Track: Honing Your Skills (North 120CD)
-
The Attacker That Never Logged In: Session Hijacking, Stolen Cookies, and the Blind Spot in WordPress Security
They didn’t guess the password. They didn’t break 2FA, bypass the firewall, or trigger a single alert. The activity log shows no failed attempts, no unusual login times, no new accounts created. And yet, the attacker is inside your WordPress site, accessing your WordPress dashboard. Session hijacking leaves no login trace, because the attacker never…
-
3 Things All Website Owners Need to Check for Privacy Compliance
Many modern websites are still not complying with a single privacy law. Not GDPR. Not CIPA. Not PIPEDA. Nothing. With the rise of privacy-law lawsuits – and exploding cases of CIPA demand letters – now is not a good time to tempt the fates. But, as with most problems, the first step towards fixing a…
-
WordPress for the Public Good: Modernizing Civic Websites for Accessibility, Services, and the Open Web
WordPress has changed dramatically since 2020, with Full Site Editing, block themes, the Site Editor, patterns, performance improvements, accessibility work, and modern development workflows reshaping what the platform can do. At the same time, public-sector websites are being asked to do more than ever. They are not just marketing tools. They are public-service infrastructure where…
-
Building Training Systems, Not Sessions
Every agency has seen it happen: the site launches, the training session goes well, and three months later the content team has questions no one remembers covering. WordPress offers a huge amount of educational material, but most of it is not designed to be handed directly to a client team with real workflows, custom tools,…
