We are a collective of digital rights advocates, security experts, and educators committed to empowering individuals and communities with the knowledge and tools to protect their digital freedoms.
How we work to protect digital rights and empower communities
Raising awareness about digital rights, privacy threats, and security best practices.
Advocating for policies and regulations that protect digital rights and freedoms.
Providing training and resources on digital security for vulnerable groups.
Offering direct assistance to individuals and organizations facing digital threats.
Creating networks of digital rights defenders to share knowledge and resources.
Working with partners globally to develop solutions to digital security challenges.
Latest WordPress security vulnerabilities affecting plugins, themes, and core.
Published Date: Apr 2, 2026
The Webmention plugin for WordPress is susceptible to a Server-Side Request Forgery (SSRF) vulnerability in versions up to and including 5.6.2. This flaw allows attackers to send unauthorized requests from the web application, potentially exposing internal service data or altering configuration.
Published Date: Apr 2, 2026
The Webmention plugin for WordPress is affected by a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows authenticated users with Subscriber-level access and above to make requests to arbitrary servers from the web application, enabling potential discovery and modification of internal resources.
Published Date: Apr 2, 2026
The Spam Protect for Contact Form 7 plugin prior to version 1.2.10 contains a vulnerability that permits logging to a PHP file. This vulnerability enables an attacker with editor-level access to potentially execute arbitrary code remotely by manipulating crafted HTTP headers.
Stay informed about the latest digital rights issues, threats, and community resources
Recently, Cloudflare unveiled EmDash, the innovative step forward in WordPress security introduced by two cybersecurity experts coincidentally named Matt. EmDash is heralded as a revolutionary platform designed to address the persistent security challenges associated with WordPress plugins. For years, WordPress, while being one of the most popular content management systems, has struggled with vulnerabilities stemming from third-party plugins. These vulnerabilities often serve as gateways for cyber threats that can compromise websites. EmDash aims to tackle this issue by offering a robust architectural redesign that inherently incorporates stricter security protocols, limiting the potential for exploitation. The unveiling of EmDash holds promise for website owners who have long been concerned about the security risks posed by traditional WordPress setups. By integrating advanced threat detection and mitigation measures, EmDash provides an elevated level of protection that extends beyond traditional security plugins whose efficacy has sometimes been inconsistent. As Cloudflare ventures into this territory, it's clear that enhancing the CMS infrastructure itself could be more beneficial than retroactive security measures, proposing a proactive approach to safeguarding digital content. This announcement is particularly timely given the increasing sophistication of cyber-attacks targeting CMS platforms. With EmDash, Cloudflare seems committed to not just provide a spiritual successor to WordPress but a robust, secure foundation that potentially sets a new standard in content management security. The introduction of EmDash could symbolize not just an upgrade in CMS technology but a shift towards prioritizing security at the core of digital publishing.

In a development that has cast a spotlight on the complexities of international cyber-espionage, the FBI has classified a suspected incursion by Chinese hackers into a U.S. government surveillance system as a 'major incident'. This event underscores the evolving landscape of cyber threats, where sophisticated attacks not only breach organizational data but also pose substantial threats to national security platforms. According to sources within U.S. law enforcement and individuals familiar with the investigation, the intrusion has compromised sensitive law enforcement information, raising alarms about the potential exposure of critical data that could be leveraged for strategic gain by nation-state actors. This breach is part of a broader pattern attributed to China, known for deploying advanced persistent threats targeting various sectors, from critical infrastructure to emerging technologies. The magnitude of this breach reflects the challenges faced by national security defenses in counteracting state-sponsored cyber capabilities, calling for heightened vigilance and improved cyber defenses across various government and private entities. The attack's implications are far-reaching, potentially disrupting intelligence operations and risking the exposure of data integral to national security. Organizations globally are reminded of the critical need to maintain robust cybersecurity measures, continually evolving their defenses against increasingly sophisticated cyber threats that transcend geographical boundaries.

In a striking incident that underscores how personal habits can lead to vulnerabilities in digital security, FBI Director Kash Patel became a victim of a cyberattack that took advantage of his apparent tradition of using a university-linked username. Patel, who attended a Virginia-based college, reportedly carried over his school spirit into his digital life by using a consistent username across multiple platforms. This choice seemed innocuous but ultimately rendered him susceptible to a targeted hack on his private email address. The incident serves as a stark reminder of the risks associated with uniform usernames that tie back to personal information. As hackers gain access to more databases, they can pull together bits of personal information to conduct spear phishing or other targeted attacks. For anyone using a recognizable pattern in digital handles, this hack serves as a cautionary tale. It highlights the importance of employing strong, varied usernames and passwords and the value of two-factor authentication to safeguard personal and professional data. This breach also raises concerns about the security practices of high-profile individuals who may carry sensitive information vulnerable to hacking. Digital security experts emphasize the necessity of reviewing one's digital footprint and ensuring that current security measures are robust enough to prevent unauthorized access.
Join us in defending digital rights and protecting vulnerable communities.
Get in touch to discuss your needs or how you can support our mission
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.