By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    Web Malware: Out of the Shadows and Hiding in Plain Sight
    1 year ago
    7 Reasons Kaspersky Internet Security 2015 is better than ever
    1 year ago
    Multi-stage phishing that starts with real links
    1 year ago
    Latest News
    Patchstack Becomes Member Of Open Source Security Foundation
    14 hours ago
    PDF Phishing: Beyond the Bait
    17 hours ago
    Update ASAP! Critical Unauthenticated Arbitrary File Upload in MW WP Form Allows Malicious Code Execution
    20 hours ago
    Fake CVE Phishing Campaign Tricks WordPress Users Into Installing Malware
    2 days ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    Critical vulnerability fixed in popular WordPress plugin Jetpack
    Critical vulnerability fixed in popular WordPress plugin Jetpack
    1 year ago
    Windows 10 22H2 new features and changes
    1 year ago
    Windows 11 build 22000.652 (KB5012643) out as preview
    1 year ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    10 months ago
    Now you can speed up any video in your browser
    10 months ago
    How to restore access to a file after EFS or view it on another computer?
    10 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    11 months ago
  • How To
    How ToShow More
    A year in recap: Windows accessibility
    20 hours ago
    How to stop, disable, and remove any Android apps — even system ones
    3 days ago
    Bigger, Better, Cooler in a 2U1N form factor
    Bigger, Better, Cooler in a 2U1N form factor
    4 days ago
    Vulnerability in crypto wallets created online in the early 2010s
    5 days ago
    Use Windows 11 features to inspire creativity, speed up everyday tasks
    6 days ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    How to find out the hidden age in Vkontakte?
    1 year ago
    How to remove the background from a photo?
    1 year ago
    Useful commands for the Siri voice assistant. Part 1
    1 year ago
    Latest News
    How to check CPU temp on Windows 11
    18 mins ago
    How to disable news feed from Widgets on Windows 11
    18 hours ago
    How to fix performance issues after upgrading to Windows 11 23H2
    18 hours ago
    How to disable updates on Windows 10 Pro and Home
    2 days ago
  • Glossary
  • My Bookmarks
Reading: Patchstack Is Introducing Patchstack Priority
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
Wordpress Threats

Patchstack Is Introducing Patchstack Priority

Vitus White
Last updated: 9 November
Vitus White 4 weeks ago
Share
5 Min Read

Over the past 6 months, we’ve been building, testing and fine-tuning a new vulnerability scoring system called Patchstack Priority to provide a more accurate representation of the seriousness of security vulnerabilities. The goal? Help WordPress developers reduce alert fatigue and know what to patch first.

Contents
Vulnerability prioritization for Patchstack usersDifferent levels of Patchstack PriorityHigh Priority:Medium Priority:Low Priority:Data behind the Patchstack PriorityWhat’s next?

We have carefully assigned the Patchstack Priority scores to all historic vulnerabilities, and the scores are now added to every new vulnerability. (Some of you may have already noticed “Priority” levels on the Patchstack Database vulnerability entries.)

Today, we roll Patchstack Priority out to all our users!

Vulnerability prioritization for Patchstack users

Patchstack users can now prioritize and filter vulnerabilities directly on their main dashboard.

By default, vulnerabilities will be sorted based on their Patchstack Priority score and date (newest first).

If you have planned maintenance windows for your websites, you can jump into the Patchstack App to see what needs your attention first. You’ll see which vulnerabilities could be resolved with a security update and which vulnerabilities are mitigated by the Patchstack virtual patches.

Patchstack priority

As we continue working on the Patchstack Priority, the users will soon also get a “security tasklist,” recommending when to update specific software and helping you optimize your security maintenance.

Our Developer and Business users will be able to adjust their notifications. For example, if you’d only like to receive notifications for high-priority threats, toggle it in the Settings, and alert fatigue will be no more!

Different levels of Patchstack Priority

With the rapidly increasing amount of security vulnerabilities being fixed in the WordPress plugin ecosystem, it’s more important than ever to know where to put the attention first. Unfortunately, setting a focus is difficult when everything seems equally severe.

Patchstack Priority sets vulnerabilities into three categories, so users direct their attention to where it’s needed first and reduce noise from vulnerabilities which are not an imminent threat.

Patchstack Priority simply sets all vulnerabilities to High, Medium and Low:

High Priority:

  • Expected to become actively exploited
  • Known to be actively exploited already
  • Receives a virtual patching rule from Patchstack
  • Recommended time to patch/update (RTTP): 0 days.

Medium Priority:

  • Could be exploited in more targeted attacks
  • Is not yet publicly known to be exploited
  • Receives a virtual patching rule from Patchstack
  • Recommended time to patch/update (RTTP): 7 days.

Low Priority:

  • Not expected to become exploited
  • Not known to be exploited
  • Does not require a virtual patching rule from Patchstack
  • Recommended time to patch/update (RTTP): 30 days.

The priorities are updated as we get more data, ensuring you always know what needs your attention first.

Data behind the Patchstack Priority

Patchstack Priority is a dynamic scoring system, which takes into account different variables to predict whether a vulnerability will:

  1. Become actively mass-exploited, or
  2. Potentially be exploited in more targeted attacks, or
  3. Be unlikely to become exploited.

We analyze each vulnerability and the software where we found the vulnerability. Then, we compare them with similar vulnerabilities in the past that we have attack data for.

We also monitor each vulnerability in real time in case we need to increase the priority.

Some of the variables we analyze when assigning Patchstack Priority to security vulnerabilities include the following:

  • Analyzing the vulnerability prerequisites (i.e. What privileges are required for the vulnerability to be exploitable?)
  • Analyzing the vulnerability type (i.e. Some vulnerabilities like RCE are more prone to exploitation than others, such as CSRF.)
  • Analyzing the software itself (i.e. how big of a target it is, where it’s commonly used, how many active installs it has, etc.)
  • Analyzing the standard CVSS scores
  • Monitoring active exploitation attempts

What’s next?

In addition to introducing Patchstack Priority so you know what to tackle first, our team has also made more changes to the Patchstack App:

  • An easier way to control the Protection modules and search and review the protection logs
  • See active modules on the Apps Overview page
  • Partner Mode in the plugin
  • New rule creation page for our new firewall engine (and templates)

And more!

Stay tuned for more updates as our team works to help you take charge of your WordPress security.

Try Patchstack Priority in your dashboard, and let us know if you have any feedback!


Source: patchstack.com

Translate this article

TAGGED: PoC, Security, Software, Targeted Attack, Threat, Threats, Vulnerabilities, Windows, WordPress
Vitus White November 9, 2023 November 9, 2023
Share This Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

How to check CPU temp on Windows 11
News 3 hours ago
Patchstack Becomes Member Of Open Source Security Foundation
Patchstack Becomes Member Of Open Source Security Foundation
Wordpress Threats 17 hours ago
PDF Phishing: Beyond the Bait
Threats 20 hours ago
A year in recap: Windows accessibility
Windows 20 hours ago
How to disable news feed from Widgets on Windows 11
News 21 hours ago

You Might Also Like

News

How to check CPU temp on Windows 11

3 hours ago
Patchstack Becomes Member Of Open Source Security Foundation
Wordpress Threats

Patchstack Becomes Member Of Open Source Security Foundation

17 hours ago
Threats

PDF Phishing: Beyond the Bait

20 hours ago
Windows

A year in recap: Windows accessibility

20 hours ago
Show More

Related stories

Several Critical Vulnerabilities including Privilege Escalation, Authentication Bypass, and More Patched in UserPro WordPress Plugin
BridesMaid – neuron writes toasts For those very occasions when you need to give out a powerful
The other day Yandex pleased us with the announcement of a new Midi station – an excellent reason to listen
REMIX – remixes of pictures from neural networksCreate, share and correct works
How to download Diablo IV for free and absolutely legallyBlizzard has opened a free
Rostelecom employees were forced to abandon Android and iOS in favor of Aurora.
Previous Next

10 New Stories

How to fix performance issues after upgrading to Windows 11 23H2
Update ASAP! Critical Unauthenticated Arbitrary File Upload in MW WP Form Allows Malicious Code Execution
Fake CVE Phishing Campaign Tricks WordPress Users Into Installing Malware
How to disable updates on Windows 10 Pro and Home
How to stop, disable, and remove any Android apps — even system ones
Patchstack Alliance Bounty Program Events for December
Previous Next
Hot News
How to check CPU temp on Windows 11
Patchstack Becomes Member Of Open Source Security Foundation
PDF Phishing: Beyond the Bait
A year in recap: Windows accessibility
How to disable news feed from Widgets on Windows 11
10alert.com10alert.com
Follow US
© 10 Alert Network. All Rights Reserved.
  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?