This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.
“Who would bother hacking us?” is the most common security objection we hear — and it rests on a misunderstanding of who, or rather what, is doing the attacking.
GPT-6 Astra beat all 48 levels of “I’m Not a Robot”Neal Agarwal’s I’m Not a Robot is 48 CAPTCHAs in a row, with a certificate at the end declaring you a human being. GPT-6 Astra played it start to finish and got the certificate. Every level is a new interface with rules nobody explains, and the model figured out what each one wanted and clicked. […]
The First 24 Hours: What a Hacked WordPress Site Looks Like From the Owner’s ChairModern infections don’t deface your homepage — they hide from you specifically, while showing malware to your visitors. A walkthrough of how a compromise actually unfolds, and what to do hour by hour.
MCP in WordPress: Why Your Site Is Learning to Talk to AI AgentsThe official MCP Adapter exposes site actions as tools that AI agents can call. What it needs, and how to connect one without handing it your admin account.
Vibe Coding Came to WordPress — and Brought Its Holes With ItAI now writes plugins on demand and React front-ends by prompt. The productivity is real. So are the vulnerabilities. Here’s how we use AI in development without shipping its mistakes.
Backups That Won’t Save You: The Classic Mistakes of WordPress Backup StrategyAlmost every site we take over has backups running. Far fewer have a restore that anyone has tested. The six failures we keep finding, and what to change.
Claude Cowork now ships with its own built-in browserClaude Cowork now has its own browser. When a task involves a website, a panel opens next to the chat and Claude clicks, reads and fills forms in there while you carry on with whatever you were doing. That browser has nothing to do with yours. Your tabs and passwords stay invisible to it, which […]
The EU Cyber Resilience Act: What It Actually Means for Your WordPress ProjectFrom September 11, 2026, the EU requires software manufacturers to report actively exploited vulnerabilities within 24 hours. Here’s what that means for WordPress sites, plugins, and the people who run them.
Five Hours to Mass Exploitation: How AI Changed the Speed of WordPress AttacksThe median time between a critical WordPress vulnerability being disclosed and mass exploitation is now five hours. Manual patching didn’t lose the race — the race changed.