Oliver Sild
@OliverSild
Nerding out on cyber security, community building, and open source software | CEO of @patchstackapp | 🇪🇪 Pärnu
In 2016, I made a post to Reddit that #WordPress (and other CMSs) need a proper vulnerability management tool and an effective way to prevent attacks against vulnerabilities in plugins. Here's what happened 🧵1/6

Before you can start setting up any security measures, you should have a clear understanding of where security is even needed. 🧐 To do that, you’ll first need to start mapping your attack surface. oliversild.com/how-to-map-the…
Ever struggled to convince a client they need to invest in security? Here’s my approach to helping customers actually get it. oliversild.com/how-to-help-cu…
I found an idea I fell in love with while walking with my dog Lilly this morning - an idea of a pivot. It's so common we don't even think about it much. But I think we should! 💪 oliversild.com/its-time-for-a…
What a comeback.
Tomorrowland Mainstage at night 🧡 (📸 via @tomorrowland)
‼️ MiniOrange Password Policy Manager patched a vulnerability that allows subscriber level users to take over any (including admin) accounts on site. Update immediately! patchstack.com/articles/accou…
Vibedept is going to be smth we will call technical dept and AI spaghetti code in the following years. There will be a lot of it!
One of the fastest @patchstackapp integrations we’ve seen (launched in 5 days) and generated $4000 MRR in the first month 👏 patchstack.com/articles/case-…
Offering WordPress maintenance isn’t just good for clients – it’s good for your business. I wrote a guide on setting it up (and avoiding common mistakes). oliversild.com/how-to-set-up-…
U.S. President Donald J. Trump states that upwards of 17 MIM-104 “Patriot” Surface-to-Air Missile Systems, as well as additional missiles and associated equipment, are being prepared and will be sent to Ukraine, with many set to arrive on the battlefield “within days.”
Initial IOCs from @patchstackapp article: patchstack.com/articles/criti… gravityapi\.io gravityapi\.org Potentially related domains with very close creation date found by @ValidinLLC Lookalike mechanism: gravityapi\.ai gravityapi\.co gravityapi\.dev gravityapi\.net
‼️ Gravity Forms had a supply chain breach and their official website distributed a plugin with a backdoor. If you happened to download their plugin via the website on 10/11th of July, make sure to scan your server now. IOCs and details in the article. patchstack.com/articles/criti…
“But my WordPress site isn’t a target.” Yes it is. Assume you’re already hacked. Then start building like it. oliversild.com/consider-yours…
Hmm, @WordCampUS happens in a month and only 333 tickets have been bought as of today. 🙃 Are people normally buying tickets last minute or is WCUS going to be significantly smaller this year?


Not all vulnerabilities are created equal. Here’s what you need to know: oliversild.com/most-dangerous…