Blog
First-person notes from Mac Clark on protecting public websites. Guides · Count mode · Branded 403 · Solutions · Pricing
WAF Watch: Events Calendar RCE, Elementor uploads, Drupal table fieldWeekly WAF Watch for campus and agency operators — The Events Calendar unauthenticated RCE, Elementor Pro form-upload exploitation, Drupal Ultimate Table Field access bypass, and a Berkeley EECS outage lesson. Count first, then promote what’s safe to block.WAF Watch: Magento zero-day, school-year outages, and Drupal XSSWeekly WAF Watch for campus and agency operators — StyleSmuggler Magento RCE, France education outages, Drupal Monster Menus XSS, and Feide login floods. Count first, then promote what’s safe to block.WAF Watch: WordPress RCEs and campus login floodsRoundup of WordPress XSS2Shell, Imagick RCE, Elementor Pro upload RCE, and Norway Digdir/Sikt DDoS — plus a count-mode tip for campus and agency sites.A client was taking 90 million requests an hour. The WAF was only half the fight.First-person account of a request flood on a client's public site and a second customer-facing portal — 90 million requests an hour, origin bypass, and what actually stopped it.