Reading view

Anyone else find WordPress migrations always take longer than the estimate?

Every migration I have scoped ends up taking longer once I actually get into the site. Looks straightforward from the outside, then I find sections the scraper does not detect properly, or content that got duplicated somewhere, and the timeline slides. Curious if that has been everyone's experience or if I am just bad at estimating.

submitted by /u/Fun_Tone3954
[link] [comments]
  •  

How Social Media Spurred a Refugee Crisis Between Spain and Morocco

An anonymous reader quotes a report from The New York Times: Two days before tens of thousands of migrants surged into Ceuta, one of Spain's enclaves on Morocco's northern coast, a newspaper there posted a video on TikTok and Instagram showing two young women walking in the city in wet suits, their hair still damp. The posts didn't say so explicitly, but the implication was clear: The women had just swum across the border from Morocco. "Ceuta can't take it anymore," the newspaper, El Faro de Ceuta, declared in the posts. On the other side of the border, the video resonated very differently. Cropped and reposted in Arabic, the video seemed like an invitation. The women were smiling, flashing peace signs and thumbs up and, most of all, walking around freely. The video seemed to legitimize rumors that had percolated for weeks on social media suggesting that a recent ruling by Spain's Supreme Court meant migrants who arrived illegally by sea could stay in the country. As one account on Facebook put it, falsely, "Ceuta is turning into an open gate," when in fact migrants still faced expulsion after a judicial review. The responses to the posts about the swimmers were a critical part of a cascade of disinformation that experts described as one of the starkest instances in which social media contributed directly to a real-world tragedy.

Read more of this story at Slashdot.

  •  

Trump Administration Enlists Private Companies To Hack Foreign Cybercrime Groups

The Trump administration today unveiled a new program that will allow vetted U.S. companies to conduct cyber surveillance and offensive cyber operations against foreign transnational criminal organizations. A presidential memorandum signed August 12 directs the National Coordination Center to establish and manage the program, expanding the government's fight against cybercrime by tapping the technical capabilities of the private sector. It builds on a March executive order that called for greater private-sector involvement, but goes significantly further by establishing a formal operational framework for the initiative. The White House argues that American companies possess a "critical offensive cyber advantage" whose capabilities have "historically been underutilized" in efforts to identify and disrupt criminal networks operating online. There are two broad categories of authorized activity. "Cyber Surveillance Operations" can involve secretly accessing foreign information systems without authorization to gather intelligence, including information that could later be used for offensive operations. "Cyber Effects Operations," meanwhile, can result in the "manipulation, disruption, denial, degradation, or destruction" of information systems, networks, or infrastructure. It's worth noting that companies will not be free to launch their own operations. The memorandum requires program officials to "review every cyber operations package and provide written approval and direction" before a participating company can act. Operations that could cause death or serious injury, or "rise to the level of use of force or armed attack under international law," are classified as "Critical Outcomes" and cannot be approved through the standard process. The program includes safeguards requiring companies to halt and report operations that unintentionally affect U.S. persons or systems, as well as any imminent threats to critical infrastructure.

Read more of this story at Slashdot.

  •  

Big Tech Wants to Harvest Your Thoughts

Wired reports that consumer neurotechnology is rapidly moving from the lab into workplaces and homes, with companies including Apple, Meta, and Snap developing products that can monitor or interpret brain activity. Researchers warn that as these systems improve, neural data could become the next major privacy battleground. Some neuroscientists are already calling for a series of core rights, coined "neurorights," that protect "mental privacy," "identity," and personal "agency." Here's an excerpt from the article: Over the past two decades, researchers using functional magnetic resonance imaging (fMRI), which tracks the iron in the hemoglobin supplying oxygen to neurons, have been building up increasingly detailed maps and inventories of the mammalian cortex. Thanks to huge advances in machine-learning artificial intelligence -- computer algorithms that are able to sort through enormous amounts of information and use statistical methods to make classifications and predictions -- fMRI scans can now be used to identify everything from depressive thoughts to the nuanced feelings of envy and schadenfreude. Other algorithms have been able to accurately piece together reconstructions of movie clips watched by subjects, just by analyzing their brain scans; or have detected, in probing the brain activity of swing voters in the US presidential election, responding to photographs and videos of presidential candidates, which candidates provoked anxiety or even disgust, and which elicited positive responses or feelings of empathy. In just the last few years, neuroscience researchers have progressed from decoding images and emotions as they play across the cortex to sounds, words, phrases, and even language. In 2023, in a remarkable demonstration of this emerging technology, a woman called Ann Johnson, who had been paralyzed for 18 years by a brain-stem stroke, was able to speak again through the insertion of a grid of 253 electrodes onto the surface of her brain, which translated her neuronal signals into sentences, in real time, at a rate of 78 words per minute (just about half the speed of standard conversation). The research team at the University of California, led by neurosurgeon Edward Chang, had combined this brain-computer interface with an animated avatar of Johnson's head, which spoke in her own voice, as reconstructed from a recording of a 15-minute toast she had given at her wedding. Just as the avatar's mouth spoke Johnson's words as she thought them, so its expressions were similarly influenced by the nuances of her brain activity, which turned her thoughts about facial gestures into displays of emotion -- from smiles to pursed lips and frowns. [...] The more invasive the recording equipment, the richer and more detailed the data. Surgical interventions are at the vanguard of neuroscience and remain very rare -- fewer than 100 people on the planet have brain-computer interfaces like Johnson's embedded beneath their skulls. Yet almost inevitably, a concerted trickle-down effect is occurring. In the summer of 2023, a team at the University of Texas demonstrated that they could use fMRI to translate brain scans into words and sentences, after subjects listened to 16 hours of the storytelling podcasts The Moth Radio Hour and The New York Times' Modern Love to train an AI model. When the subjects then listened to new podcasts, the algorithm was able to convert the gist of what they heard, as it manifested in their brains, into words, phrases, and sentences that roughly captured the stories. As the team's lead computational neuroscientist, Alexander Huth, put it in an interview with Science, "Our thought when we actually had this working was, 'Oh my God, this is kind of terrifying.'" Now noninvasive, wearable brain scanners are beginning to proliferate beyond the lab, making their way into our workplaces and, through the vast global consumer market, into our homes too.

Read more of this story at Slashdot.

  •  

'Godmother of AI' Says Biggest AI Risk In Schools Is Students Losing the Desire to Learn

Fei-Fei Li, aka The Godmother of AI, says the biggest AI risk in education may be students losing the motivation and agency to learn, rather than simply using the technology to cheat. She argues against banning AI outright, saying it can be valuable when used to support engaged students instead of replacing the thinking and struggle that learning requires. Techspot reports: Speaking on an episode of the science podcast Huberman Lab this week, Li talked about the fears around how students are using AI. "The absolute bad outcome is that our young generation, their agency and human-level motivation of learning and living is taken away by tools," the ImageNet inventor warned. "It should not be taken away by humans nor should it be taken away by machines." If we see a generation of graduates who have completely relied on AI without actively trying to learn anything for themselves, they risk leaving education without having "properly developed the brain," Li said. [...] Li certainly isn't advocating for a complete ban on students using AI. She believes it can genuinely help struggling students who are already engaged in their learning. Li herself noted how she struggled with organic chemistry as a premed student, when teaching assistants and professors didn't have enough time to answer every question. While there's no obvious solution, Li says we need to find a way to keep children and students' motivation and agency. "Let's find a way to give them the access and the right way of using these tools," she said. Li added that if AI is used properly in education, it could make the students of the future "way smarter than us because they are superpowered."

Read more of this story at Slashdot.

  •  

US Tries to Override New York Gambling Laws, Orders Kalshi to Keep Operating

The CFTC has ordered Kalshi to keep operating in New York, claiming the state's lawsuit against the prediction market created a "market emergency." They said it acted "to ensure market stability" and "ordered the exchange to continue to operate in accordance with the Commodity Exchange Act's Core Principles." Ars Technica reports: The market emergency alleged by the CFTC is that New York Attorney General Letitia James sued Kalshi on July 31. James' lawsuit seeks a court order to permanently enjoin Kalshi "from operating an unlawful gambling business" in the state. The lawsuit also demands that Kalshi "make full restitution to customers who have engaged in betting" and pay financial penalties. "New York intends to make event contract derivatives waste away under its iron curtain of state gaming laws before the courts get the chance to issue final rulings," CFTC Chairman Michael Selig said yesterday. "Congress did not intend for derivatives exchanges to be regulated under a patchwork of state gaming laws... New York has no business regulating these interstate financial markets. The commission is required by law to ensure order in these markets, and that is what we have done today." [...] The CFTC says it alone has the power to regulate platforms such as Kalshi and Polymarket under the Commodity Exchange Act, a US law that gives the CFTC exclusive jurisdiction over designated contract markets (DCMs). "These are financial exchanges that offer financial instruments and operate across state lines," Selig said yesterday. "They match the bid from a resident of one state with the offer of a resident from another state and submit the trade to a clearinghouse that backstops the transactions of customers throughout the country."

Read more of this story at Slashdot.

  •  

China-Linked Hackers Used AI To Run First-Ever 'Autonomous' Cyberattack On Taiwan

Researchers at Israeli cybersecurity firm Dream say suspected China-linked hackers used an open-source AI-agent system to conduct what may be the first observed end-to-end autonomous cyberattack against a government. According to the Financial Times (paywalled), the attack compromised at least 85 accounts and resulted in the theft of more than 2,500 personnel records from Taiwanese systems. Tom's Hardware reports: The campaign reportedly ran for four days at the beginning of July and at times deployed as many as eight autonomous agents in parallel. Dream said the system mapped 21 government systems before compromising user accounts and extracting personnel information. The attackers subsequently expanded their activity to Taiwan's nuclear safety agency, at least seven energy companies, government suppliers, and other government systems. Dream says it found the evidence inside a 160-megabyte (160MB) online archive that surfaced during its broader tracking of cyberthreat actors. The archive reportedly held 1,395 files showing that the tool was built on two open-source AI agent systems -- Hermes and OpenClaw -- both of which can be downloaded freely and are designed to let large language models carry out multi-step tasks on their own. Researchers could not determine which underlying model powered the agents, but the data reportedly showed the model's safeguards had been sidestepped by presenting the intrusion as an authorized penetration test rather than a real attack. Of particular concern is that the toolkit for the hack comprised such easily available systems, neither of which was purpose-built for offense. The operators appear to have assembled a capable autonomous tool out of components any developer can pull down and run. What the researchers describe as the tool's most striking feature was its ability to continuously devise attacks on its own, rather than follow a preprogrammed route. The platform continuously assessed available evidence, ranked possible attack paths, and reprioritized them as circumstances changed. When one technique failed, the tool tasked another agent with searching the internet for information and developing an alternative approach.

Read more of this story at Slashdot.

  •  

What’s the most frustrating part of using your CRM every day?

I'm doing some research into how people actually use CRMs day-to-day, and I'd love to hear from people who work with them regularly.

I'm especially interested in the gap between what a CRM can do and what people actually end up doing manually.

For those of you using a CRM:

  • What's the most frustrating part of your current workflow?
  • Do you frequently have to jump between multiple tools to complete one task?
  • What customer information is hardest to get a complete picture of?
  • What's one thing you wish your CRM could just handle automatically?
  • If your CRM had an AI assistant, what would you actually trust it to do?

I'm trying to understand real workflows rather than just compare CRM feature lists.

If you're willing to share your experience, I'd really appreciate it. I also have a short research survey for anyone who'd prefer to answer anonymously.

submitted by /u/Simple-Mix163
[link] [comments]
  •  

Introducing Site Doctor

"...We spent three weeks trying to fix a problem with the checkout process.

An online store. Payments were failing on the first attempt. Credit card fields weren't displaying correctly on mobile devices. The client was losing sales daily, and no one knew why.

So, we did what everyone does: we swapped out the payment plugin. Then we swapped it again. We ran a full security scan with Wordfence Premium—nothing detected. We tweaked the reCAPTCHA. We cleared the cache, tested across different browsers, disabled features one by one, and combed through the payment gateway logs line by line.

Each fix worked for a moment. Then, the problem would return.

Three weeks. Neither the client nor we had the slightest clue what was going on.

Only then did we hear about Site Doctor and decide to give it a try.

It turned out to be a credit card-stealing script. It was injected into the checkout process, hidden inside a legitimate snippet of code the team had written weeks earlier. The payload was Base64-encoded and stored in a variable named to mimic a reCAPTCHA license key—with a typo so subtle that it looked like "recaptcha" and was simply overlooked. It only executed on the checkout page, so all the tests we ran elsewhere came back clean.

It had been stealing data from that store the whole time we were blaming the payment gateway, the cache, and the browser.

From the moment we ran the scan to the moment the site was fixed: about an hour.

Three weeks of guesswork. One hour once we could see what was happening under the hood. ... So thanks SYSWP and thanks Site Doctor... we use it on all our projects now...."

That’s why this tool exists.

Site Doctor monitors all the WordPress sites we manage… (continue with what it does / doesn't do / beta / DM — the rest is the same as before)

https://sitedoctor.syswp.pro is currently in beta; fill out the form if you’d like to try it. We are not selling nothing is just a Tool MCP that you can use for free

#WordPress #WebAgency #WordPressSecurity #WooCommerce

submitted by /u/aporce123
[link] [comments]
  •  

Everyone's arguing auto-updates on vs off. The thing that actually got people this month was the update itself

https://preview.redd.it/krk2vsiajzih1.png?width=1762&format=png&auto=webp&s=379a2494f2b3d48cad954ad9e1b770de023c1f6e

The 7.0.x releases have restarted the oldest argument in this sub. Auto-updates on, because a patched hole beats a broken layout. Auto-updates off, because you don't push untested code to production at 4am. Both camps have been making the same case for a decade, and both are working from an assumption I think is the actual problem.

Both assume the update itself is safe.

The case for patching fast is strong and I'm not arguing against it. Patchstack's State of WordPress Security in 2026 puts the weighted median time from disclosure to first exploitation at five hours, across 11,334 vulnerabilities disclosed in 2025, 91% of them in plugins. If you're patching on a weekly review cycle you are losing that race, every time, and the 4am-broken-layout crowd is trading a rare outage for a common breach.

Here's the number from that same report that nobody quotes though. 46% of those vulnerabilities had no patch available at the moment they were disclosed. Patchstack's own conclusion is that this "shows why website owners can't rely on plugin updates as a security measure." Their words, not mine.

But look at what the update actually is. Your site fetches a package from a vendor's server, unpacks it, and executes it. That's a write path the site trusts by design. There's no authentication event anywhere in that chain to harden and no second opinion on what arrived. 2FA, lockouts, a firewall sitting in front of the login page, none of them are in that request path at all.

That's not hypothetical this month. An agency posted a writeup here on the 3rd describing their plugin vendor's update server being compromised and a backdoor landing on client sites through a routine update. Someone in another thread described a window in early August where pressing update in wp-admin could hand you a tampered package. Both are those posters' accounts and neither is independently verified, so treat the specifics as claims. The shape is what I'm interested in.

So my position is that both sides of the argument are defending the wrong door. The useful question isn't auto or manual. It's how you'd know.

There is a partial answer built into WP-CLI that hardly anyone runs. wp plugin verify-checksums compares the plugin files on your site against the checksums wordpress org publishes for that version. If a file changed after install, it says so.

Then you hit the part that matters here. It only works for plugins from the repo. Point it at a premium plugin and you get "could not retrieve the checksums, skipping," because there is no published source of truth to compare against. The vendor ships the package themselves.

So the one integrity check built into the tooling covers everything except the category where vendor-delivered tampering actually happens. In the ShapedPlugin case reported in June, the backdoor went into the Pro builds on 21 May and the first customer reports landed on 10 June. Twenty days, three paid plugins, delivered through the vendor's own update system. That timeline is from Wordfence's data as reported at the time, not something I measured.

Which brings me to the part I don't have a good answer for, and the reason I'm posting.

If a plugin update you installed last month had been tampered with in transit, how would you find out? Not in theory. What in your current setup would actually tell you?

submitted by /u/Capital_Attention702
[link] [comments]
  •  

Why your security plugin shows "blocked attacks" for plugins you never installed

This comes up every few weeks, and the answer never seems to be wherever people go looking for it. So, here.

You open your firewall summary and find something like:

Blocked for [Plugin Name] <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API in query string: rest_route = /[plugin-slug]/v1/tests/mock-data 

You have never installed that plugin. It isn't in your plugins folder, it isn't sitting there deactivated, it was never there at all. Two things are getting confused here, and separating them makes the whole thing boring, which is the correct outcome.

The request is generic. WordPress serves REST routes at /wp-json/..., and it also accepts ?rest_route=... as a query-string fallback so the API still works when pretty permalinks are off. That fallback resolves on every WordPress install. So a bot needs to know nothing about your site to try it. It takes a list of recently disclosed plugin vulnerabilities, builds the request for each one, and fires the whole list at every WordPress site it can find. The sites running that plugin answer with something useful. The rest return nothing, because the route was never registered.

The block is a pattern match, not a detection. Your firewall recognized the shape of the request and stopped it before WordPress got a chance to shrug at it. That's why the log names a plugin and a version range: it's describing the exploit the request was written for, not something it found on your site. The phrasing makes it read like you were targeted and narrowly got away with it. You weren't, and there was nothing to get away from.

So: nothing is installed that shouldn't be, there's nothing to clean up, and it isn't related to some other plugin of yours with a similar name.

What the alert does tell you is that your site is on somebody's list. About 91% of last year's disclosed WordPress vulnerabilities were in plugins rather than core, per Patchstack's 2026 report, so those lists are long and they get worked constantly. Being on one only means your site answered a WordPress fingerprint check at some point.

If you'd rather be on fewer of them, look at what an anonymous request can learn about your install. Version strings hanging off your CSS and JS URLs. Readme files sitting under plugin directories. Directory listings nobody turned off. None of that is secret and none of it is why anyone gets hacked. It's just what makes a site cheap to sort into "worth coming back to" rather than "no idea what this is."

submitted by /u/Capital_Attention702
[link] [comments]
  •  

DEF CON Crowd Suspected In Fake-Hotspot Attack On Delta Flight

An anonymous reader quotes a report from Ars Technica: On Monday, passengers aboard Delta flight 591 going from Las Vegas to Atlanta allegedly spoofed the onboard Wi-Fi, raising the attention of federal law enforcement. The incident came one day after the DEF CON security conference concluded in Las Vegas, and was first described on social media accounts that follow publicly available air-to-ground messages, known as ACARS. According to the "ACARS Drama" account, a message was sent by pilots from the plane stated: "NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL." A description of the incident posted to Reddit further stated that these passengers created a fake hotspot ("Delta WiFi Fast"), with a phishing landing page "designed to harvest passengers' personal credentials." This technique, sometimes known as an "evil twin" attack, has been long-known to the IT security community. It involves setting up a fake Wi-Fi network and then capturing login credentials and other data. "One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight," said a Delta spokesperson. Delta further noted that the flight's safety was "never in question and no aircraft operating systems were affected," and that no emergency was declared. Ars notes that the "actual onboard Wi-Fi was disabled for 30 minutes."

Read more of this story at Slashdot.

  •  

Bulk update multi-select field selections

We have a content type with a multi-select field with (let's say) options A, B, C, D. A ton of nodes already have the field populated with content. We need to add an option E, and would like to have it selected if B is also already selected.

Is Views Bulk Operations with Views Bulk Edit our best (or only) option?

submitted by /u/dressed_to_the_left
[link] [comments]
  •  

The Pixel Tag Is Google's Answer To the AirTag

Google has unveiled the $29 Pixel Tag, its long-awaited AirTag rival that combines UWB with Bluetooth 6.0 Channel Sounding for two forms of precision tracking. It launches November 11. The Verge reports: The Pixel Tag is a slim oblong device available in one grayish color -- Fog -- that weighs about 12g, or 0.4oz. Like the AirTag, it has no built-in hooks or clips for attaching to objects you want to track. There's a single button that will trigger a sound on your phone, for the rare occasion when you've got the Tag but have lost your main device. It also has an IP67 rating, so it should be safe from dust and rain. As for the battery, the Pixel Tag takes CR2032 coin batteries, and says one battery should last for over a year. Naturally, it'll be compatible with Google's Find Hub network, which leverages the Bluetooth capabilities of Android devices worldwide to help locate lost objects. [...] Once you're close enough to the Pixel Tag, UWB lets the Find Hub app display the distance and direction to the tracker, so long as you're using a phone with a UWB chip. Channel Sounding is a newer development that can display the exact distance, but not direction, and it will work with any phone or tablet that includes Bluetooth 6.0. The Moto Tag 2 is the only other tracker to currently support it.

Read more of this story at Slashdot.

  •  

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and

  •  
❌