Ninety minutes, then four days: the WordPress core RCE from a different perspective

On July 17, Patchstack published an account of how quickly attackers weaponised the WordPress core RCE chain — CVE-2026-60137 and CVE-2026-63030 — measuring roughly ninety minutes from public patch to live exploitation attempts. Their post closed with a section on what to grep for in your own logs. We took them up on it. Sitting…

PCI DSS 4.0 Requirements

There are new broad PCI DSS 4.0 compliance requirements that apply to eCommerce websites. The new requirements add a Level 4 which applies to small eCommerce websites handling less than 20,000 transactions per year. These websites did not previously have to complete requirements for PCI DSS version 3. The deadline for compliance with these is…

Could Your WordPress Security Plugin be Lying?

Many people have received notifications from their cloud server provider indicating their server’s IP address has been reported as attacking other websites. We Watch Your Website’s services have been used frequently to investigate these claims. The following is a recent one that is very interesting. We Watch Your Website has just completed another investigation of…