Critical vulnerability identified in WordPress plugin “BackupBuddy” (CVE-2022-31474)
We would like to bring to your attention a newly discovered vulnerability within the WordPress plugin “BackupBuddy".
We would like to bring to your attention a newly discovered vulnerability within the WordPress plugin “BackupBuddy".
This vulnerability is currently being actively exploited with over five million attempts to exploit having been recorded so far.
The flaw exists within the WordPress plugin BackupBuddy (https://ithemes.com/backupbuddy/) and any WordPress instances with the plugin installed may be affected. This vulnerability allows an unauthenticated attacker to view the contents of any file on the affected server that could be read by your WordPress installation. This may include the WordPress wp-config.php file and, depending on your server setup, sensitive files like /etc/passwd.
This issue has been remediated in version 8.7.5, all users of the BackupBuddy plugin are advised to upgrade to the latest version available.
CovertSwarm named a Sample Vendor for Agentic Red Teaming in the Gartner® Emerging Tech Impact Radar: Preemptive Cybersecurity
The question for security leaders is who’s in charge of the agents that test their defenses. We think it should be ethical hackers. That’s how we’re…
Security by obscurity is dead.
On June 18, 2026, an OpenAI agent got into the Medicare statistics reporting service portal run by Services Australia. ABC News describes it as a legacy…
The growing impact of nation-state cyber-attacks on businesses
Nation-state cyber threats no longer stop at government and defense. Here’s what makes these attackers different, and what it actually takes to raise the bar against…