes Aim at WordPress With New Ad Campaign

A new Wix ad campaign targets WordPress but ends up being tone deaf in both content and strategy.
Wordfence think like a hacker 111

Episode 111: PHP Git Repository Compromised

The self-hosted Git repository for PHP was compromised, with attackers adding a backdoor to a development version of PHP 8.1.
Think Like a Hacker Episode 110

Episode 110: Active Exploitation Continues on Unpatched Thrive Themes

Attackers continue to exploit recently patched vulnerabilities in Thrive Themes, though not all of them are successful.
Episode 109: Stop using sms 2fa

Episode 109: This Attack Will Make You Want to Stop Using SMS 2FA

An attack shows how a SMS enablement service was used to bypass SMS 2FA for $16.
Think Like a Hacker Episode 108

Episode 108: Hack Exposes 150,000 Security Cameras at Tesla, Cloudflare and Others

A data breach exposes 150,000 security cameras used by organizations around the world, including Tesla and Cloudflare.
Think Like a Hacker Episode 107

Episode 107: Two Plugin Vulnerabilities Target File Upload Capabilities

The Wordfence Threat intelligence team finds vulnerabilities in two plugins, the User Profile Picture plugin and the WooCommerce Upload Files plugin.
Think Like a Hacker 106

Episode 106: Admin Password Resets, Blockchain Botnets and a Central Management RCE

WordPress 5.7 is due to be released on March 9, and it will allow administrators to send password reset emails to users.