PHL Tech Magazine

Post: WordPress patches a critical severity security vulnerability – Computerworld

coder_prem

coder_prem

Hi, I'm Prem. I'm professional WordPress Web Developer. I developed this website. And writing articles about Finance, Startup, Business, Marketing and Tech is my hobby.
Hope you will always get informative articles which will help you to startup your business.
If you need any kind of wordpress website then feel free to contact me at webexpertprem@gmail.com

Categories



IDC’s Harris noted that Patchstack’s telemetry illustrated the new reality, with attacker reconnaissance occurring within five hours of the patch, and full exploitation within about a day. “The window between disclosure and exploitation has collapsed to the point that mean time to exploit for critical vulnerabilities is now negative in some cases, meaning exploit code appears before or immediately after a patch ships,” he said. “This WordPress bug tracks that pattern closely: Patchstack recorded the first probing traffic under five hours after WordPress 7.1.2 was released, and traffic volume increased roughly tenfold within a day as attackers moved from scanning to actual payload delivery.”

Aman Mahapatra, chief strategy officer for New York City-based technology consulting firm Tribeca Softech, agreed.

“The number that should anchor this story is not the 9.2 CVSS score, but it is the gap between patch and exploit. With this vulnerability, that gap was effectively zero,” he said. “WordPress shipped 7.1.2 on September 22, and Patchstack blocked the first exploitation attempt at 11:49 UTC the same day, using payloads that matched the exact encoding the patch was written to fix. Attackers did not discover this bug. They read the fix. Publishing a patch is now functionally publishing an exploit guide, and any enterprise still running a remediation cycle measured in weeks is operating on a timeline that stopped existing some time ago.”

Lora Helmin

Lora Helmin

Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Popular Posts

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.