WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review
WordPress.org now runs AI-powered automated security reviews on every plugin release, automatically blocking high-risk updates before distribution to millions of sites.
WordPress launched an automated security review that combines multiple AI models and Jetpack Scan during a six-hour cooldown to score each plugin release; updates above the blocking threshold are automatically held back from the WordPress.org update API. The change follows a July 28 incident where a backdoor added to a plugin with roughly 20,000 active installations was detected during cooldown and never delivered; the Plugins Team removed it 26 minutes after a Wordfence notification. Blocked developers receive an email with findings and are advised to publish a corrected version rather than await manual appeal.
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
WordPress will automatically scan every plugin release and block high-risk updates from distribution using AI analysis plus Jetpack Scan.
WordPress announced automated security reviews for every plugin release during its cooldown period before distribution through the WordPress.org update API, combining AI models with Jetpack Scan into a security score. The system already caught a backdoor committed to a plugin with about 20,000 active installations on July 28, 2026, blocking it within 26 minutes of a Wordfence alert. Flagged patterns include missing capability checks, unsafe $wpdb queries, unserialize() on request data, and obfuscated code.
Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates
ANY.RUN August release adds TI Lookup connections view, 81 behavior signatures, 16 YARA rules, 559 Suricata rules, and three new threat intelligence reports.
ANY.RUN released August product updates expanding its Threat Intelligence Lookup with a Connections block for pivoting between related observables (domains, IPs, URLs), JSON export for retrohunting and SIEM/NDR integration, and hidden whitelisted data by default. Detection coverage grew with 81 new behavior signatures, 16 YARA rules, and 559 Suricata rules covering malware execution, phishing, and C2 traffic. Three new Threat Intelligence Reports cover a US-focused RMM phishing campaign across 46 countries, the Mirage2FA phishing-as-a-service targeting Microsoft 365 (1,249 sandbox sessions, 9,332 potential compromise events), and a threat brief on OVERLORD RAT, CRPX0, and TRIBACK loader.
Update modules/auxiliary/scanner/http/elasticsearch_tika_xfa_xxe.rb
Rapid7 updated a Metasploit auxiliary scanner module that detects XML external entity injection in Elasticsearch via Apache Tika.
A commit in the Metasploit Framework updated modules/auxiliary/scanner/http/elasticsearch_tika_xfa_xxe.rb, an auxiliary scanner module. The module targets XML external entity (XXE) injection in Elasticsearch through Apache Tika, and was co-authored by jheysel-r7. The terse commit message contains no additional details, CVE references, or exploitation notes.
automatic module_metadata_base.json update
Automated Metasploit Framework commit updating module_metadata_base.json to reflect newly added or modified exploit modules.
An automated commit updated module_metadata_base.json in the rapid7/metasploit-framework repository. The routine maintenance change reflects newly added or modified Metasploit modules and carries no standalone security significance.
automatic module_metadata_base.json update
Metasploit Framework automatically updates its module metadata JSON in routine maintenance commit.
The Metasploit Framework repository received an automatic update to module_metadata_base.json, the metadata file that tracks module information. No specific new vulnerability, exploit module, or feature is described in the commit message. This is routine repository maintenance rather than a notable security event.
automatic module_metadata_base.json update
Routine automated Metasploit Framework commit updates module_metadata_base.json with new module metadata.
The Metasploit Framework repository received an automated commit updating module_metadata_base.json, the file that tracks module metadata for the framework. This is routine maintenance accompanying new or updated exploit modules rather than a standalone disclosure. No vulnerability details, CVEs, or exploitation evidence are included.
automatic module_metadata_base.json update
Metasploit Framework pushed an automated update to its module_metadata_base.json module metadata file.
This repository commit is an automated update to the Metasploit Framework's module_metadata_base.json file. No new modules, vulnerabilities or exploit changes are described in the commit message.
automatic module_metadata_base.json update
Routine automated Metasploit Framework commit updating module metadata, with no disclosed vulnerability or exploitation activity.
The Metasploit Framework repository received an automatic update to its module_metadata_base.json file. The commit text contains no vulnerability details, CVE references, or new exploit modules. This is routine maintenance activity on the open-source penetration testing framework.
HHS Releases Updated Security Risk Assessment Tool
HHS OCR and ONC released version 3.7 of the Security Risk Assessment Tool for healthcare organizations.
The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator for Health IT (ONC) released version 3.7 of the Security Risk Assessment (SRA) Tool. The tool helps covered entities conduct HIPAA security risk assessments. ONC and OCR provided guidance on the updates.
automatic module_metadata_base.json update
Metasploit Framework's automated pipeline refreshed its module metadata file, a routine repository maintenance commit introducing no new modules or exploits.
An automated Metasploit Framework commit updated module_metadata_base.json, the metadata database consumed by module tooling. The change is routine maintenance and contains no new exploit modules or vulnerability content.
automatic module_metadata_base.json update
Automated Metasploit Framework commit refreshes module_metadata_base.json with no new exploit content or vulnerability details.
An automated commit updated module_metadata_base.json in the Rapid7 Metasploit Framework repository. The change reflects routine metadata maintenance and introduces no new modules, exploits, or vulnerability information.
Huntress API Update: New Endpoints, Webhooks, and Automation
Huntress expanded its API from six read-only endpoints into an automation platform adding webhooks and Model Context Protocol support.
Huntress announced a major expansion of its API, growing from six read-only endpoints into a full integration and automation platform. New capabilities include webhook support, additional endpoints, and MCP (Model Context Protocol) support to enable AI-assisted automation. The update targets defenders building integrations and automated workflows around the Huntress managed detection and response platform.