Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
News
Sports
TV & Film
About Us
Contact Us
Copyright
© 2024 PodJoint
Podjoint Logo
US
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts112/v4/31/c0/79/31c0790c-1be1-e702-f2ca-819384f0f3c7/mza_1081328326622802760.jpg/600x600bb.jpg
Patchstack Weekly
Patchstack Weekly
68 episodes
5 days ago
This is a weekly series where you can get caught up on recent events relevant to open source security, with an initial focus on WordPress security. This series is brought to you by Patchstack and your host Robert. I look forward to helping keep you regularly up to date on open source security issues here at the Patchstack weekly Update.
Show more...
Tech News
News
RSS
All content for Patchstack Weekly is the property of Patchstack Weekly and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
This is a weekly series where you can get caught up on recent events relevant to open source security, with an initial focus on WordPress security. This series is brought to you by Patchstack and your host Robert. I look forward to helping keep you regularly up to date on open source security issues here at the Patchstack weekly Update.
Show more...
Tech News
News
Episodes (20/68)
Patchstack Weekly
Patchstack Weekly - Ending On a High Note

This is the final episode of the Patchstack Weekly podcast. All things come to an end - so it's only fitting to dedicate the last episode to software end-of-life, and how developers and website owners should handle sunsetting their projects.

We also want to thank our host, Robert, for sharing lessons on WordPress security (and beyond) over these past 68 episodes!

Show more...
2 years ago
7 minutes 20 seconds

Patchstack Weekly
Patchstack Weekly - Securing Open-Source Forks

Forking is a fundamental part of open-source software - it offers anyone the opportunity to lead an existing project in a new direction. But forking also means that the owners of the new fork are taking over the responsibility for the security of their new project.

Show more...
2 years ago
5 minutes 44 seconds

Patchstack Weekly
Patchstack Weekly - Preventing Insecure Inclusion Bugs

This week's knowledge share is about a rare but serious security bug that can be found in any PHP application. Luckily it is easy to avoid, and WordPress has a built-in function that developers can utilize to help secure against it. In vulnerability news we'll cover three vulnerabilities, including one PHP Object Injection bug in the popular Advanced Custom Fields plugin.

Show more...
2 years ago
5 minutes 57 seconds

Patchstack Weekly
Patchstack Weekly - The One Serious Vulnerability That Open-Source Will Never Have

Closed-source software has one vulnerability open-source software will never face - source code leaks. This episode is all about embracing people who review open-source software, and consequently make it safer.

We'll also cover the recent Elementor Pro vulnerability that is, unfortunately, being actively exploited by attackers.


Show more...
2 years ago
5 minutes 40 seconds

Patchstack Weekly
Patchstack Weekly - Understanding WordPress Security Bug Severity

When you see a security fix available for your website, you should of course update the affected component. But should you drop everything and apply the update immediately? Or can you at least finish your coffee first? Or is it OK to deal with it when you get a break? That depends on the bug.

Also in this episode, we'll cover the recent critical WooCommerce security bug which was, luckily, fixed with a rare forced update by the WordPress team.

Show more...
2 years ago
7 minutes 13 seconds

Patchstack Weekly
Patchstack Weekly - Un-updatable Plugins - What Do They Mean?

Abandoned plugins with security bugs in them are a silent risk for WordPress site owners - but there's an easy way to spot plugins that have been out of date for a while straight from your WordPress admin page. This episode is a quick tutorial on that!

Show more...
2 years ago
5 minutes 8 seconds

Patchstack Weekly
Patchstack Weekly - State of WordPress Security 2022 Report

We've just released our annual State of WordPress Security report, chock full of security stats and trends from the WordPress ecosystem.

Last year we saw 328% more reported security bugs added to our vulnerability database compared to 2021. This is actually a positive sign of the ecosystem becoming more secure, as more bugs are being caught (and patched). On the downside, the trend of critical vulnerabilities being left unpatched persists.

Today's episode is a sort of a tl;dr, as we dive into some of the bigger findings from the whitepaper and explain what they mean for the community.


Show more...
2 years ago
8 minutes 13 seconds

Patchstack Weekly
Patchstack Weekly - Using WordPress As a Headless CMS

This week's knowledge share is an introduction to headless CMS's and WordPress. Robert will dive into what a headless CMS is, how WordPress can be used as one, and the security concerns that go along with it.

Show more...
2 years ago
7 minutes 31 seconds

Patchstack Weekly
Patchstack Weekly - Should You Convert WordPress To a Static Website?

A static website is basically just some HTML files sitting on a server. It's very fast, cheap and secure - and it's rare to have all three.

This week's episode is all about the benefits of static sites, and when should you consider using them.

Show more...
2 years ago
7 minutes 52 seconds

Patchstack Weekly
Patchstack Weekly - Do You Need Virtual Patching?

Regular software updates are essential for security - but they are not enough. Even if you make it a habit to regularly update your WordPress components or use auto-updates, sometimes developers won't release security updates. In fact in 2022, a quarter of critical vulnerabilities found in WordPress plugins did not receive a fix.

This is where "virtual patching" comes in - tune in to learn more about this handy extra security layer.

Show more...
2 years ago
6 minutes 58 seconds

Patchstack Weekly
Patchstack Weekly - Do You Need a 'security.txt' File?

Security.txt is a new proposed standard to encourage website owners to adopt a more proactive approach to security.

The file is an easy way to quickly communicate your vulnerability disclosure program to security researchers. Big companies like Google, Slack, Github and Automattic are already using it - should you?

Show more...
2 years ago
7 minutes 39 seconds

Patchstack Weekly
Patchstack Weekly - The Spurious Infinity of Security

The practice of security is boundless, with infinite context about what constitutes danger. Today's episode looks into how you can practice security to better your resume, services, business, and life.

This week's vulnerability roundup will share details on three security bugs that were patched last month in a popular Learning plugin for WordPress.

Show more...
2 years ago
8 minutes 33 seconds

Patchstack Weekly
Patchstack Weekly - How Can Developers Prove Security?

This week's knowledge share is for developers and site owners alike. Robert will be discussing all about how open-source projects (or really any code project) can show, not just tell, their users that their project's code is secure and safe to use.

This week's vulnerability roundup will share details about three high-risk security bugs in WordPress components - of which two received patches and one went without.

Show more...
2 years ago
7 minutes 46 seconds

Patchstack Weekly
Patchstack Weekly - What Makes a Secure Hosting Service?

The security of your web hosting provider is just as important as the security of your WordPress site. So in this episode Robert talks about how you can check for some important security features your hosting provider may or may not be offering.

This week's security news will cover two critical vulnerabilities - one that received a patch, and one that did not.

Show more...
2 years ago
8 minutes 56 seconds

Patchstack Weekly
Patchstack Weekly - Are You Running Insecure Plugins?

Join Robert on his second episode of new year's security resolutions - this time, he'll be running you through the checklist for ensuring the plugins on your site are safe to use.

He'll also be talking about the recent Doctor Web report about a botnet targeting specific outdated WordPress plugins - which is a great reminder to always keep all your components up-to-date!

Show more...
2 years ago
8 minutes 14 seconds

Patchstack Weekly
Patchstack Weekly - Rotate Your Passwords

In this episode we want to say two things: 1) Happy new year and 2) rotate your passwords!

Rotating your passwords regularly is a key security practice. We feel it's important to stress this in light of the latest news from the LastPass security breach - we now know that attackers did gain access to encrypted customer data, including password vaults.

Granted, this doesn't mean they got their hands on passwords and emails in plain text, but if you've used LastPass then it's high time to change all your passwords now.

Show more...
2 years ago
7 minutes 51 seconds

Patchstack Weekly
Patchstack Weekly - Will AI Change Web Security?

Last week we confirmed that ChatGPT can write basic WordPress plugins - but should you let it? Does AI write safe code? Can it detect vulnerabilities?

Tune in to this year's last episode of Patchstack Weekly to find out what the recent advances in AI mean for the future of web development.

Show more...
2 years ago
9 minutes 7 seconds

Patchstack Weekly
Patchstack Weekly - How One Vulnerability Affects Many

This week's knowledge share is about a recent influx of patched security bugs affecting a single vendor. Don't panic though - the bugs are low-risk. 

The noteworthy part is the number of products affected by the same bug. Stay tuned for this weekly knowledge share where Robert explains why one vendor has multiple products affected by the same bug, and what this has to do with the software supply chain.

Show more...
2 years ago
8 minutes 20 seconds

Patchstack Weekly
Patchstack Weekly - When Hacks Come Back

Recently LastPass reported a secondary security incident that occurred months after an initial break-in. We applaud their honesty and transparency in handling the matter - this is a great example of how to handle any security incident!

LastPass team's investigation concluded that this recent issue - of unexpected access to a third party service - was likely made by someone with information leaked from an incident that happened months ago in August.

So in this week's knowledge share, Robert will discuss the topic of lingering threats from old hacks.

Show more...
2 years ago
9 minutes 25 seconds

Patchstack Weekly
Patchstack Weekly - Hunting Open-Source Security Bugs With SAST

Knowing where to look is the key to finding what you're looking for. For security bugs, it is essential.

In this week's knowledge share, Robert will teach you the basic process of finding security bugs using static code analysis - also known as SAST.

Show more...
2 years ago
8 minutes 13 seconds

Patchstack Weekly
This is a weekly series where you can get caught up on recent events relevant to open source security, with an initial focus on WordPress security. This series is brought to you by Patchstack and your host Robert. I look forward to helping keep you regularly up to date on open source security issues here at the Patchstack weekly Update.