Predictions about technology and trends emerge year-round, but many can be trivial or obvious, lacking real insight or originality. But there are the golden nuggets.
Predictions about technology and trends emerge year-round, but many can be trivial or obvious, lacking real insight or originality. But there are the golden nuggets.
Bob Dunn shares his perspective on open source and the web in the first (official) solo episode of Open Signal.
A new weekly show focused on commentary and observations about the open source and open web community.

At the beginning of President Donald Trump’s second term, 1.3 million individuals from 17 countries were living and working in the U.S. under Temporary Protected Status, or TPS.
TPS is a humanitarian form of protection from deportation for people who cannot return to their home countries because of an armed conflict, environmental disaster or other extraordinary circumstances.
In 2025, the Trump administration began terminating or not renewing TPS for those countries, making its way through 13 of them. As the administration turns its attention to the few remaining nations, most TPS holders have lost or will soon lose their protection from deportation and their authorization to work. Many will be separated from their families and the communities they have lived in for decades. Some will be forced to return to countries like Afghanistan, Haiti and Syria, all of which are on the U.S. State Department’s “Do Not Travel” list due to war, terrorism or other extreme violence.
As a law scholar who studies immigration detention, I can say that most people with TPS never had a path to anything more permanent, which means, as they face deportation, they have little recourse.
In the fall of 2025, the Trump White House announced that it would not renew Syrian or Haitian TPS; Syria’s would expire in 60 days, Haiti’s in February 2026. Lower courts blocked both terminations, triggering appeals that took the cases to the Supreme Court.
In June 2026, in Mullin v. Doe, the Supreme Court ruled that federal courts cannot review most challenges to a TPS termination because, in the original 1990 law creating TPS, Congress barred judicial review of the decision to give a country TPS – or extend or end it.
James Percival, the general counsel of the Department of Homeland Security, celebrated the decision, saying “Temporary Protected Status was always supposed to be temporary and can be canceled at the appropriate time.”
But the ruling means no court can consider whether a cancellation is, in fact, “appropriate,” or whether it follows the law.

When Congress passed TPS as part of the Immigration Act of 1990, it was responding to a specific failure: the ad hoc and inconsistent use of something called Extended Voluntary Departure, which permitted a noncitizen to remain in the U.S. regardless of their immigration status.
That discretionary relief allowed some displaced Salvadorans to remain in the U.S. during their country’s civil war in the 1980s, but its application was arbitrary and often discriminatory. Because the U.S. backed the Salvadoran government, Salvadorans were denied both Extended Voluntary Departure and asylum more than 90% of the time – not for lack of merit but because of the government they were fleeing.
Congress recognized a humanitarian need for more uniform protection for people who, like Salvadorans, faced a return to violence or extreme danger but were not covered by narrow asylum laws that require proof of targeted persecution.
A new protected status would “standardize the procedure for granting temporary stays of deportation,” Representative Sander Levin explained at the time.
“Refugees, spawned by the sad and tragic forces of warfare, should not be subject to the vagaries of our domestic politics as well,” Levin added. When the 1990 Immigration Act passed, El Salvador was the first country designated for TPS.
Congress avoided placing time limits on these new TPS designations, leaving that to the discretion of the presidential administration, which would evaluate a country’s humanitarian needs at least every 18 months. Whether TPS holders should ever gain something more permanent was left for future congressional action.
Not every person from a TPS-designated country is eligible for it. Anything that disqualifies someone from asylum – national security concerns, persecuting others or criminal history – also disqualifies them from TPS.
Congress did not want to incentivize unlawful immigration. For that reason, it wrote the law in such a way that TPS itself could not lead to permanent residence. Lawful permanent residents are eligible to become citizens after five years. TPS recipients, though living in the U.S. lawfully, are not classified as lawful permanent residents.
Congress has since passed laws creating a pathway to permanent residence for certain nationalities, including some with TPS – the Nicaraguan Adjustment and Central American Relief Act, for example. It did not do so for most.
TPS designations for some countries have ended after a few years, like Rwanda and Guinea; others have been renewed for decades, like El Salvador, Honduras and Nicaragua. Over the years, TPS became a kind of limbo status, dependent on each presidential administration’s regular evaluation of a country’s humanitarian conditions – and on Congress to turn TPS into a pathway to lawful permanent residence. For most, the latter never happened.

Many people who lose TPS are not eligible for any other immigration status.
Lawful permanent residence, commonly known as a “green card,” is mainly available in three ways: through a close family relationship, like being married to a U.S. citizen or lawful permanent resident; through a job that requires special skills, like being a professional soccer player; or through asylum status.
Even if a person can apply for permanent residence, their immigration history, such as entering the U.S. without a visa or remaining in the U.S. without lawful status for a certain time, may be a permanent barrier.
TPS holders are given at least 60 days’ notice before termination takes effect, at which point they lose authorization to work and become undocumented, meaning they can be arrested by immigration officers at any time. There is little they can do in those 60 days that would allow them to lawfully remain in the U.S.
A TPS holder who has been continuously present in the U.S. for more than two years has a right to an immigration hearing before removal, where they may be able to apply for asylum or other relief. Others may hope to switch to a different status, but most TPS holders cannot obtain a student or employment visa. Some would have to apply from outside the U.S., some face years of quota backlogs, and some are from countries under a travel ban.
Past immigration violations or insufficient financial resources would also disqualify them. Most significantly, TPS holders are unlikely to convince an immigration officer that they intend to return home after their visa’s purpose is complete, as most visas require – especially someone from a country in distress due to violence or environmental disaster, the reason they have TPS in the first place.
Some 300,000 people from El Salvador, Sudan, Ukraine and Lebanon are set to lose status this year. Ukraine and Lebanon are in active war, so terminating TPS means deporting those people to war zones, which is what TPS was meant to prevent. Some TPS holders from El Salvador and Sudan have lived in the U.S. for more than 20 years.
Perhaps the 1990 Congress did not anticipate that individuals with TPS would make the U.S. their home for so long. Whatever it envisioned, it did not limit TPS to a fixed time. In my analysis, Percival’s assertion that TPS was always meant to be temporary is not, by itself, an “appropriate” reason to end protection.
As Justice Elena Kagan stated in her dissent to the recent Supreme Court ruling, even if TPS does not promise “never-ending humanitarian protection,” the end of it for certain individuals – like the plaintiffs in Mullin v. Doe – could deliver them to “devastating, and indeed life-threatening, injury.”
![]()
Jean Lantz Reisz is affiliated with the USC Gould School of Law Immigration Clinic.
Politics + Society – The Conversation
bbPress 2.6.15 is a security and maintenance release that fixes five security issues and includes a few compatibility improvements. Everyone running bbPress should update as soon as possible. 
This release strengthens authorization around topic and reply editing, topic splitting and merging, user profile updates, and private or hidden forum visibility. It also hardens imported password verification, avoids PHP warnings on some forum requests, and improves compatibility with modern WordPress UTF-8 handling.
All of these fixes have already been merged into the 2.7 development branch.
Thank you to mickey_cyberkid, itznullbyte, eldoniis, and tristaninsec for reporting issues through HackerOne, and to Ananda Dhakal at Patchstack for reporting CVE-2026-74010. Thank you for helping keep bbPress communities safe! 
Download bbPress 2.6.15 from WordPress.org, or update directly from your WordPress dashboard.

For much of the past 25 years, each anniversary of the Sept. 11 attacks has arrived with signs and stickers reminding people to “never forget.”
I have always felt unsure about what those words mean. For those of us who were alive in 2001, forgetting the day itself is almost impossible.
I remember the shock and fear, the replays of the second plane hitting the World Trade Center, and the moment the second tower fell. I remember seeing on television the missing-person photographs that covered New York and the awful recognition that very few of those people were likely to be found alive. I remember the bravery of the New York firefighters and police.
My college students have no such memories or feelings. Most were born years after Sept. 11, 2001.
They encounter what happened through photographs, documentaries, memorials, classroom lessons and stories told by people who were alive on that day. The National September 11 Memorial & Museum estimates that about 100 million Americans have been born since the attacks.
The shift is ordinary and still somehow startling. An event that once felt like it had split time into a permanent before and after is fading into history itself.
In my work as a professor of politics and public affairs, I pay close attention to the stories Americans tell about their past and the ways those stories shape civic identity in the present. The 25th anniversary of 9/11 is especially interesting to me because it marks a moment when an event once experienced as immediate and world-changing is increasingly being carried forward through memory, ritual and interpretation.

Scholars of collective memory, also called public memory, have long argued that societies do not remember the past simply by preserving it.
Public memory describes how collective meaning gets made and remade through stories, institutions, rituals and political arguments. For example, the Department of Homeland Security was created in response to 9/11. Many Americans understand DHS as a structural and cultural reform made to fix the intelligence failures that the attacks made evident.
Forgetting is part of the process, too. As memory scholar Paul Connerton has argued, some forms of forgetting are not failures but necessary parts of social life.
No individual, school or nation can keep everything equally present forever. History accumulates faster than collective memory can accommodate it. The question, then, is not whether Americans will forget parts of 9/11. They will. The more interesting question is what remains after that forgetting takes place.
From the first anniversary, commemorating the attacks has carried a careful choreography. There is the annual reading of the names of those who died, the memorial lights and the stories of first responders, each of which keeps the human loss and courage of the day in view.
In a 2016 Pew Research Center survey, 76% of Americans named 9/11 as one of the 10 most consequential events of their lifetimes. Nearly 1 in 5 said the nation’s immediate response to the attacks was the moment when they felt most proud of the United States.
I understand those points of view. Some of what I most want preserved about Sept. 11 is the shared grief of those first days and the ways ordinary people revealed their humanity under unimaginable circumstances.
Firefighters climbed stairs and ran toward mortal danger, while a cascade of people tried as hard as they could to get down. Office workers helped colleagues and strangers. Families searched for missing loved ones long after hope had become terribly thin. And passengers on United Flight 93 fought back and forced the plane they were on to crash in a field in the middle of Philadelphia, sacrificing themselves in the hopes of saving others.
Before 9/11 became a justification, a policy, a war or a political symbol, it was an experience of shared human vulnerability.
No event remains sealed inside its original meaning. Sept. 11 became the starting point for a series of political choices that reshaped American life and, in turn, reshaped the memory of the day itself.
The attacks led to the war in Afghanistan, which lasted for 20 years after the invasion’s initial success in dismantling al-Qaida and removing the Taliban government.
Next was the invasion of Iraq, even though Saddam Hussein’s regime had no role in 9/11.
And the aftermath of the attacks helped create an atmosphere that allowed for expanding government surveillance, enlarging presidential power and narrowing the space for dissent. Muslim Americans found themselves subjected to new suspicion and hostility.
Those consequences now compete with the original experience of Sept. 11 for a place in its meaning.
For some Americans, the attacks have become inseparable from the wars and broader official willingness to sacrifice civil liberties in the name of security that followed. From this perspective, 9/11 is remembered not only as a national trauma but also as a warning about how fear and grief can make policies that once seemed unthinkable appear necessary.
For others, the day – and its aftermath – represent restored American pride and military perseverance.
For still others, 9/11 remains most powerfully a story about innocent lives lost and ordinary people behaving with extraordinary courage.
Each way of remembering draws a boundary around the terrorism the nation experienced, deciding how far beyond that September morning its meaning should extend.
Even events once regarded as world-defining eventually have to share the historical landscape with everything that follows. Since 2001, Americans have experienced Hurricane Katrina, the 2008 financial crisis, the election of the first Black president, the rise of Donald Trump, the violence on Jan. 6, 2021, and a global pandemic.
Sept. 11 has not become unimportant because those things happened. Its place in the story has changed because life – because the world – kept going.
For people who were alive during the attacks, there is something sad about watching that distance and diminishment happen. When an event once remembered in minute detail becomes a date others know only from history, the passage of one’s own life becomes newly visible. There is a strange nostalgia in realizing that something once so immediate now belongs increasingly to people who know it only as the past.

Maybe this is why “never forget” feels both moving and impossible.
What is supposed to be the subject of our remembering? The people who died? The courage? The grief? The fear? The wars that followed? The mistakes? The unexpected decency of people thrown together on an unbearable day?
A society cannot keep all of those things equally vivid forever. Nor should its members confuse remembering everything with understanding anything. The task of collective memory is inevitably one of selection.
For me, one part of the memory seems especially important to preserve. Before Sept. 11 became an argument about war, security, patriotism or political allegiance, it was an encounter with human vulnerability and then human resilience. The solidarity of Sept. 11 and the political choices made in its aftermath were not the same thing, even if they have become intertwined in our memory of the period.
If the ongoing march of history means Sept. 11 cannot always carry the emotional weight it does for people who were alive when it happened, perhaps the best outcome would be to focus on the collective grief, along with the extraordinary human response that grief engendered.
Doing so would not erase any of what followed. But it might help preserve the understanding that the day was one of imaginable horror and tragedy before it became a political inheritance.
![]()
Stephanie A. (Sam) Martin does not work for, consult, own shares in or receive funding from any company or organization that would benefit from this article, and has disclosed no relevant affiliations beyond their academic appointment.
Politics + Society – The Conversation
Examining the impact of AI on podcast content, marketing, and the value of real human voices.

The Democratic Party’s coalition headed into the 2026 midterms is as broad as it’s been in years. That seems likely to help them pick up dozens of seats in Congress and win majorities back from Republicans in either or both chambers.
One notable and attention-getting portion of that coalition is a group of progressive political newcomers who affiliate with the Democratic Socialists of America, or DSA. This growing left-wing organization had a hand in the 2025 election of New York City Mayor Zohran Mamdani and has high-profile allies in Congress, including U.S. Rep. Alexandria Ocasio-Cortez, a New York Democrat, and U.S. Sen. Bernie Sanders, the independent from Vermont.
In the 2026 election cycle, DSA-affiliated candidates have won a handful of Democratic primaries. Most did so in districts that Democrats are very likely to win in November. As a result, at least a half-dozen DSA-affiliated candidates are all but guaranteed a seat in the next Congress.
But history tells us that a “big tent” party is also likely to face big divisions and even bigger challenges when putting together a governing coalition in Congress. Depending on the size of the Democrats’ possible majorities, the DSA-affiliated lawmakers’ reach and power, despite their small numbers, could extend beyond elections and deep into the process of legislating.

Before any policy can even be debated, Congress has to elect its leadership. In the Senate, the party with the most seats selects the “majority leader” and the other party the “minority leader.” This vote is fully internal to each party: Democratic senators will vote on their leader and Republicans on theirs. But in the House, this vote is on full display. Per the Constitution, the full House must select the speaker of the House. Because only a simple majority is required to win, the majority party typically dominates the speaker selection process.
While these processes seem simple on paper, they may be a hurdle for relatively unpopular Democratic leaders facing an ideologically divided caucus and slim margins of control. This is particularly true in the House, where a public, on-the-record roll call vote may pressure some members to rebel against the Democrats’ current House minority leader, Hakeem Jeffries of New York, who is largely presumed to be the next Democratic speaker.
For evidence of this potential, look no further than the 118th Congress: Following the election of a new Republican majority in 2023, then-leader Kevin McCarthy, a California Republican, faced a grueling 15 rounds of ballots before finally being elected speaker. The culprit? The ideologically extreme, far-right members of the Republican Party that didn’t want to support him.
Who the speaker is, and to whom they are beholden in their caucus, matters greatly for the policy goals of the upcoming 120th Congress.
The speaker controls House floor proceedings, shepherding legislation to the floor or preventing it from ever seeing a vote. They also head the steering committee, which determines committee assignments, manages a large and powerful staff, and controls the messaging of constituent communication.
For a speaker faced with managing an ideologically diverse coalition, these procedural advantages can be tools to protect their party from tough votes or, perhaps, to appease ideological extremists.
But as leaders of both their party and the entire chamber, balancing the demands of partisan peers can come into conflict with the necessities of lawmaking.
For instance, despite making policy and procedural deals with conservative members in his leadership bid, Speaker McCarthy was ultimately removed from office by his own party less than 10 months later for the transgression of compromising with moderate Democratic members to prevent a government shutdown.
While compromise may be necessary for a functioning government, it’s also antithetical to the goals of the conservative movement.
The man who took over the GOP leader’s job, current Speaker Mike Johnson of Louisiana, appears to have learned from this lesson: In the 119th Congress, his leadership has been defined by his deference to President Donald Trump and party conservatives, rather than trying to find the moderate middle between the two parties.
As Democratic leaders look to the upcoming 120th Congress, this same policymaking challenge will likely await them as well, regardless of which Democrat wins control of the speaker’s gavel.
Yet ideological alignment alone is not enough to accelerate chamber action. Key to the success of any group seeking power in Congress is the size of its party’s advantage over the minority and the ability of ideological groups to organize.
That’s because narrow margins between the two parties force the majority’s leaders to pay attention to the demands of every member of their caucus in any effort to pass legislation.
Large majorities, meanwhile, can allow errant members to wander, with little risk to the majority party’s policy goals. And in 2026, with the median prediction in some models giving Democrats control of the House by as many as 30 seats, the half-dozen or so DSA-affiliated members may not always be essential to passing legislation.
Yet margin size alone does not guarantee clout. Groups must also be organized and cohesive.
In order for any ideological group to have a say in policymaking, it must not only be unified in policy goals but prepared to act as a voting bloc in the face of leadership. A potential DSA insurgency could take heed of the lessons of the conservative – and effective – Freedom Caucus before it, just one recent example from a long history of ideological rebellions in Congress.
But when ideological groups are disorganized, they don’t have much power to influence policy. So the ample resources and processes available to party leaders present an opportunity for the leader-driven lawmaking that has defined much of the modern congressional era.
Even the most organized, ideologically driven coalitions face a few underlying realities of lawmaking that political science tells us remain true.
For one thing, despite its reported demise as a victim of polarization and more recent bare-knuckle partisanship, bipartisanship still produces many significant legislative agreements in Congress. The 21st Century Road to Housing Act to increase access to affordable housing, the CHIPS and Science Act to encourage domestic technological development, and the First Step Act to reduce rising prison populations are recent examples of major bipartisanship policy solutions. And research has shown that members who attract more bipartisan co-sponsors tend to be more successful legislators.
Furthermore, most of these likely-to-be-elected DSA members are either political newcomers or have been successful only outside of the traditional Democratic establishment. This may have been a selling point in their primary campaigns, but these new members’ lack of experience and lack of experienced staff could limit their ability to maneuver in a Congress that even today is heavily structured by rules and norms, many of which are dictated by party leadership.
Leadership also has key institutional advantages that even the most fiery new members of Congress may find themselves unable to overcome.
Evidence since the 1970s demonstrates the deteriorating lawmaking capacity of individual members, particularly compared to party leaders. That makes it difficult for any member of Congress – particularly new, inexperienced members – to direct floor activity or get consideration of their biggest policy priorities.
DSA-affiliated members may be able to enhance their power by forming coalitions with other younger, establishment-skeptical new members, or with more experienced progressives such as Democrats Ayanna Pressley of Massachusetts or Maxwell Frost from Florida. These members may share many of the DSA’s values but do not specifically affiliate with their political movement.
As leaders of both their chambers and their parties, speakers and majority leaders have a responsibility to pass necessary legislation. But in cases of tight margins and well-organized ideological caucuses, the job of negotiating often comes within their own membership.
![]()
The authors do not work for, consult, own shares in or receive funding from any company or organization that would benefit from this article, and have disclosed no relevant affiliations beyond their academic appointment.
Politics + Society – The Conversation

Many Americans will pause on the 25th anniversary of the 9/11 attacks to remember the nearly 3,000 people who were killed that day. The attacks became a shared national tragedy, the impact of which reached far beyond those who experienced them firsthand.
The aftermath of such a disaster can place enormous strain on a community. If disruption is prolonged, support is inadequate and the economic and social structures that hold a community together are damaged. Relationships can fracture, trust can erode, and conflict can emerge. Disaster researchers describe this pattern as a “corrosive community.”
As a social work researcher who has studied disaster recovery and worked alongside disaster-affected communities for more than two decades, I have witnessed another side of the human response to catastrophe: Amid tremendous hardship and loss, people reach for connection and find strength in community.
A national survey conducted just after 9/11 found that about half of Americans had responded to the crisis by giving to charity, and nearly a quarter donated or tried to donate blood. Volunteer sign-ups surged.
The research I conducted with colleagues on marriage and divorce following 9/11 offered another window into the disaster’s effects. We examined divorce rates across all 62 New York counties, comparing the four years after the attacks with the decade before them. Divorce rates were significantly lower than expected in three of those four years. Even by 2005, the statewide divorce rate remained about 8% below what the previous decade’s trend would have predicted.
These patterns point to something I have observed in the decades since: During collective crises, people often turn toward family and social relationships.
I saw that instinct again in 2005, after Hurricane Katrina, which killed nearly 1,400 people and caused more than US$125 billion in damage, making it one of the costliest natural disasters in U.S. history.
Amid enormous devastation and displacement, families took in relatives, and volunteers and organizations from across the country stepped forward. In our research on more than 7,200 children and adolescents from Louisiana communities heavily affected by Katrina, we found that two years after the storm, disruptions such as separation from family and community were among the experiences associated with greater post-traumatic stress symptoms. In our work with crisis counselors in Louisiana, we found that people who had experienced significant losses themselves described finding meaning and healing through helping others recover.
The National Oceanic and Atmospheric Administration has documented a sharp rise in billion-dollar disasters in recent decades. In 2024, the last year for which NOAA shared data, the U.S. saw 27 such disasters, compared with an average of about nine a year since 1980. As these events grow more frequent, understanding what helps communities recover will become more urgent.
For some communities – like those on the Gulf Coast – disasters are not isolated events but repeated experiences. Following the Deepwater Horizon oil spill in 2010 – the largest marine oil spill in U.S. history, which released 134 million gallons of oil into the Gulf – I asked 41 residents what advice they would give others facing similar crises. Many of them had endured multiple disasters, including Hurricanes Katrina, Rita and Gustav. Their advice was striking in its simplicity: Lean on your faith and find strength in community.
Years later, I heard the same message thousands of miles away when I visited Hawaii after the 2023 Maui wildfires, which destroyed the town of Lahaina and killed more than 100 people, making it the deadliest U.S. wildfire in more than a century. During my research for a book about community resilience, residents spoke to me not about individual survival, but about community and a shared commitment to rebuilding.
These were different disasters, places and decades, yet the message was remarkably similar.

Recognizing the strength within a community does not diminish its losses or lessen the responsibility to support it. People recovering from catastrophe need housing, economic assistance, mental health services and sustained investment.
Without adequate resources to rebuild, the connections that help people move forward can themselves become strained, contributing to a corrosive community.
The 1989 Exxon Valdez oil spill was one of the largest environmental disasters in U.S. history. It killed hundreds of thousands of birds and other wildlife and billions of fish eggs, driving families and businesses dependent on fishing into bankruptcy. In its aftermath, the community of Cordova, Alaska, experienced years of economic loss, prolonged litigation and uncertainty. Researchers documented declining trust, weakened social connections, conflict and population decline – effects that, in some cases, persisted for decades.
A corrosive community becomes more likely when recovery is prolonged, resources are inadequate or uneven, and trust erodes. Communities are more likely to cohere when support is adequate, resources are distributed fairly and institutions are trusted.
In my assessment, recovery is rarely an individual accomplishment; instead, it happens through families, neighbors, community organizations, volunteers and, sometimes, strangers.
The American Psychological Association reports that 62% of adults identify divisions in society as a significant source of stress. And despite being more connected than ever through technology and social media, roughly half of Americans show signs of loneliness.
Our differences do not disappear after catastrophes, but people find ways to connect despite them.
Research following Hurricane Maria, a 2017 storm estimated to have killed nearly 3,000 people, found that survivors extended help beyond their social circles, crossing political, socioeconomic and religious divides and even past conflicts.
Disaster solidarity may be temporary, but it reveals something enduring: Our capacity for connection does not appear when a hurricane makes landfall, wildfire spreads or an unimaginable act of violence like 9/11 occurs. It’s already there.
There is something to learn from a disaster that can help in the everyday moments that test us, too.
![]()
Tonya Cross Hansel does not work for, consult, own shares in or receive funding from any company or organization that would benefit from this article, and has disclosed no relevant affiliations beyond their academic appointment.
Politics + Society – The Conversation
[00:00:19] Nathan Wrigley: Welcome to the Jukebox Podcast from WP Tavern. My name is Nathan Wrigley.
Jukebox is a podcast which is dedicated to all things WordPress. The people, the events, the plugins, the blocks, the themes, and in this case, navigating WordPress security in the era of AI.
If you’d like to subscribe to the podcast, you can do that by searching for WP Tavern in your podcast player of choice, or by going to wptavern.com/feed/podcast, and you can copy that URL into most podcast players.
If you have a topic that you’d like us to feature on the podcast, I’m keen to hear from you and hopefully get you, or your idea, featured on the show. Head to wptavern.com/contact/jukebox and use the form there.
So on the podcast today we have Aaron D. Campbell.
Aaron is a seasoned veteran in both the internet and WordPress space. With over 25 years of experience spanning agency work, security products, hosting giants like GoDaddy and Newfold, and now his role at Monarx, a company focused on malware detection and remediation, particularly for web hosts. He’s led, the WordPress Security Team, has been involved deeply in shaping security practises, and remains tightly connected to the WordPress ecosystem.
We talk about the rapidly changing landscape of WordPress security, specifically how the advent of AI has escalated the speed, scale, and complexity of attacks, moving the security game from a battle of wits to a battle of compute power. Aaron discusses how attacks that once required human ingenuity are now orchestrated by AI agents, capable of chaining vulnerabilities that humans would struggle to conceive.
We get into the shift from a reactive to a proactive security posture across the WordPress ecosystem. Aaron explains how both attackers and defenders are now deploying AI leading to an arms race, where AI is used to combat AI, and where collaboration among security teams is just as crucial as information sharing among adversaries.
Which chat about the motivators behind attacks, spoiler, it’s almost always money. And the specific vulnerabilities WordPress faces as the most popular CMS on the web. Of interest is the narrowing window between when vulnerabilities are discovered and when they’re exploited, how supply chain attacks are on the rise, and what the WordPress “Protect the Shire” innovation means for plugin security.
Towards the end of the episode, we explore practical security advice for everyday WordPress users, with Aaron, recommending actionable tips on updates, choosing security minded hosts, and monitoring for Compromise credentials.
If you are concerned about how AI is reshaping the WordPress security landscape, and want to know how the community is responding, this episode is for you.
If you’re interested in finding out more, you can find all of the links in the show notes by heading to wptavern.com/podcast, where you’ll find all the other episodes as well.
And so without further delay, I bring you Aaron D. Campbell.
I am joined on the podcast by Aaron Campbell. Hello, Aaron.
[00:03:43] Aaron D Campbell: Hello, nice to be here.
[00:03:44] Nathan Wrigley: Yeah. Thank you for joining me. We’re in a corridor. I should say that at the very beginning. We’re in a corridor at WordCamp US, and so if background noise becomes a problem, we’re just going to have to cope with it. So apologies. But thank you for joining me in a corridor.
[00:03:57] Aaron D Campbell: Absolutely.
[00:03:58] Nathan Wrigley: We’re going to talk today a little bit about WordPress security, and particularly about the advent of AI, and the way that certainly in the more recent past, it appears to have upended what once was normal, I think it’s fair to say. I think things are happening at a rate of knots that perhaps a year or two ago we wouldn’t necessarily have predicted.
Do you want to just give us a little bit of background about yourself in terms of where you have worked, where you currently work, and what it is that you do for a living?
[00:04:25] Aaron D Campbell: Sure. So I guess I have worked in the internet space for a very long time at this point. I guess 25 years-ish. Ran my own agency for a long time and then into security product in the WordPress space, and over into hosting at GoDaddy, at Newfold, at hosting.com.
During that time I ran the WordPress security team for a couple years, have continued to be involved with it along the way, and now I am over at Monarx. We do malware detection and remediation, and have some security tooling for web hosts. So I’m still very tightly tied into that space on a few fronts.
[00:05:09] Nathan Wrigley: Is Monarx a new company? Because it’s not one that may necessarily come into mind when we talk about security online, WordPress security specifically.
So if you’re willing, could you just give us a little bit of a potted history of Monarx and what specifically you do in the WordPress space? I think it’s perhaps more related to hosting companies than it might be to end users. Just flesh that out a little bit.
[00:05:33] Aaron D Campbell: Yeah. Monarx has been around probably longer than you expect, six or seven years. The name’s may be not as recognisable, because a lot of times we are a white label in the background. Hosts run us, and you may not know that.
We protect more than just WordPress, but obviously WordPress is a big part of that. And we help hosts keep their users, their end users, safe and secure and malware free by monitoring the files, the runtime, having a WAF layer, protecting it several different layers along the way.
[00:06:08] Nathan Wrigley: So is this kind of like a white label solution? You are in talks with hosts, many of which I’m sure we’ve heard of, but their purchase of the products and services that you sell is white labelled.
[00:06:20] Aaron D Campbell: Yes, they may sell us as their own security product. They may also just include us in higher end hosting packages so that the malware detection and remediation and all that kind of stuff is included in your package. It varies from host to host, but most of the time you’re not seeing the Monarx name out in front, but you’re benefiting from our services anyway.
[00:06:40] Nathan Wrigley: So does that allow you to, because you are cross platform in terms of hosting company, hosting company X, hosting company Y, hosting company A, B, and C. Does that give you a larger depth of knowledge for want of a better word? So you can see that hosting company A’s got this Linux set up, and these kind of things are happening.
[00:06:59] Aaron D Campbell: Yes, it does. It’s less about their specific setups. I think the most valuable thing of being across many hosts like that, is that we see attacks, or new and novel malware, or those kinds of things happening in pockets and can often then protect against it globally, even though maybe it first started at host A.
By the time it spreads to host B X or Y in your example, we’ve already been able to understand what that is and block it across the whole realm. So we get a bigger picture, which is super useful. Especially as we start talking about some of the AI stuff and how fast it moves. That’s really necessary to stay ahead of that curve.
[00:07:42] Nathan Wrigley: Okay, so let’s move into that a little bit. And I think if we were having this conversation, let’s go for four years ago, that seems like a long enough period of time where AI was not really on anybody’s menu.
And now we seem to be in the era where the human is really being surpassed in almost everything logical, let’s go with that word. If it can be achieved with some kind of logic then AI seems to have surpassed humans.
And, especially recently, there seems to have been an uptick, not just in the WordPress news cycle, but also just in the general news cycle about, okay, we need to be a little bit more mindful about the products and services that we buy. We need to be more mindful about the security and logging in and credentials and all of that.
But specifically in the WordPress space over the last three or four months, I’ve heard story after story, which was unlike anything I’d heard before. These kind of chained attacks where, something that a human probably would never have conceived and pulled off is now possible. You spend 25 US cents on an AI agent, wait for six hours, and it’s come up with these 14 overlapping things, and it can hack WordPress Core and various other things.
So just paint the landscape of how alarming it is, and then presumably you can paint the landscape of how not alarming it is, because how you can mitigate against that.
[00:09:00] Aaron D Campbell: That’s fair. Let’s explain the reality and then let’s hopefully, help comfort people at least a little. It can be pretty scary. You’re absolutely right. AI has dramatically changed the game. And the way I like to explain it is it hasn’t changed the absolute core realities of the game in that there’s still a bit of cat and mouse. They’re trying to surpass us. We’re, trying to stay ahead of them.
But the scale and the speed and the complexity at which it is able to happen now is nothing we could have imagined four years ago. Honestly, even two, two and a half years ago. It has moved that fast. And what that looks like are, a few different things.
One, the speed at which AI can find issues in code, potential exploits, vulnerabilities, et cetera, is so much faster than any human. Like the compute power of it doing those logical bits rather than humans doing those logical bits, makes that move so fast. So the number of things being found, and being either reported or exploited, or both, the volume has just gone up dramatically.
And then on the complexity side of it, you are right. A simple example of that, one of the WordPress Core reports that I looked at recently, I needed to print it out and mark it up with a pen to wrap my brain around all these steps that it was taking. When I printed it out, it was 11 pages. 11 pages of like steps and instructions for an actual vulnerability that turned out to be real.
If four years ago that had existed in your piece of software, you would consider your software absolutely secure. No human’s ever going to find that. No one would ever know about it. And now AI is able to chain all those steps together into something that it can then write scripts to go automate and exploit.
And so those two things have both really shifted the game in a way that feels like it can put software owners, software managers, SaaS services, all these things on their back foot. There’s just such this flood, and such a complex flood coming at you.
[00:11:10] Nathan Wrigley: So I guess also the problem is that these things never sleep. So four years ago, every human, maybe they could put 10 hours in at the computer and then they would have to rest. So you get a, breathing space, and and the human can do this one thing.
But that’s not the case here. With an AI, presumably it could have 10, 50, a hundred, a thousand, the sky is the limit, things happening simultaneously. Just testing absolutely every permutation of everything conceivable. And then coming back with something. I don’t even know how we compete against that. And obviously we can get into that in a moment.
Is this a moment of despair or is there genuinely a way of getting out ahead of it? Or is it always going to be a case looking into the future where you are going to be reactive instead of proactive? In other words, when you wake up in the morning and you print out the 11 and then next year, the 30, and then the year after that, the 80 page document, how does that make you feel? Are you sanguine or is it just a prophecy of doom.
[00:12:08] Aaron D Campbell: I think it is a time of overwhelm, but hopefully not despair. Which is different. And I think that as big technology shifts hit, which AI is a big technology shift. There is often a significant adjustment. And we are at that time, and I am even one that maybe would say, I think it might get a little bit worse before it gets better, but it’s definitely going to get better.
And I see the path there in some of the foundations that we’re laying in things that we’re learning right now during this time of overwhelm, where we’re feeling flooded like this, is going to put us in a place to start getting into that curve where everything gets better.
And I think that, what’s the right way to put this? I think that the path there is apparent, but takes some time. And part of that’s because we have to shift from the being reactive to the being proactive all the time. Because agents move so fast to 24 hours a day, seven days a week. And the second they find a thing, they can immediately, automatically start trying to exploit it.
We have to shift to being ahead. Because there is no longer a gap in between when a thing is found and when it’s exploited, for us to fix the thing. We have to get ahead.
[00:13:36] Nathan Wrigley: So, you are obviously deep in the weeds of this, and it sounds like you’ve got an intuition that at some point in the near to midterm future, you feel like you are going to reach a point where things start to improve. That was the implication, I think of what you said.
What is that intuition? How do you come to the conclusion that there is an opportunity for things to improve. Even if you need to go into the weeds a little bit. I’m curious as to how it’s not a prophecy of doom, and how you believe that a moment will arrive where, I can’t answer that for you. I’ll just open it up.
[00:14:06] Aaron D Campbell: Yeah. So I think that some of this comes from historical experience, right? We’ve had these kinds of experiences where say, a certain type of hash that we used for security became a thing that hackers could break with the level of computing power that they finally had access to.
And that felt doom and gloom. But also we created better hashing algorithms. We created better things that were able to counteract that. We were able to shift to those, and we were also able to learn from them and think further forward.
So now some of the algorithms that we’re using aren’t just better enough to handle current computing, but better enough that we think they’re going to last a decent ways into the future.
I think that there are similar things with AI now. Where we are leveraging the same kind of tools now that these bad actors are, and we’re learning how to use them not just to protect against the way the bad actors are using them, but to get ahead enough to stay ahead of them.
And the way that looks, because that sounds maybe too vague to be realistic I guess, is we’re not just running those same algorithms against our code, or those same models against our code and hoping that we find the stuff before they find it. We’re instead also looking at how can we push to a different part of the stack? How can we protect against things that we’ve never seen? How can we start to recognise these patterns so that we can look at behaviours and protect against those, rather than just flaws that need to be patched. It’s shifting our thinking some, but I think in a way that’s going to help us get ahead in this game.
[00:16:03] Nathan Wrigley: Okay. That’s really interesting. I have a question surrounding how this kind of stuff happens, and I’m thinking about it from the adversarial’s point of view. What is that like? Because I have a notion that a decade ago it was individuals, perhaps offices, that’s probably the wrong word, but, collections of people sitting in a space, but there would be a finite number of them. There may be 10 in a room, one in a room, a hundred in a room.
But I don’t know if that’s still the case. Do the adversaries that you are dealing with, do they have a collaborative approach to hacking? Do they share information? And then the flip side of that is do you also, in the industry that you work in, do you share information?
If you discover something, does Monarx treat that like it’s your intellectual property? Or is there a, a whole system of sharing that amongst the community so that everybody benefits from the work that you do? You’re giving away the hard work that you’ve done. If that’s the case.
[00:16:59] Aaron D Campbell: So, first let me just say personally, one of the most important things to me is to raise the level of security across the whole internet, because that is better for humanity that relies on it so much, for all kinds of things in our daily lives, and for sharing information and making progress forward as people.
I think that I’m not alone in the space. Like I think that a lot of us that were drawn to this security space are drawn to it because it is a way to improve life for everybody. Will there be some intellectual property for individual companies? Yes, but I think it’s a lot more in how we approach the thing, and less we’re not going to tell people about this new vulnerability, or this new method that we found. Because we do want to be able to see the end user protected. Like that is the way we’re going.
Backing up to your, how do the adversaries work? It’s been a long time, I think since they sat in rooms together. They’re now virtual rooms, right? They can be spread all over the world, but still be working together. And they definitely do. They share information around. For us to be able to keep up with that, we have to share information around too. That is super important.
Simple example of that, the WordPress Security Team. Let me step back from Monarx and talk more of the space in general. The WordPress Security Team. You talked about how for the last few months you’ve seen maybe more security releases going out from WordPress and stuff. The way that the WordPress Security Team treats those, when we find out about them, and we triage them, and we realise that they’re real, and we start figuring out what our approach is to patching them. We then have a whole private Slack channel that has other people in it that can help us get protection out. Broader, wider by sharing some of that information sooner.
Cloudflare can maybe put some rules in place, and protect tonnes of people before the WordPress release goes out. So can some of the big hosts. So can some of the security groups. And so not only do we share that information, we’ve built it into our processes as a must, because that’s the only way to really do it right, and really protect as many people as possible. Because our adversaries are doing that. And so we have to as well. And we’ve just realised that, learned from it and made that the right way to do it.
[00:19:26] Nathan Wrigley: I’m just going to flip back to the comment that you made a moment ago where you said that you woke up and you printed out this summation. Let’s go with that. And it was 11 pages, and presumably that took a certain amount of your day to parse and understand.
How likely is it that that process will begin to run away from humans’ capacity to actually do it? So as an example, let’s say that a year from now that thing that you print out is 50 pages or 80 pages. Just the reading of it would be a whole morning, let alone the understanding of how those layers, and the stacks and the way that they’re overlapping and reliant upon each other.
Have we now, or have you now as an industry, have you almost handed the responsibility to figuring that stuff out, figuring out what the adversaries are doing? Has that gone to AI from your part as well? So is it AI versus AI basically, which seems very dystopian.
[00:20:18] Aaron D Campbell: We definitely pit AI against AI. It’s an extremely useful tool to combat itself essentially. And yeah, even for that 11 page one. Yes, I had to read through it and figure it out. but I did use AI to help summarise that. What are the steps that I need to do? Where does this actually track to in the code base?
I use it as an assistive tool in getting through that. And I do think that the longer the reports get, the more that’s going to be necessary. And now I personally, and several other people that I work with, have built testing rigs in AI, in various models, that are purpose built to help with this.
I can give it a report, in the repository and it can check its viability. It can see if that’s simplified. Check certain things. Is this a thing that requires some level of authentication, all these things that we use to have to do manually. And now we’re sharing around these sort of test rigs, or assessment rigs, that use this so that we can all use them, and grow them faster and make them better and make them more efficient. Because we are pitting AI against AI in many ways.
And as human, I think that it’s still important for the human to guide the process in a way that’s ensuring the fix is forward thinking enough, and that it’s in the right place and whatnot. Because in the end, the software is largely used by humans. But, in order to scale to the level that AI is pushing us to scale to, the human needs to be the decision maker, and possibly the opinionated one on form, and function, but not the logical power behind any of it now.
[00:22:01] Nathan Wrigley: Do you get the sense that WordPress itself is the target, or is WordPress just a bit of collateral damage? Are these adversaries of yours, are they specifically targeting WordPress because it’s got this giant footprint? Or is it more a case of this is just the adversaries just spraying and scatter gunning, and it just so happens that every so often they stumble across a WordPress thing.
[00:22:23] Aaron D Campbell: There is spray and scatter gun, just not running WordPress, or running your own bespoke thing is not enough to get away from AI trying to break your thing. But the bigger you are, the bigger the potential benefit from finding an exploit in you. And therefore, the more you are, like the bigger you are, the target is on you.
So WordPress has a big target, but it’s not just WordPress. Some big hosting companies also have a big target on their infrastructure in the same way that they’re targeting WordPress, their targeting, maybe a Hosting or a GoDaddy or a Blue. Someone big that has many people on it, not because they think their security is lax, or that they have some reason to suspect that there’s vulnerabilities, but because the payoff of finding a vulnerability there can be big. And so there’s a big focus there.
So yes, the bigger you are, the bigger the target. But that doesn’t mean that the scattershot isn’t also happening. And that they’re not also hitting small targets.
[00:23:24] Nathan Wrigley: Yeah. I suppose there would’ve had to have been a lot of joined up thinking in the past from a human to discover that, “Okay, this thing with Linux over here, okay we’ll just store that somewhere. But then there’s a PHP thing over here. Oh, and then curiously, there’s a PHP thing in WordPress, which,” that would’ve all had to have been conjured up by a human. And the memory of that would be difficult to maintain over time. But presumably the AI can just remember that forevermore. Store that PHP thing for the next decade and suddenly whip it out when it’s happens to coincide with some other thing. It’s fairly bleak.
Okay, so in terms of WordPress specifically, what is the incentive specifically? Why would somebody, let’s say somebody was coming after WordPress. What is it that they gain? What could they possibly have that benefits them off the back of a, let’s go for WordPress Core vulnerability which is, I don’t know, you can successfully log in as an admin or whatever it may be. What do they actually gain?
[00:24:17] Aaron D Campbell: It really comes down to money in end, if I’m honest. WordPress Core powers tens of millions of sites all over the web. Some of those have valuable stuff on them. Many of them frankly don’t. But that doesn’t mean that they’re worthless. They can be used, you’ve seen pharma ads and stuff showing up on a site, and it’s a pay per click kind of thing. And someone’s making some money off of putting not great ads your site. Even if you don’t get a lot of traffic, they’re making something. And when you’re looking at the potential of this vulnerability could apply to tens of millions of sites, you don’t need to make much per site.
But also, you could use that site as a way to have broad compute power to attack some other site. You’re using tens of thousands of sites to do it. Each one of them is on some separate IP. So now you have a distributed attack that’s harder to block than if you were doing the same attack from one place.
But you’re only doing that because it costs a lot to buy your own distributed power from everywhere. So you’re essentially stealing it and it’s making it, there’s some sort of worthwhile monetary value from it.
And so you may think, they can’t make anything off my site. They don’t have to. Your site’s one small bit in a huge array of sites that they’re trying to get, to get some monetary benefit in the end.
[00:25:40] Nathan Wrigley: So there’s no one size fits all. But money is essentially the broad overlapping thing?
[00:25:46] Aaron D Campbell: I mean, there are exceptions to that, where people are doing it for some political reason. Or some moral directive that they have or whatever. But the vast majority can be traced back to there’s money in it somewhere.
[00:25:59] Nathan Wrigley: I wonder curiously, because you mentioned about things like, pay per click style, you take oversight and you flood it with, I don’t know, nonsense about the thing that you’ve got and you want the world to notice. I wonder if curiously, people’s adoption of AI and that different way that we’re searching for things will actually impoverish that way of monetizing, because simply nobody’s actually looking on a search, well, increasingly people seem to be relying less and less on a search engine, and so maybe that kind of bit of it will dry up. Who knows?
[00:26:27] Aaron D Campbell: I love the optimism there. And I would like to think that those ads specifically probably will at some point. But the root of how those work is, I’ve broken into a site and I can inject some JavaScript ad, or some something like that.
And if those ads stop being valuable, then maybe I can inject some AI directives so that when an AI agent of some kind hits that site, it’s getting some sneaky thing snuck into its memory, or pulled in as a skill, that can then use that AI agent for nefarious purposes in the future.
I think that we can’t lower our guard against those things, because our adversaries will pivot and reuse it for something else. And so we will continue to protect against it.
[00:27:13] Nathan Wrigley: I’m going to peel back the contents of your head a little bit here. Because I’ve often wondered what the characteristic is of somebody like you who constantly facing this tidal wave of things. You’ve got to get up every morning, and every morning you could potentially wake up to the next big thing.
How do you just remain calm in the face of all of it? It’s a peculiar question, I realise, but tomorrow could be the next big thing. The day after that could be the next big thing. I’m imagining on most days now there is not necessarily the next big thing, but there’s a thing. It’s like you’re a fireman or something, except that there’s a fire going off in every district of town, and you are constantly busy and you never get to put the fire hose down. You’re just constantly at work.
[00:27:52] Aaron D Campbell: Some of us love that little consistent regular shot of adrenaline, and we get it in different ways than the firemen. But, honestly, I love complex problems solve. I love the challenges. Do I get exhausted and burnt out at times when they really do come every day for X amount of time? Sure, I’m human, I need to sleep, et cetera. But I think that it’s because I enjoy figuring out those really difficult problems, that I enjoy being in this space. And even specifically on this side of the space, the white hat side.
[00:28:26] Nathan Wrigley: Yeah. I suppose it’s like playing a good opponent at chess. You enjoy the chess game, even though it’s a hard thing and it stretches your brain. You play the chess over and over again because it’s a pleasurable thing to have your brain exercised in that way.
[00:28:39] Aaron D Campbell: And it’s like the more you do it the better chance you have at winning at chess. And I think it’s the same way in our game, right? Like the more you’re doing it, the more ways you’re finding to outmanoeuvre and to essentially win, and keep people safe online. And that’s, that’s exciting.
[00:28:56] Nathan Wrigley: You get the fist pump moment do you, there’s once in a while where you literally figure something out and you’re like, I nailed that.
[00:29:04] Aaron D Campbell: You absolutely do.
[00:29:04] Nathan Wrigley: Okay. Yeah. That’s really interesting. Your bio reads like an open source manifesto. I know that open source has been the thing for you throughout your career. I imagine that you could have gone into proprietary security and all of that.
But how does open source, particularly WordPress, how does that approach to developing software, how does that benefit the position that we can take and the security posture that you can take, and the reliability that you can have in things like WordPress going forwards? In your head, does it offer a superior model for fighting the adversaries?
[00:29:35] Aaron D Campbell: Yes, in my opinion it offers a superior model for fighting the adversaries. And the reason is actually still the same as it was 20 years ago when I started doing this. And I’ll explain why in just a second, but first, the reason is because we are able to benefit from many intelligent people, many more than any single company could with their source code.
Looking at our source code, and finding the weaknesses and even pitching in to help fix them. Hundreds of thousands, or millions, of people around the world are looking at our source code, finding those issues, and able to help pitch in and fix them, or report them to us so that we can, by having all that out there, it’s sort of like a building’s not less likely to collapse because no one saw the crack. It’s actually better that people are inspecting it, and finding those things and making sure it’s done right.
Now, that has shifted a little bit now, where in the past our adversaries looked at our source code too, right? They would immediately look at our repository when new things went out. As a matter of fact, when I ran the security team, I stopped committing stuff for a while, because it turned out that was a tell that this thing was probably a security issue, and people would look at that and try to figure it out.
So now the adversaries are using AI to watch our source code, which is also open to them, 24 7 and really look deep at it. But so are those many thousands of people using our source code for good. And so it’s still true that we have so many people on our side in helping us out, because our source code is out there because we’re open source, and it outweighs the bad. We find things faster because of that, and ultimately end up with more secure software more rapidly.
[00:31:36] Nathan Wrigley: Is there ever going to become a time where the amount of time that a vulnerability is available becomes moot? So in the past, a six hour window, where something wasn’t patched in WordPress Core, that’s a thing, but it’s not really a big thing. Maybe a month where something’s unpatched, that’s a big, I’m just wondering if in the future with the nature of the adversaries that you described and the tooling that they can bring to bear, if even like a three or five second window is going to become a thing.
[00:32:05] Aaron D Campbell: That is possible. We’re not at the three to five second window yet, so that’s good. I’ll let everybody relax a little bit. But the time from vulnerability disclosure to exploitation has shrunk dramatically over the last few years.
We did in fact used to have weeks, and then eventually days where it was okay to find out about the vulnerability, and responsible people, or responsible hosts, or responsible software companies could see that disclosure, patch the problem before there was much exploitation at all. And that’s now hours for major vulnerabilities.
As a matter of fact, we did a Monarx in conjunction with Patchstack, did like a year in review, thing looking back at last year. And we saw that for the more major vulnerabilities, it was about five hours. That’s not enough time for, you know, what happens if it happens in the middle of the night for a host who’s constantly monitoring that, immediately patching it, that’s difficult. And I do think that it will continue to shrink. And that that time that causes risk will be shorter and shorter.
And, we saw that with the recent wp2shell WordPress exploit. Once we released the patch, and everything was out there, the spike of exploitation that we as Monarx saw, like monitoring stuff happened within 30 minutes. Honestly, even a little bit faster than that. But the big spike started coming in about 30 minutes later, and that is just really fast.
But on the flip side, all that coordination that I talked about that WordPress did, had many millions of people already protected by then. And that’s how we have to look at it. We have to say, this is eventually going to get down to three to five seconds being a problem. How do we get ahead of it? And that’s what we’re trying to do.
[00:34:03] Nathan Wrigley: So a timely thing at the moment is this new innovation in the WordPress space called Protect the Shire. And Protect the Shire is the, a time bound moment where a plugin that has an update, it can’t be updated at the moment, I believe it’s standing at something in the region of six hours. On the face of it, that seems like a really excellent posture. But then there’s the flip side of that. If an exploit becomes discovered, and nobody can update their plugin for six hours, then that’s a big six hour window we’ve just painted. in the future where milliseconds may count. What do you think about that? It’s a interesting innovation. It’s something new. It was worth a try. Do you think that’s the way forward?
[00:34:41] Aaron D Campbell: I think it, was not only worth a try. I think it was a really good choice, and I think it will continue to be. We are seeing that a lot of current attacks are essentially supply chain attacks. How can we compromise whether it’s some package, an NPM package or something like that. Or whether it’s a plugin that’s gotten sold to a nefarious person, or even just hacked into and taken over by a nefarious person. That is happening more and this six hour gap helps protect against that.
But it can’t be a hard and fast, locked in stone, can never have exceptions, rule. And the truth is, it’s not. If there is a vulnerability in your plugin, or especially in a major plugin, reach out to the WordPress Security Team because we can coordinate a faster release, we can make an exception to that rule when it’s necessary.
And I think that for security fixes that are clearly security fixes that exception iss an easy one to make, because we do want to protect immediately. But slowing things down enough to make sure that there’s not been some sort of supply chain issue that is actually going to cause a vulnerability rather than fix one, is smart.
And so I think that it will find the right balance there as we continue to move forward, and figure out how to make better processes around this, to make it easier to do the right thing all the time, and know exactly which of those right things. But I think at the moment we’re in a pretty good place there and continuing to find the exact right place.
[00:36:18] Nathan Wrigley: It feels from the outside as if security’s fairly binary. On the one hand, adversary on the other hand, good guys. On the one hand hacked, on the other hand, not hacked. It’s black and white. But it seems from everything that you’ve been talking about today, that you are occupying a really grey area. You’re just trying to figure out what the path is forward. You’re constantly staring into the future trying to figure out what the adversaries are doing. Trying to patch, trying to make sure that everything is as good as it possibly can be. And I hadn’t really thought about it in that way. It’s not, there is no destination here where everything’s white. It’s a journey and every day’s going to be a bit grey. There’s going to be a bit of black and a bit of white, but a lot of grey in the middle.
[00:36:58] Aaron D Campbell: I don’t really look at it as grey, but I can see where you’re going there. But I think that there is this black and white, and then there’s sort of the cloudy. The further forward you look, the more difficult it is to know exactly where the black and white are always going to be. And some of that sort of comes across as grey. It’s a little blurry. You can’t quite figure it out.
But you’re right. there’s some prediction. There’s some, we think that moving this way is going to cause more white and less black. And that’s what we’re, that’s what we’re constantly aiming for. But you can’t just say turning right always makes things more white. Because sometimes there could be black over on that side somewhere, right? You’re really trying to be predictive, but not just randomly predictive, right?
Many of the people like myself that are trying to help guide this path forward, and even more than me, some of the people like Matt, who instituted that wait policy and some of the people that are running the WordPress Security Team, we have decades of experience watching this, that’s helping to inform our predictions. And so it’s not, we’re not just willy-nilly guessing. And I think that’s important to point out to the people that rely on us, to help guide them to the right space going forward.
[00:38:02] Nathan Wrigley: Yeah. Okay. So my schooling in chemistry was pretty basic, but I know that if I want to understand chemistry, my quickest way to do that is to rely on an expert, is to go and find a chemist who has years of experience. And, the same would be true here. I think most of us have probably not got the capacity to actually get a hold of what you’re saying. We, understand that your expertise is what we need to be listening to. But I’m just wondering for a typical WordPress user of whom many listen to this podcast, they have a WordPress site, but they’re not really interested in security, other than how it may impact their business.
So I’m going to ask for some very basic advice here. What would be the 1, 2, 3 things that somebody using WordPress with no security credentials whatsoever. What would be the few things that you would advise them to either go and read, or go and do, or go and think about?
[00:38:51] Aaron D Campbell: Yeah, so I think the biggest thing that I would encourage them to do, is essentially position themselves in such a way that they are relying on the experts, right? You’re not an expert and that’s okay. No one can be an expert in everything. But there are some things you can do to position yourself such that you’re benefiting from those experts.
One of those is updating as fast as possible. So WordPress auto updates turned on, those kinds of things. This WordPress Security Team that I’m talking about that has so much expertise in the area, and their whole focus is trying to make sure that WordPress is always secure. That lets you rely on them to help keep your site secure.
I think in similar ways, you want to find the right host that is also doing those security focused things for you, so that you don’t need to. And maybe that’s asking your host, what do you do to keep me safe? We talk about security, like the best security is layered security. It’s almost like having a gate at the complex, but also having a lock on your door, right? Those kinds of things. You can ask your host, what do you do to protect me in a layered way?
And maybe that question doesn’t make sense to you, and maybe even their answers don’t make sense to you, but if they have an answer, that’s good for you. It means that you can rely on their expertise.
And then stepping out of the obvious space to give a third thing that people should be doing. And this is, this may sound out in left field, but you should get some form of dark web monitoring for yourself, for your own credentials. And whether that’s going to someplace like, Have I Been Pwned, and looking at your own email address, and passwords and seeing if they’ve been in some breached data from somewhere, and are now being sold on the dark web. Or whether that’s using some service that offers it. I think that’s important, more so now than it’s ever been.
Because one of the other things that AI is doing that it’s particularly good at is collecting all this massive amount of breach data that’s happened over the last couple decades, that’s being sold on the dark web. Collating it all and saying, oh, we see that, gosh, 15 years ago, an account that Aaron had was in a breach. And we now know one of his passwords.
And granted it’s 15 years old, but it’s very easy for that AI to then say, where is Aaron now? What’s he doing? What can we learn about him? He works at Monarx. I wonder if this password works for his Monarx account. I wonder if this password works for the bank that he’s at. Or this other tool that we see that he uses. Let’s try all his social media accounts.
And so knowing whether that’s out there and being able to, you can’t get rid of that data, but being able to do things to protect yourself because you now know it’s out there is more important than it’s ever been.
[00:41:47] Nathan Wrigley: I hope you take this in the spirit in which it’s offered, but I really do wish to live in a world where you don’t have a job.
[00:41:55] Aaron D Campbell: Me too.
[00:41:56] Nathan Wrigley: But, am glad that we live in a world where you do, somebody like you does have a job. So I hope that landed correctly.
[00:42:02] Aaron D Campbell: If I could work to the point where I could work myself out of a job, I would find a new career and I would feel so accomplished, you couldn’t even imagine it. I’m okay with that.
[00:42:12] Nathan Wrigley: Yeah. Good. Aaron, just before we wrap up, is there a place where you hang out online where people could poll you if they’ve got a question, or any thoughts about what we’ve talked about?
[00:42:21] Aaron D Campbell: Yeah, if you’re looking for me professionally, you can find me Monarx.com, M-O-N-A-R-X.com. I also have aarondcampbell.com if you want some of my own more personal takes on security and things. And you can find me on Bluesky or the WordPress Slack. Those are probably the biggest places I’m at.
[00:42:40] Nathan Wrigley: What I will do, dear listener, into the show notes, if you go to wptavern.com and you search for the episode with Aaron Campbell, you’ll be able to find the links. I will dig out the Bluesky, and the various social links and the Monarx website and what have you, so you don’t have to hunt around too much. Go there wptavern.com. And Aaron, thank you so much for chatting to me today.
[00:43:01] Aaron D Campbell: Thank you. This was a really fun talk.
On the podcast today we have Aaron D Campbell.
Aaron is a seasoned veteran in both the internet and WordPress space, with over 25 years of experience spanning agency work, security products, hosting giants like GoDaddy and Newfold, and now his role at Monarx, a company focused on malware detection and remediation, particularly for web hosts. He’s led the WordPress Security Team, has been deeply involved in shaping security practices, and remains tightly connected to the WordPress ecosystem.
We talk about the rapidly changing landscape of WordPress security, specifically how the advent of AI has escalated the speed, scale, and complexity of attacks, moving the security game from a battle of wits, to a battle of compute power. Aaron discusses how attacks that once required human ingenuity are now orchestrated by AI agents capable of chaining vulnerabilities that humans would struggle to conceive.
We get into the shift from a reactive to a proactive security posture across the WordPress ecosystem. Aaron explains how both attackers and defenders are now deploying AI, leading to an arms race where AI is used to combat AI, and where collaboration among security teams is just as crucial as information-sharing among adversaries.
We chat about the motivators behind attacks, spoiler, it’s almost always about money, and the specific vulnerabilities WordPress faces as the most popular CMS on the web. Of interest is the narrowing window between when vulnerabilities are discovered and when they’re exploited, how supply chain attacks are on the rise, and what the WordPress “Protect the Shire” innovation means for plugin security.
Towards the end of the episode, we explored practical security advice for everyday WordPress users, with Aaron recommending actionable tips on updates, choosing security-minded hosts, and monitoring for compromised credentials.
If you’re concerned about how AI is reshaping the WordPress security landscape, and want to know how the community is responding, this episode is for you.
Monarx and Patchstack’s State of WordPress Security In 2026
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning