Critical vulnerability identified in WordPress plugin “BackupBuddy”: (CVE-2022-31474)
We would like to bring to your attention a newly discovered vulnerability within the WordPress plugin “BackupBuddy".
We would like to bring to your attention a newly discovered vulnerability within the WordPress plugin “BackupBuddy".
This vulnerability is currently being actively exploited with over five million attempts to exploit having been recorded so far.
The flaw exists within the WordPress plugin BackupBuddy (https://ithemes.com/backupbuddy/) and any WordPress instances with the plugin installed may be affected. This vulnerability allow an unauthenticated attacker to view the contents of any file on the affected server that can could be read by your WordPress installation. This may include the WordPress wp-config.php file and, depending on your server setup, sensitive files like /etc/passwd.”
This issue has been remediated in version 8.7.5, all users of the BackupBuddy plugin are advised to upgrade to the latest version available.
CovertSwarm named in two Gartner® Hype Cycle™ reports in the Red Teaming as a Service category
CovertSwarm has been named a Sample Vendor for Red Teaming as a Service in the Gartner Hype Cycle for XaaS, 2026, published 7 July 2026. Five…
The two DORA testing programs
Having the right security testing capabilities is not enough. Most firms building a DORA-aligned program are covering the right pillars at the wrong intervals, and that…
The attack your training prepared them for doesn’t exist
I’ve delivered more security awareness sessions than I can count. I’m also a social engineer, which means I’ve been the person those sessions are trying to…