Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Ebola, twins and women-led conservation: Reporting on gorillas for World Gorilla Day

    September 25, 2026

    Unpacking allegations FCC Chair Brendan Carr was in ‘sex trafficking cult’

    September 25, 2026

    Lula says Trump wants to ‘colonise’ and capture Brazil’s resources by meddling in election | Brazil

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Ebola, twins and women-led conservation: Reporting on gorillas for World Gorilla Day
    • Unpacking allegations FCC Chair Brendan Carr was in ‘sex trafficking cult’
    • Lula says Trump wants to ‘colonise’ and capture Brazil’s resources by meddling in election | Brazil
    • Hält der Tankrabatt, was Merz verspricht? – POLITICO
    • Here’s the Tesla Semi… again
    • WordPress patches a critical severity security vulnerability
    • Bitget Suspects North Korea Behind $352M Hack
    • “We just need to go back” – Uranus’ moon Ariel may have hidden a 100-mile-deep ocean
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    WordPress patches a critical severity security vulnerability

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    IDC’s Harris noted that Patchstack’s telemetry illustrated the new reality, with attacker reconnaissance occurring within five hours of the patch, and full exploitation within about a day. “The window between disclosure and exploitation has collapsed to the point that mean time to exploit for critical vulnerabilities is now negative in some cases, meaning exploit code appears before or immediately after a patch ships,” he said. “This WordPress bug tracks that pattern closely: Patchstack recorded the first probing traffic under five hours after WordPress 7.1.2 was released, and traffic volume increased roughly tenfold within a day as attackers moved from scanning to actual payload delivery.”

    Aman Mahapatra, chief strategy officer for New York City-based technology consulting firm Tribeca Softech, agreed.

    “The number that should anchor this story is not the 9.2 CVSS score, but it is the gap between patch and exploit. With this vulnerability, that gap was effectively zero,” he said. “WordPress shipped 7.1.2 on September 22, and Patchstack blocked the first exploitation attempt at 11:49 UTC the same day, using payloads that matched the exact encoding the patch was written to fix. Attackers did not discover this bug. They read the fix. Publishing a patch is now functionally publishing an exploit guide, and any enterprise still running a remediation cycle measured in weeks is operating on a timeline that stopped existing some time ago.”

    critical Patches Security severity Vulnerability WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

    Begin at the End: How to Enable Agentic Remediation

    Autonomous AI Hacks Raise Thorny Questions of Legal Accountability

    MacSync malware uses public iCloud calendars to deliver new payloads

    ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

    Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Ebola, twins and women-led conservation: Reporting on gorillas for World Gorilla Day

    September 25, 2026

    Unpacking allegations FCC Chair Brendan Carr was in ‘sex trafficking cult’

    September 25, 2026

    Lula says Trump wants to ‘colonise’ and capture Brazil’s resources by meddling in election | Brazil

    September 25, 2026

    Hält der Tankrabatt, was Merz verspricht? – POLITICO

    September 25, 2026
    Latest Posts

    Spain’s Pedro Sánchez is a progressive outlier in Europe – and over Ceuta, he is being made to pay for it | Eoghan Gilmartin

    August 6, 2026

    Putin Signs Law For Russia To Regulate Crypto Exchanges

    August 6, 2026

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Ebola, twins and women-led conservation: Reporting on gorillas for World Gorilla Day

    September 25, 2026

    Unpacking allegations FCC Chair Brendan Carr was in ‘sex trafficking cult’

    September 25, 2026

    Lula says Trump wants to ‘colonise’ and capture Brazil’s resources by meddling in election | Brazil

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.