And Now For Something Completely Different

There was no post last Thursday as I was traveling by rail from the east coast to Colorado, where I’m spending this week. I’ll also be traveling next Thursday on the return trip back east, so there will be no post next week. With that said, I’m going to post this months And Now For Something Completely Different a week early.

I’ll also note, I like writing these posts more than the internal controls posts, so might try to find a way to post them more often, maybe one at a time, also making the posts quicker reads.


WordPress

WordPress implemented a new automated security review prior to the release of plugins. The review will assess plugins to determine their potential security risk and any that are assessed a high security risk will be blocked. This automated security review also applies to themes. It should be noted the automated review only applies to plugins and themes made available to WordPress.org self-hosted sites. I didn’t look into this, but I would assume a similar tool already existed for sites hosted on WordPress.com.


IDScan Breach

Brian Krebs once spoke at an ISACA conference I attended. Pretty sure it was in Las Vegas and he might have been the keynote speaker, but could be wrong. It was at least 10 years ago. Either way, I found his story interesting and have followed his writing since, which he does at krebsonsecurity.com. A few weeks ago he posted an article about an IDScan branch that was initial brought to his attention and later picked up by the FBI.

The article brings up some interesting thoughts regarding the dangers of requiring drivers licenses to verify identification prior to accessing services provided by social media sites in order to protect kids. These requirements are mostly being pushed by governments. However, there are some social media sites, take Gander for example, that are doing this on their own accord. I do think we need to separate the sites doing this on their own from those being forced to by governments, whereas one is a choice and the other is a requirement.

https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/


AI

The AI industry was thrown for a little loop last week when leaders in the AI industry called to slow things down. The concept is something I’m in favor of, but for different reasons.

AI is outpacing governance, which is creating unknown control risks.

I find it interesting that the request is coming from the big AI companies that are spending money hand over fist without the income to offset expenses, going into massive debt. The request isn’t coming from companies like Apple, Google, Meta, and Amazon. These are income generating companies that are mostly able to offset the expenses. Just something to keep an eye on.

https://www.theverge.com/ai-artificial-intelligence/995186/is-big-techs-ai-slowdown-a-safety-pact-or-a-cartel


That’s it for this month.

And Now For Something Completely Different

Last month I asked some friends to come up with a title for the monthly post of topics outside the normal focus of the blog. One of them gave me the idea of naming it “And Now For Something Completely Different”, which is taken from Monty Python’s Flying Circus, or so I’m told. I liked the idea, but should also note I didn’t know where the phrase came from and never actually watched the show outside of a few skits on YouTube. Feel free to use that against me. 😀


WordPress

Let’s start things off with a topic related to this blog and millions of sites on the interweb. A WordPress vulnerability was found in the wild affecting versions 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. The vulnerabilities affect self-hosed WordPress.org sites, not sites hosted by WordPress.com.

I self-hosted my personal blog for a while, leasing server space with GoDaddy, but then transferred it to WordPress.com in 2012. Self-hosting was fun for a while as it allowed me to make unlimited changes to the look and feel of the site, without restrictions. It also put me in a position to learn a little more about how things work on the backend, but as life got busy it just turned into more of a hassle. It was worth moving to a hosted site with WordPress.com for its ease of use.

With that said, if you’re using a self-hosted .org site and don’t have it set to automatically update, you should do that now.

https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk


Click to Pray

Bob the Hacker posted another doozy this month related to the Click to Pray app. Click to Pray is the Pope’s official prayer app launched in 2018 that does the things you would think it would do. However, Bob found a vulnerability that made Personally Identifiable Information (PII) available to anyone. He notified various powers that be about the vulnerability during January 2026, but never received a response and it didn’t get fixed. That is, it wasn’t fixed until he posted about it earlier this month. Again, he received no response about the fix, only finding out it was fixed after reading about it online.

https://bobdahacker.com/blog/click-to-pray


META

The more Meta pushes to expand their use of AI, and that doesn’t even include their “glasses”, the more I want to delete all my Meta accounts. As I noted last month, I still have a Facebook account to keep up with things going on in my community / neighborhood and also still have a IG account. The IG account is set to private, limiting it to only friends / contacts I’ve approved, which is a pretty small group. The last picture I posted there was in 2022. There’s still a high probability I’ll delete both FB and IG accounts at some point.

Meta announced they were going to start using pictures from public IG accounts as a basis for other users to create alternate pictures with it’s AI image generator and it was going to be automatically turned on for all public accounts, requiring the user to turn it off. In essence, if you weren’t paying attention to the news, you wouldn’t even know it was happening. The public wasn’t having it and they eventually decided to back off their plan.

https://www.androidcentral.com/apps-software/meta/meta-removes-muse-image-ai-from-instagram-after-users-voiced-major-concerns


That’s it for this month.