Maciek Palmowski and the five-hour zero-day

Community + Code: Episode 34 - Maciek Palmowski

For years, the standard line on WordPress security was: core is secure, it’s the plugins you have to worry about. Maciek Palmowski — grown-up Spectrum kid, current growth engineer at Patchstack, and newly minted conference organizer — is here to tell you that line doesn’t hold anymore. AI-assisted research just found real vulnerabilities in WordPress core itself, and the window between a bug getting discovered and someone exploiting it in the wild has shrunk from weeks to about five hours.

We get into that, plus why the WordPress plugin repository is a lot thinner than its numbers suggest, the “Drupalisms” talk that convinced him WordPress and Drupal keep making the exact same mistakes under different names, why “vibe coding” has an unglamorous sequel called “vibe maintenance,” and his running joke about being asked to talk about literally anything except pottery.

It’s a good one for anyone who’s ever assumed “keep WordPress updated” was enough to call a site secure.

Listen to the full episode and subscribe so you catch the next one.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *