03 Sep 2026

feedWordPress Planet

bbPress: bbPress 2.6.15 is out!

bbPress 2.6.15 is a security and maintenance release that fixes five security issues and includes a few compatibility improvements. Everyone running bbPress should update as soon as possible. đź”’

This release strengthens authorization around topic and reply editing, topic splitting and merging, user profile updates, and private or hidden forum visibility. It also hardens imported password verification, avoids PHP warnings on some forum requests, and improves compatibility with modern WordPress UTF-8 handling.

All of these fixes have already been merged into the 2.7 development branch.

Thank you to mickey_cyberkid, itznullbyte, eldoniis, and tristaninsec for reporting issues through HackerOne, and to Ananda Dhakal at Patchstack for reporting CVE-2026-74010. Thank you for helping keep bbPress communities safe! 🙏

Download bbPress 2.6.15 from WordPress.org, or update directly from your WordPress dashboard.

03 Sep 2026 7:54pm GMT

feedThe Official Google Blog

Start the year AI-ready with the Google AI Educator Series

An overview of upcoming training sessions from the Google AI Educator Series (GES), and how teachers are putting these tools to work.

03 Sep 2026 5:00pm GMT

Use your voice to get more done in Gmail, Docs, and Keep

Three new voice-activated features will change the way you use Google Workspace products.

03 Sep 2026 4:00pm GMT

5 amazing visuals show how the male fruit fly’s brain map is advancing neuroscience

HHMI Janelia, Google and partners mapped the brain and central nervous system of a male fruit fly, a key model organism in science.

03 Sep 2026 3:05pm GMT

feedWordPress Planet

Open Channels FM: Podcasting Meets AI Shifting Formats, Editing, and Ethics

Examining the impact of AI on podcast content, marketing, and the value of real human voices.

03 Sep 2026 2:05pm GMT

feed20SIX.fr

Rompre par SMS : lâcheté ou choix parfois légitime, ça se fait ou pas ?

femme contrariée message

Rompre par SMS est-il forcément lâche et irrespectueux ? Découvrez dans quelles situations ce moyen peut se justifier.

L'article Rompre par SMS : lâcheté ou choix parfois légitime, ça se fait ou pas ? est apparu en premier sur 20SIX.fr.

03 Sep 2026 1:22pm GMT

02 Sep 2026

feedWordPress Planet

WPTavern: #232 – Aaron D Campbell on Navigating WordPress Security in the AI Era

Transcript

[00:00:19] Nathan Wrigley: Welcome to the Jukebox Podcast from WP Tavern. My name is Nathan Wrigley.

Jukebox is a podcast which is dedicated to all things WordPress. The people, the events, the plugins, the blocks, the themes, and in this case, navigating WordPress security in the era of AI.

If you'd like to subscribe to the podcast, you can do that by searching for WP Tavern in your podcast player of choice, or by going to wptavern.com/feed/podcast, and you can copy that URL into most podcast players.

If you have a topic that you'd like us to feature on the podcast, I'm keen to hear from you and hopefully get you, or your idea, featured on the show. Head to wptavern.com/contact/jukebox and use the form there.

So on the podcast today we have Aaron D. Campbell.

Aaron is a seasoned veteran in both the internet and WordPress space. With over 25 years of experience spanning agency work, security products, hosting giants like GoDaddy and Newfold, and now his role at Monarx, a company focused on malware detection and remediation, particularly for web hosts. He's led, the WordPress Security Team, has been involved deeply in shaping security practises, and remains tightly connected to the WordPress ecosystem.

We talk about the rapidly changing landscape of WordPress security, specifically how the advent of AI has escalated the speed, scale, and complexity of attacks, moving the security game from a battle of wits to a battle of compute power. Aaron discusses how attacks that once required human ingenuity are now orchestrated by AI agents, capable of chaining vulnerabilities that humans would struggle to conceive.

We get into the shift from a reactive to a proactive security posture across the WordPress ecosystem. Aaron explains how both attackers and defenders are now deploying AI leading to an arms race, where AI is used to combat AI, and where collaboration among security teams is just as crucial as information sharing among adversaries.

Which chat about the motivators behind attacks, spoiler, it's almost always money. And the specific vulnerabilities WordPress faces as the most popular CMS on the web. Of interest is the narrowing window between when vulnerabilities are discovered and when they're exploited, how supply chain attacks are on the rise, and what the WordPress "Protect the Shire" innovation means for plugin security.

Towards the end of the episode, we explore practical security advice for everyday WordPress users, with Aaron, recommending actionable tips on updates, choosing security minded hosts, and monitoring for Compromise credentials.

If you are concerned about how AI is reshaping the WordPress security landscape, and want to know how the community is responding, this episode is for you.

If you're interested in finding out more, you can find all of the links in the show notes by heading to wptavern.com/podcast, where you'll find all the other episodes as well.

And so without further delay, I bring you Aaron D. Campbell.

I am joined on the podcast by Aaron Campbell. Hello, Aaron.

[00:03:43] Aaron D Campbell: Hello, nice to be here.

[00:03:44] Nathan Wrigley: Yeah. Thank you for joining me. We're in a corridor. I should say that at the very beginning. We're in a corridor at WordCamp US, and so if background noise becomes a problem, we're just going to have to cope with it. So apologies. But thank you for joining me in a corridor.

[00:03:57] Aaron D Campbell: Absolutely.

[00:03:58] Nathan Wrigley: We're going to talk today a little bit about WordPress security, and particularly about the advent of AI, and the way that certainly in the more recent past, it appears to have upended what once was normal, I think it's fair to say. I think things are happening at a rate of knots that perhaps a year or two ago we wouldn't necessarily have predicted.

Do you want to just give us a little bit of background about yourself in terms of where you have worked, where you currently work, and what it is that you do for a living?

[00:04:25] Aaron D Campbell: Sure. So I guess I have worked in the internet space for a very long time at this point. I guess 25 years-ish. Ran my own agency for a long time and then into security product in the WordPress space, and over into hosting at GoDaddy, at Newfold, at hosting.com.

During that time I ran the WordPress security team for a couple years, have continued to be involved with it along the way, and now I am over at Monarx. We do malware detection and remediation, and have some security tooling for web hosts. So I'm still very tightly tied into that space on a few fronts.

[00:05:09] Nathan Wrigley: Is Monarx a new company? Because it's not one that may necessarily come into mind when we talk about security online, WordPress security specifically.

So if you're willing, could you just give us a little bit of a potted history of Monarx and what specifically you do in the WordPress space? I think it's perhaps more related to hosting companies than it might be to end users. Just flesh that out a little bit.

[00:05:33] Aaron D Campbell: Yeah. Monarx has been around probably longer than you expect, six or seven years. The name's may be not as recognisable, because a lot of times we are a white label in the background. Hosts run us, and you may not know that.

We protect more than just WordPress, but obviously WordPress is a big part of that. And we help hosts keep their users, their end users, safe and secure and malware free by monitoring the files, the runtime, having a WAF layer, protecting it several different layers along the way.

[00:06:08] Nathan Wrigley: So is this kind of like a white label solution? You are in talks with hosts, many of which I'm sure we've heard of, but their purchase of the products and services that you sell is white labelled.

[00:06:20] Aaron D Campbell: Yes, they may sell us as their own security product. They may also just include us in higher end hosting packages so that the malware detection and remediation and all that kind of stuff is included in your package. It varies from host to host, but most of the time you're not seeing the Monarx name out in front, but you're benefiting from our services anyway.

[00:06:40] Nathan Wrigley: So does that allow you to, because you are cross platform in terms of hosting company, hosting company X, hosting company Y, hosting company A, B, and C. Does that give you a larger depth of knowledge for want of a better word? So you can see that hosting company A's got this Linux set up, and these kind of things are happening.

[00:06:59] Aaron D Campbell: Yes, it does. It's less about their specific setups. I think the most valuable thing of being across many hosts like that, is that we see attacks, or new and novel malware, or those kinds of things happening in pockets and can often then protect against it globally, even though maybe it first started at host A.

By the time it spreads to host B X or Y in your example, we've already been able to understand what that is and block it across the whole realm. So we get a bigger picture, which is super useful. Especially as we start talking about some of the AI stuff and how fast it moves. That's really necessary to stay ahead of that curve.

[00:07:42] Nathan Wrigley: Okay, so let's move into that a little bit. And I think if we were having this conversation, let's go for four years ago, that seems like a long enough period of time where AI was not really on anybody's menu.

And now we seem to be in the era where the human is really being surpassed in almost everything logical, let's go with that word. If it can be achieved with some kind of logic then AI seems to have surpassed humans.

And, especially recently, there seems to have been an uptick, not just in the WordPress news cycle, but also just in the general news cycle about, okay, we need to be a little bit more mindful about the products and services that we buy. We need to be more mindful about the security and logging in and credentials and all of that.

But specifically in the WordPress space over the last three or four months, I've heard story after story, which was unlike anything I'd heard before. These kind of chained attacks where, something that a human probably would never have conceived and pulled off is now possible. You spend 25 US cents on an AI agent, wait for six hours, and it's come up with these 14 overlapping things, and it can hack WordPress Core and various other things.

So just paint the landscape of how alarming it is, and then presumably you can paint the landscape of how not alarming it is, because how you can mitigate against that.

[00:09:00] Aaron D Campbell: That's fair. Let's explain the reality and then let's hopefully, help comfort people at least a little. It can be pretty scary. You're absolutely right. AI has dramatically changed the game. And the way I like to explain it is it hasn't changed the absolute core realities of the game in that there's still a bit of cat and mouse. They're trying to surpass us. We're, trying to stay ahead of them.

But the scale and the speed and the complexity at which it is able to happen now is nothing we could have imagined four years ago. Honestly, even two, two and a half years ago. It has moved that fast. And what that looks like are, a few different things.

One, the speed at which AI can find issues in code, potential exploits, vulnerabilities, et cetera, is so much faster than any human. Like the compute power of it doing those logical bits rather than humans doing those logical bits, makes that move so fast. So the number of things being found, and being either reported or exploited, or both, the volume has just gone up dramatically.

And then on the complexity side of it, you are right. A simple example of that, one of the WordPress Core reports that I looked at recently, I needed to print it out and mark it up with a pen to wrap my brain around all these steps that it was taking. When I printed it out, it was 11 pages. 11 pages of like steps and instructions for an actual vulnerability that turned out to be real.

If four years ago that had existed in your piece of software, you would consider your software absolutely secure. No human's ever going to find that. No one would ever know about it. And now AI is able to chain all those steps together into something that it can then write scripts to go automate and exploit.

And so those two things have both really shifted the game in a way that feels like it can put software owners, software managers, SaaS services, all these things on their back foot. There's just such this flood, and such a complex flood coming at you.

[00:11:10] Nathan Wrigley: So I guess also the problem is that these things never sleep. So four years ago, every human, maybe they could put 10 hours in at the computer and then they would have to rest. So you get a, breathing space, and and the human can do this one thing.

But that's not the case here. With an AI, presumably it could have 10, 50, a hundred, a thousand, the sky is the limit, things happening simultaneously. Just testing absolutely every permutation of everything conceivable. And then coming back with something. I don't even know how we compete against that. And obviously we can get into that in a moment.

Is this a moment of despair or is there genuinely a way of getting out ahead of it? Or is it always going to be a case looking into the future where you are going to be reactive instead of proactive? In other words, when you wake up in the morning and you print out the 11 and then next year, the 30, and then the year after that, the 80 page document, how does that make you feel? Are you sanguine or is it just a prophecy of doom.

[00:12:08] Aaron D Campbell: I think it is a time of overwhelm, but hopefully not despair. Which is different. And I think that as big technology shifts hit, which AI is a big technology shift. There is often a significant adjustment. And we are at that time, and I am even one that maybe would say, I think it might get a little bit worse before it gets better, but it's definitely going to get better.

And I see the path there in some of the foundations that we're laying in things that we're learning right now during this time of overwhelm, where we're feeling flooded like this, is going to put us in a place to start getting into that curve where everything gets better.

And I think that, what's the right way to put this? I think that the path there is apparent, but takes some time. And part of that's because we have to shift from the being reactive to the being proactive all the time. Because agents move so fast to 24 hours a day, seven days a week. And the second they find a thing, they can immediately, automatically start trying to exploit it.

We have to shift to being ahead. Because there is no longer a gap in between when a thing is found and when it's exploited, for us to fix the thing. We have to get ahead.

[00:13:36] Nathan Wrigley: So, you are obviously deep in the weeds of this, and it sounds like you've got an intuition that at some point in the near to midterm future, you feel like you are going to reach a point where things start to improve. That was the implication, I think of what you said.

What is that intuition? How do you come to the conclusion that there is an opportunity for things to improve. Even if you need to go into the weeds a little bit. I'm curious as to how it's not a prophecy of doom, and how you believe that a moment will arrive where, I can't answer that for you. I'll just open it up.

[00:14:06] Aaron D Campbell: Yeah. So I think that some of this comes from historical experience, right? We've had these kinds of experiences where say, a certain type of hash that we used for security became a thing that hackers could break with the level of computing power that they finally had access to.

And that felt doom and gloom. But also we created better hashing algorithms. We created better things that were able to counteract that. We were able to shift to those, and we were also able to learn from them and think further forward.

So now some of the algorithms that we're using aren't just better enough to handle current computing, but better enough that we think they're going to last a decent ways into the future.

I think that there are similar things with AI now. Where we are leveraging the same kind of tools now that these bad actors are, and we're learning how to use them not just to protect against the way the bad actors are using them, but to get ahead enough to stay ahead of them.

And the way that looks, because that sounds maybe too vague to be realistic I guess, is we're not just running those same algorithms against our code, or those same models against our code and hoping that we find the stuff before they find it. We're instead also looking at how can we push to a different part of the stack? How can we protect against things that we've never seen? How can we start to recognise these patterns so that we can look at behaviours and protect against those, rather than just flaws that need to be patched. It's shifting our thinking some, but I think in a way that's going to help us get ahead in this game.

[00:16:03] Nathan Wrigley: Okay. That's really interesting. I have a question surrounding how this kind of stuff happens, and I'm thinking about it from the adversarial's point of view. What is that like? Because I have a notion that a decade ago it was individuals, perhaps offices, that's probably the wrong word, but, collections of people sitting in a space, but there would be a finite number of them. There may be 10 in a room, one in a room, a hundred in a room.

But I don't know if that's still the case. Do the adversaries that you are dealing with, do they have a collaborative approach to hacking? Do they share information? And then the flip side of that is do you also, in the industry that you work in, do you share information?

If you discover something, does Monarx treat that like it's your intellectual property? Or is there a, a whole system of sharing that amongst the community so that everybody benefits from the work that you do? You're giving away the hard work that you've done. If that's the case.

[00:16:59] Aaron D Campbell: So, first let me just say personally, one of the most important things to me is to raise the level of security across the whole internet, because that is better for humanity that relies on it so much, for all kinds of things in our daily lives, and for sharing information and making progress forward as people.

I think that I'm not alone in the space. Like I think that a lot of us that were drawn to this security space are drawn to it because it is a way to improve life for everybody. Will there be some intellectual property for individual companies? Yes, but I think it's a lot more in how we approach the thing, and less we're not going to tell people about this new vulnerability, or this new method that we found. Because we do want to be able to see the end user protected. Like that is the way we're going.

Backing up to your, how do the adversaries work? It's been a long time, I think since they sat in rooms together. They're now virtual rooms, right? They can be spread all over the world, but still be working together. And they definitely do. They share information around. For us to be able to keep up with that, we have to share information around too. That is super important.

Simple example of that, the WordPress Security Team. Let me step back from Monarx and talk more of the space in general. The WordPress Security Team. You talked about how for the last few months you've seen maybe more security releases going out from WordPress and stuff. The way that the WordPress Security Team treats those, when we find out about them, and we triage them, and we realise that they're real, and we start figuring out what our approach is to patching them. We then have a whole private Slack channel that has other people in it that can help us get protection out. Broader, wider by sharing some of that information sooner.

Cloudflare can maybe put some rules in place, and protect tonnes of people before the WordPress release goes out. So can some of the big hosts. So can some of the security groups. And so not only do we share that information, we've built it into our processes as a must, because that's the only way to really do it right, and really protect as many people as possible. Because our adversaries are doing that. And so we have to as well. And we've just realised that, learned from it and made that the right way to do it.

[00:19:26] Nathan Wrigley: I'm just going to flip back to the comment that you made a moment ago where you said that you woke up and you printed out this summation. Let's go with that. And it was 11 pages, and presumably that took a certain amount of your day to parse and understand.

How likely is it that that process will begin to run away from humans' capacity to actually do it? So as an example, let's say that a year from now that thing that you print out is 50 pages or 80 pages. Just the reading of it would be a whole morning, let alone the understanding of how those layers, and the stacks and the way that they're overlapping and reliant upon each other.

Have we now, or have you now as an industry, have you almost handed the responsibility to figuring that stuff out, figuring out what the adversaries are doing? Has that gone to AI from your part as well? So is it AI versus AI basically, which seems very dystopian.

[00:20:18] Aaron D Campbell: We definitely pit AI against AI. It's an extremely useful tool to combat itself essentially. And yeah, even for that 11 page one. Yes, I had to read through it and figure it out. but I did use AI to help summarise that. What are the steps that I need to do? Where does this actually track to in the code base?

I use it as an assistive tool in getting through that. And I do think that the longer the reports get, the more that's going to be necessary. And now I personally, and several other people that I work with, have built testing rigs in AI, in various models, that are purpose built to help with this.

I can give it a report, in the repository and it can check its viability. It can see if that's simplified. Check certain things. Is this a thing that requires some level of authentication, all these things that we use to have to do manually. And now we're sharing around these sort of test rigs, or assessment rigs, that use this so that we can all use them, and grow them faster and make them better and make them more efficient. Because we are pitting AI against AI in many ways.

And as human, I think that it's still important for the human to guide the process in a way that's ensuring the fix is forward thinking enough, and that it's in the right place and whatnot. Because in the end, the software is largely used by humans. But, in order to scale to the level that AI is pushing us to scale to, the human needs to be the decision maker, and possibly the opinionated one on form, and function, but not the logical power behind any of it now.

[00:22:01] Nathan Wrigley: Do you get the sense that WordPress itself is the target, or is WordPress just a bit of collateral damage? Are these adversaries of yours, are they specifically targeting WordPress because it's got this giant footprint? Or is it more a case of this is just the adversaries just spraying and scatter gunning, and it just so happens that every so often they stumble across a WordPress thing.

[00:22:23] Aaron D Campbell: There is spray and scatter gun, just not running WordPress, or running your own bespoke thing is not enough to get away from AI trying to break your thing. But the bigger you are, the bigger the potential benefit from finding an exploit in you. And therefore, the more you are, like the bigger you are, the target is on you.

So WordPress has a big target, but it's not just WordPress. Some big hosting companies also have a big target on their infrastructure in the same way that they're targeting WordPress, their targeting, maybe a Hosting or a GoDaddy or a Blue. Someone big that has many people on it, not because they think their security is lax, or that they have some reason to suspect that there's vulnerabilities, but because the payoff of finding a vulnerability there can be big. And so there's a big focus there.

So yes, the bigger you are, the bigger the target. But that doesn't mean that the scattershot isn't also happening. And that they're not also hitting small targets.

[00:23:24] Nathan Wrigley: Yeah. I suppose there would've had to have been a lot of joined up thinking in the past from a human to discover that, "Okay, this thing with Linux over here, okay we'll just store that somewhere. But then there's a PHP thing over here. Oh, and then curiously, there's a PHP thing in WordPress, which," that would've all had to have been conjured up by a human. And the memory of that would be difficult to maintain over time. But presumably the AI can just remember that forevermore. Store that PHP thing for the next decade and suddenly whip it out when it's happens to coincide with some other thing. It's fairly bleak.

Okay, so in terms of WordPress specifically, what is the incentive specifically? Why would somebody, let's say somebody was coming after WordPress. What is it that they gain? What could they possibly have that benefits them off the back of a, let's go for WordPress Core vulnerability which is, I don't know, you can successfully log in as an admin or whatever it may be. What do they actually gain?

[00:24:17] Aaron D Campbell: It really comes down to money in end, if I'm honest. WordPress Core powers tens of millions of sites all over the web. Some of those have valuable stuff on them. Many of them frankly don't. But that doesn't mean that they're worthless. They can be used, you've seen pharma ads and stuff showing up on a site, and it's a pay per click kind of thing. And someone's making some money off of putting not great ads your site. Even if you don't get a lot of traffic, they're making something. And when you're looking at the potential of this vulnerability could apply to tens of millions of sites, you don't need to make much per site.

But also, you could use that site as a way to have broad compute power to attack some other site. You're using tens of thousands of sites to do it. Each one of them is on some separate IP. So now you have a distributed attack that's harder to block than if you were doing the same attack from one place.

But you're only doing that because it costs a lot to buy your own distributed power from everywhere. So you're essentially stealing it and it's making it, there's some sort of worthwhile monetary value from it.

And so you may think, they can't make anything off my site. They don't have to. Your site's one small bit in a huge array of sites that they're trying to get, to get some monetary benefit in the end.

[00:25:40] Nathan Wrigley: So there's no one size fits all. But money is essentially the broad overlapping thing?

[00:25:46] Aaron D Campbell: I mean, there are exceptions to that, where people are doing it for some political reason. Or some moral directive that they have or whatever. But the vast majority can be traced back to there's money in it somewhere.

[00:25:59] Nathan Wrigley: I wonder curiously, because you mentioned about things like, pay per click style, you take oversight and you flood it with, I don't know, nonsense about the thing that you've got and you want the world to notice. I wonder if curiously, people's adoption of AI and that different way that we're searching for things will actually impoverish that way of monetizing, because simply nobody's actually looking on a search, well, increasingly people seem to be relying less and less on a search engine, and so maybe that kind of bit of it will dry up. Who knows?

[00:26:27] Aaron D Campbell: I love the optimism there. And I would like to think that those ads specifically probably will at some point. But the root of how those work is, I've broken into a site and I can inject some JavaScript ad, or some something like that.

And if those ads stop being valuable, then maybe I can inject some AI directives so that when an AI agent of some kind hits that site, it's getting some sneaky thing snuck into its memory, or pulled in as a skill, that can then use that AI agent for nefarious purposes in the future.

I think that we can't lower our guard against those things, because our adversaries will pivot and reuse it for something else. And so we will continue to protect against it.

[00:27:13] Nathan Wrigley: I'm going to peel back the contents of your head a little bit here. Because I've often wondered what the characteristic is of somebody like you who constantly facing this tidal wave of things. You've got to get up every morning, and every morning you could potentially wake up to the next big thing.

How do you just remain calm in the face of all of it? It's a peculiar question, I realise, but tomorrow could be the next big thing. The day after that could be the next big thing. I'm imagining on most days now there is not necessarily the next big thing, but there's a thing. It's like you're a fireman or something, except that there's a fire going off in every district of town, and you are constantly busy and you never get to put the fire hose down. You're just constantly at work.

[00:27:52] Aaron D Campbell: Some of us love that little consistent regular shot of adrenaline, and we get it in different ways than the firemen. But, honestly, I love complex problems solve. I love the challenges. Do I get exhausted and burnt out at times when they really do come every day for X amount of time? Sure, I'm human, I need to sleep, et cetera. But I think that it's because I enjoy figuring out those really difficult problems, that I enjoy being in this space. And even specifically on this side of the space, the white hat side.

[00:28:26] Nathan Wrigley: Yeah. I suppose it's like playing a good opponent at chess. You enjoy the chess game, even though it's a hard thing and it stretches your brain. You play the chess over and over again because it's a pleasurable thing to have your brain exercised in that way.

[00:28:39] Aaron D Campbell: And it's like the more you do it the better chance you have at winning at chess. And I think it's the same way in our game, right? Like the more you're doing it, the more ways you're finding to outmanoeuvre and to essentially win, and keep people safe online. And that's, that's exciting.

[00:28:56] Nathan Wrigley: You get the fist pump moment do you, there's once in a while where you literally figure something out and you're like, I nailed that.

[00:29:04] Aaron D Campbell: You absolutely do.

[00:29:04] Nathan Wrigley: Okay. Yeah. That's really interesting. Your bio reads like an open source manifesto. I know that open source has been the thing for you throughout your career. I imagine that you could have gone into proprietary security and all of that.

But how does open source, particularly WordPress, how does that approach to developing software, how does that benefit the position that we can take and the security posture that you can take, and the reliability that you can have in things like WordPress going forwards? In your head, does it offer a superior model for fighting the adversaries?

[00:29:35] Aaron D Campbell: Yes, in my opinion it offers a superior model for fighting the adversaries. And the reason is actually still the same as it was 20 years ago when I started doing this. And I'll explain why in just a second, but first, the reason is because we are able to benefit from many intelligent people, many more than any single company could with their source code.

Looking at our source code, and finding the weaknesses and even pitching in to help fix them. Hundreds of thousands, or millions, of people around the world are looking at our source code, finding those issues, and able to help pitch in and fix them, or report them to us so that we can, by having all that out there, it's sort of like a building's not less likely to collapse because no one saw the crack. It's actually better that people are inspecting it, and finding those things and making sure it's done right.

Now, that has shifted a little bit now, where in the past our adversaries looked at our source code too, right? They would immediately look at our repository when new things went out. As a matter of fact, when I ran the security team, I stopped committing stuff for a while, because it turned out that was a tell that this thing was probably a security issue, and people would look at that and try to figure it out.

So now the adversaries are using AI to watch our source code, which is also open to them, 24 7 and really look deep at it. But so are those many thousands of people using our source code for good. And so it's still true that we have so many people on our side in helping us out, because our source code is out there because we're open source, and it outweighs the bad. We find things faster because of that, and ultimately end up with more secure software more rapidly.

[00:31:36] Nathan Wrigley: Is there ever going to become a time where the amount of time that a vulnerability is available becomes moot? So in the past, a six hour window, where something wasn't patched in WordPress Core, that's a thing, but it's not really a big thing. Maybe a month where something's unpatched, that's a big, I'm just wondering if in the future with the nature of the adversaries that you described and the tooling that they can bring to bear, if even like a three or five second window is going to become a thing.

[00:32:05] Aaron D Campbell: That is possible. We're not at the three to five second window yet, so that's good. I'll let everybody relax a little bit. But the time from vulnerability disclosure to exploitation has shrunk dramatically over the last few years.

We did in fact used to have weeks, and then eventually days where it was okay to find out about the vulnerability, and responsible people, or responsible hosts, or responsible software companies could see that disclosure, patch the problem before there was much exploitation at all. And that's now hours for major vulnerabilities.

As a matter of fact, we did a Monarx in conjunction with Patchstack, did like a year in review, thing looking back at last year. And we saw that for the more major vulnerabilities, it was about five hours. That's not enough time for, you know, what happens if it happens in the middle of the night for a host who's constantly monitoring that, immediately patching it, that's difficult. And I do think that it will continue to shrink. And that that time that causes risk will be shorter and shorter.

And, we saw that with the recent wp2shell WordPress exploit. Once we released the patch, and everything was out there, the spike of exploitation that we as Monarx saw, like monitoring stuff happened within 30 minutes. Honestly, even a little bit faster than that. But the big spike started coming in about 30 minutes later, and that is just really fast.

But on the flip side, all that coordination that I talked about that WordPress did, had many millions of people already protected by then. And that's how we have to look at it. We have to say, this is eventually going to get down to three to five seconds being a problem. How do we get ahead of it? And that's what we're trying to do.

[00:34:03] Nathan Wrigley: So a timely thing at the moment is this new innovation in the WordPress space called Protect the Shire. And Protect the Shire is the, a time bound moment where a plugin that has an update, it can't be updated at the moment, I believe it's standing at something in the region of six hours. On the face of it, that seems like a really excellent posture. But then there's the flip side of that. If an exploit becomes discovered, and nobody can update their plugin for six hours, then that's a big six hour window we've just painted. in the future where milliseconds may count. What do you think about that? It's a interesting innovation. It's something new. It was worth a try. Do you think that's the way forward?

[00:34:41] Aaron D Campbell: I think it, was not only worth a try. I think it was a really good choice, and I think it will continue to be. We are seeing that a lot of current attacks are essentially supply chain attacks. How can we compromise whether it's some package, an NPM package or something like that. Or whether it's a plugin that's gotten sold to a nefarious person, or even just hacked into and taken over by a nefarious person. That is happening more and this six hour gap helps protect against that.

But it can't be a hard and fast, locked in stone, can never have exceptions, rule. And the truth is, it's not. If there is a vulnerability in your plugin, or especially in a major plugin, reach out to the WordPress Security Team because we can coordinate a faster release, we can make an exception to that rule when it's necessary.

And I think that for security fixes that are clearly security fixes that exception iss an easy one to make, because we do want to protect immediately. But slowing things down enough to make sure that there's not been some sort of supply chain issue that is actually going to cause a vulnerability rather than fix one, is smart.

And so I think that it will find the right balance there as we continue to move forward, and figure out how to make better processes around this, to make it easier to do the right thing all the time, and know exactly which of those right things. But I think at the moment we're in a pretty good place there and continuing to find the exact right place.

[00:36:18] Nathan Wrigley: It feels from the outside as if security's fairly binary. On the one hand, adversary on the other hand, good guys. On the one hand hacked, on the other hand, not hacked. It's black and white. But it seems from everything that you've been talking about today, that you are occupying a really grey area. You're just trying to figure out what the path is forward. You're constantly staring into the future trying to figure out what the adversaries are doing. Trying to patch, trying to make sure that everything is as good as it possibly can be. And I hadn't really thought about it in that way. It's not, there is no destination here where everything's white. It's a journey and every day's going to be a bit grey. There's going to be a bit of black and a bit of white, but a lot of grey in the middle.

[00:36:58] Aaron D Campbell: I don't really look at it as grey, but I can see where you're going there. But I think that there is this black and white, and then there's sort of the cloudy. The further forward you look, the more difficult it is to know exactly where the black and white are always going to be. And some of that sort of comes across as grey. It's a little blurry. You can't quite figure it out.

But you're right. there's some prediction. There's some, we think that moving this way is going to cause more white and less black. And that's what we're, that's what we're constantly aiming for. But you can't just say turning right always makes things more white. Because sometimes there could be black over on that side somewhere, right? You're really trying to be predictive, but not just randomly predictive, right?

Many of the people like myself that are trying to help guide this path forward, and even more than me, some of the people like Matt, who instituted that wait policy and some of the people that are running the WordPress Security Team, we have decades of experience watching this, that's helping to inform our predictions. And so it's not, we're not just willy-nilly guessing. And I think that's important to point out to the people that rely on us, to help guide them to the right space going forward.

[00:38:02] Nathan Wrigley: Yeah. Okay. So my schooling in chemistry was pretty basic, but I know that if I want to understand chemistry, my quickest way to do that is to rely on an expert, is to go and find a chemist who has years of experience. And, the same would be true here. I think most of us have probably not got the capacity to actually get a hold of what you're saying. We, understand that your expertise is what we need to be listening to. But I'm just wondering for a typical WordPress user of whom many listen to this podcast, they have a WordPress site, but they're not really interested in security, other than how it may impact their business.

So I'm going to ask for some very basic advice here. What would be the 1, 2, 3 things that somebody using WordPress with no security credentials whatsoever. What would be the few things that you would advise them to either go and read, or go and do, or go and think about?

[00:38:51] Aaron D Campbell: Yeah, so I think the biggest thing that I would encourage them to do, is essentially position themselves in such a way that they are relying on the experts, right? You're not an expert and that's okay. No one can be an expert in everything. But there are some things you can do to position yourself such that you're benefiting from those experts.

One of those is updating as fast as possible. So WordPress auto updates turned on, those kinds of things. This WordPress Security Team that I'm talking about that has so much expertise in the area, and their whole focus is trying to make sure that WordPress is always secure. That lets you rely on them to help keep your site secure.

I think in similar ways, you want to find the right host that is also doing those security focused things for you, so that you don't need to. And maybe that's asking your host, what do you do to keep me safe? We talk about security, like the best security is layered security. It's almost like having a gate at the complex, but also having a lock on your door, right? Those kinds of things. You can ask your host, what do you do to protect me in a layered way?

And maybe that question doesn't make sense to you, and maybe even their answers don't make sense to you, but if they have an answer, that's good for you. It means that you can rely on their expertise.

And then stepping out of the obvious space to give a third thing that people should be doing. And this is, this may sound out in left field, but you should get some form of dark web monitoring for yourself, for your own credentials. And whether that's going to someplace like, Have I Been Pwned, and looking at your own email address, and passwords and seeing if they've been in some breached data from somewhere, and are now being sold on the dark web. Or whether that's using some service that offers it. I think that's important, more so now than it's ever been.

Because one of the other things that AI is doing that it's particularly good at is collecting all this massive amount of breach data that's happened over the last couple decades, that's being sold on the dark web. Collating it all and saying, oh, we see that, gosh, 15 years ago, an account that Aaron had was in a breach. And we now know one of his passwords.

And granted it's 15 years old, but it's very easy for that AI to then say, where is Aaron now? What's he doing? What can we learn about him? He works at Monarx. I wonder if this password works for his Monarx account. I wonder if this password works for the bank that he's at. Or this other tool that we see that he uses. Let's try all his social media accounts.

And so knowing whether that's out there and being able to, you can't get rid of that data, but being able to do things to protect yourself because you now know it's out there is more important than it's ever been.

[00:41:47] Nathan Wrigley: I hope you take this in the spirit in which it's offered, but I really do wish to live in a world where you don't have a job.

[00:41:55] Aaron D Campbell: Me too.

[00:41:56] Nathan Wrigley: But, am glad that we live in a world where you do, somebody like you does have a job. So I hope that landed correctly.

[00:42:02] Aaron D Campbell: If I could work to the point where I could work myself out of a job, I would find a new career and I would feel so accomplished, you couldn't even imagine it. I'm okay with that.

[00:42:12] Nathan Wrigley: Yeah. Good. Aaron, just before we wrap up, is there a place where you hang out online where people could poll you if they've got a question, or any thoughts about what we've talked about?

[00:42:21] Aaron D Campbell: Yeah, if you're looking for me professionally, you can find me Monarx.com, M-O-N-A-R-X.com. I also have aarondcampbell.com if you want some of my own more personal takes on security and things. And you can find me on Bluesky or the WordPress Slack. Those are probably the biggest places I'm at.

[00:42:40] Nathan Wrigley: What I will do, dear listener, into the show notes, if you go to wptavern.com and you search for the episode with Aaron Campbell, you'll be able to find the links. I will dig out the Bluesky, and the various social links and the Monarx website and what have you, so you don't have to hunt around too much. Go there wptavern.com. And Aaron, thank you so much for chatting to me today.

[00:43:01] Aaron D Campbell: Thank you. This was a really fun talk.

On the podcast today we have Aaron D Campbell.

Aaron is a seasoned veteran in both the internet and WordPress space, with over 25 years of experience spanning agency work, security products, hosting giants like GoDaddy and Newfold, and now his role at Monarx, a company focused on malware detection and remediation, particularly for web hosts. He's led the WordPress Security Team, has been deeply involved in shaping security practices, and remains tightly connected to the WordPress ecosystem.

We talk about the rapidly changing landscape of WordPress security, specifically how the advent of AI has escalated the speed, scale, and complexity of attacks, moving the security game from a battle of wits, to a battle of compute power. Aaron discusses how attacks that once required human ingenuity are now orchestrated by AI agents capable of chaining vulnerabilities that humans would struggle to conceive.

We get into the shift from a reactive to a proactive security posture across the WordPress ecosystem. Aaron explains how both attackers and defenders are now deploying AI, leading to an arms race where AI is used to combat AI, and where collaboration among security teams is just as crucial as information-sharing among adversaries.

We chat about the motivators behind attacks, spoiler, it's almost always about money, and the specific vulnerabilities WordPress faces as the most popular CMS on the web. Of interest is the narrowing window between when vulnerabilities are discovered and when they're exploited, how supply chain attacks are on the rise, and what the WordPress "Protect the Shire" innovation means for plugin security.

Towards the end of the episode, we explored practical security advice for everyday WordPress users, with Aaron recommending actionable tips on updates, choosing security-minded hosts, and monitoring for compromised credentials.

If you're concerned about how AI is reshaping the WordPress security landscape, and want to know how the community is responding, this episode is for you.

Useful links

Aaron's website

Monarx website

Monarx and Patchstack's State of WordPress Security In 2026

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Protect The Shire

Have I Been Pwned

Aaron on Bluesky

02 Sep 2026 2:00pm GMT

31 Aug 2026

feed20SIX.fr

Les meilleurs revêtements d’allée en 2026 : classement par budget et durabilité

Les meilleurs revêtements d'allée en 2026 : classement par budget et durabilité

Quel revêtement privilégier pour une allée durable ? Comparez coûts, longévité, drainage et entretien des meilleures solutions de 2026 pour bien investir !

L'article Les meilleurs revêtements d'allée en 2026 : classement par budget et durabilité est apparu en premier sur 20SIX.fr.

31 Aug 2026 4:51pm GMT

Comment bien assurer sa trottinette électrique : comprendre ses obligations et ses besoins de protection

Assurer sa trottinette électrique : obligations et besoins de protection

Trottinette électrique et assurance vont de pair. Obligations légales, garanties et niveau de protection, faites les bons choix pour rouler bien couvert !

L'article Comment bien assurer sa trottinette électrique : comprendre ses obligations et ses besoins de protection est apparu en premier sur 20SIX.fr.

31 Aug 2026 3:52pm GMT

02 Jan 2024

feedL'actu en patates

Bonne année 2024

Acheter des originaux sur le site LesDessinateurs.com Vous pouvez me suivre sur Instagram, Bluesky ou Facebook.

02 Jan 2024 10:41am GMT

01 Jan 2024

feedL'actu en patates

Une année de sport

Dans le journal L'Equipe du dimanche et du lundi, vous pouviez trouver un de mes dessins en dernière page. Voici un petit échantillon des dessins réalisés en 2023 pour le quotidien sportif. Acheter des originaux sur le site LesDessinateurs.com Vous pouvez me suivre sur Instagram, Bluesky ou Facebook. Acheter des originaux sur le site LesDessinateurs.com Vous …

01 Jan 2024 9:11am GMT

30 Dec 2023

feedL'actu en patates

Attention aux monstres !

Acheter des originaux sur le site LesDessinateurs.com Vous pouvez me suivre sur Instagram, Bluesky ou Facebook.

30 Dec 2023 1:06pm GMT

15 Feb 2022

feedCooking with Amy: A Food Blog

How to Use Bean and Legume Pasta

Much as I love pasta, I'm not sure it loves me. Last year my carb-heavy comfort food diet led to some weight gain so I looked into low carb pasta as an alternative. There's a lot out there and I'm still trying different brands and styles, but I thought now would be a good time to share what I've learned so far.

Pasta with Butternut Squash and Brussels Sprouts

My introduction to legume and bean-based pasta was thanks to Barilla. I was lucky because I got to attend a webinar with Barilla's incredible chef, Lorenzo Boni. I tried his recipe for pasta with butternut squash and Brussels sprouts which I definitely recommend and have now made several times. If you've seen his wildly popular (150k+ followers!) Instagram feed you know he's a master at making all kinds of pasta dishes and that he often eats plant-based meals. I followed up with him to get some tips on cooking with pasta made from beans and legumes.

Pasta made with beans and legumes is higher in protein and so the recommended 2-ounce portion is surprisingly filling. But the texture isn't always the same as traditional semolina or durum wheat pasta. Chef Boni told me, "The nature of legume pasta makes it soak up more moisture than traditional semolina pasta, so you always want to reserve a bit of cooking water to adjust if needed." But when it comes to cooking, he says that with Barilla legume pasta you cook it the same way as semolina pasta. "Boil in salted water for the duration noted on the box and you'll have perfectly al dente pasta." They are all gluten-free.

Chickpea pasta

When I asked Chef Boni about pairing chickpea pastas with sauce he said, "Generally speaking, I prefer olive oil based sauces rich with vegetables, aromatic herbs and spices. Seafood also pairs well with chickpea options. If used with creamy or tomato-based sauces, keep in mind to always have some pasta water handy to adjust the dish in case it gets too dry." He added, "One of my favorite ways to prepare a legume pasta dish would be a simple chickpea rotini with shrimp, diced zucchini and fresh basil. The sauce is light enough to highlight the flavor of the pasta itself, while the natural sweetness helps keep the overall flavor profile more appealing to everyone." I like the Barilla brand because the only ingredient is chickpeas. Banza makes a popular line of chickpea pasta as well although they include pea starch, tapioca and xanthan gum.

Edamame pasta


I tried two different brands of edamame pasta, Seapoint Farms and Explore Cuisine. The Seapoint pasta has a rougher texture than the Explore. With the Seapoint I found the best pairings were earthy chunky toppings like toasted walnuts and sautéed mushrooms. The Explore Cuisine edamame & spirulina pasta is smoother and more delicate, and worked well with an Asian style peanut sauce. I was happy with the Seapoint brand, but would definitely choose the Explore brand instead if it's available.


Red lentil pasta

Red lentil pasta is most similar to semolina pasta. Barilla makes red lentil pasta in a variety of shapes. But for spaghetti, Chef Boni says, "Barilla red lentil spaghetti is pretty flexible and works well with pretty much everything. I love red lentil spaghetti with light olive oil based sauces with aromatic herbs and some small diced vegetables. It also works well with a lean meat protein." I have to admit, I have yet to try red lentil pasta, but I'm excited to try it after hearing how similar it is to semolina pasta. It is made only with red lentil flour, that's it. It's available in spaghetti, penne and rotini.

Penne for Your Thoughts

Do you remember seeing photos from Italian supermarkets where the shelves with pasta were barren except for penne? I too seem to end up with boxes of penne or rotini and not a clue what to do with them so I asked Chef Boni his thoughts on the subject. He told me, "Shortcuts such as rotini and penne pair very well with all kind of ragouts as well as tomato based and chunky vegetarian sauces. One of my favorite ways to prepare a legume pasta dish would be a simple chickpea rotini with shrimp, diced zucchini and fresh basil. The sauce is light enough to highlight the flavor of the pasta itself, while the natural sweetness helps keep the overall flavor profile more appealing to everyone." Thanks chef! When zucchini is in season I know what I will try!

15 Feb 2022 6:46pm GMT

23 Nov 2021

feedCooking with Amy: A Food Blog

A Conversation with Julia Filmmakers, Julie Cohen and Betsy West


Julia is a new film based on Dearie: The Remarkable Life of Julia Child by Bob Spitz and inspired by My Life in France by Julia Child with Alex Prud'homme and The French Chef in America: Julia Child's Second Act by Alex Prud'homme. Julia Child died in 2004, and yet our appetite for all things Julia hasn't waned.

I grew up watching Julia Child on TV and learning to cook the French classics from her books, And while I never trained to be a chef, like Child I also transitioned into a career focused on food, a subject I have always found endlessly fascinating. I enjoyed the new film very much and while it didn't break much new ground, it did add a layer of perspective that can only come with time. In particular, how Julia Child became a ubiquitous pop culture figure is addressed in a fresh way.


I reached out to the filmmakers,Julie Cohen and Betsy West to find out more about what inspired them and why Julia Child still holds our attention.



Julia Child died over 15 years ago and has been off TV for decades. Why do you believe we continue to be so fascinated by her?

In some ways Julia is the Godmother of modern American cooking - and eating. Her spirit looms over cooking segments on the morning shows, The Food Network, and all those overhead Instagram shots the current generation loves to take of restaurant meals. Beyond that, though, Julia's bigger than life personality and unstoppable joie de vivre are infectious. People couldn't get enough of her while she was living, and they still can't now.

There have been so many Julia Child films and documentaries, what inspired this one?

Well there'd been some great programs about Julia but this is the first feature length theatrical doc. Like everyone else, we adored Julie & Julia, but a documentary gives you a special opportunity to tell a person's story in their own words and with the authentic images. This is particularly true of Julia, who was truly one of a kind.

The impact of Julia Child how she was a groundbreaker really comes across in the film, are we understanding her in a different light as time passes?

People understand that Julia was a talented television entertainer, but outside the professional food world, there's been an under-recognition of just how much she changed the 20th century food landscape. As Jose Andres points out in the film, almost every serious food professional has a sauce-splashed copy of "Mastering the Art of French Cooking" on their shelves. We also felt Julia's role in opening up new possibilities for women on television deserved more exploration. In the early 1960's the idea of a woman on TV who was neither a housewife nor a sex bomb but a mature, tall, confident expert was downright radical. She paved the way for many women who followed.

The food shots add an extra element to the film and entice viewers in a very visceral way, how did those interstitials come to be part of the film?

We knew from the start that we wanted to make food a major part of this story, not an afterthought. We worked with cook and food stylist Susan Spungen to determine which authentic Julia recipes could be integrated with which story beats to become part of the film's aesthetic and its plot. For instance the sole meunière is a key part of the story because it sparked her obsession with French food, and the pear and almond tart provides an enticing metaphor for the sensual side of Julia and Paul's early married years.

Note: Susan Spungen was also the food stylist for Julie & Julia

Julia is in theaters now.

23 Nov 2021 11:30pm GMT

05 Oct 2021

feedCooking with Amy: A Food Blog

Meet my Friend & Mentor: Rick Rodgers of the Online Cooking School Coffee & Cake


Rick Rodgers

I met Rick Rodgers early in my career as a recipe developer and food writer when we were both contributors to the Epicurious blog. Not only is he a lot of fun to hang out with, but he has also been incredibly helpful to me and is usually the first person I call when I'm floundering with a project, client, or cooking quandary. His interpersonal skills, business experience, and cooking acumen explain why he's been recognized as one of the top cooking instructors in America. Literally.


You built a career as a cooking instructor and cookbook author. How many cookbooks have you written?

I was asked recently to make an official count, and It looks like an even hundred. Many of those were collaborations with chefs, restaurants, celebrities, bakeries, and business entities, such as Tommy Bahama, Williams-Sonoma, and Nordstrom. I made it known that I was available for collaboration work, and my phone literally rang off the hook for quite a few years with editors and agents looking for help with novice writers or those that wanted a branded book.


Which cookbook(s) are you most proud of?

There are three books that I get fan mail for almost every day: Kaffeehaus (where I explore the desserts of my Austrian heritage), Thanksgiving 101 (a deep dive into America's most food-centric holiday and how to pull it off), and Ready and Waiting (which was one of the first books to take a "gourmet" approach to the slow cooker). These books have been in print for 20 years or more, which is a beautiful testament to their usefulness to home cooks.


How did you get started as a cooking instructor and what are some highlights of your teaching career?

I was a theater major at San Francisco State College (now University), so getting in front of a crowd held no terrors for me. When more brick-and-mortar cooking schools opened in the eighties, I was ready for prime time. During that period, there were at least twelve cooking schools in the Bay Area, so I made quarterly trips here a year from the east coast, where I had moved. My Thanksgiving classes were so popular that I taught every day from November 1 to Thanksgiving, with a couple of days off for laundry and travel. The absolute pinnacle of my teaching career was being named Outstanding Culinary Instructor of The Year by Bon Appétit Magazine's Food and Entertaining Awards, an honor that I share with only a handful of other recipients, including Rick Bayless and Bobby Flay.

FlĂłdni
FlĂłdni


How have cooking classes changed since you started?

Because there are so many classes available, I can teach at any level of experience. At the cooking schools, we tended to walk a fine line between too difficult and too easy. The exposure to different cuisines and skill levels on TV also has seriously raised the bar. Unfortunately, students want to walk before they can run. They want to learn how to make croissants when I doubt that they can bake a pound cake correctly. It is best to build on your skills instead of going right to the top. That being said, in my online classes, I am concentrating on the more challenging recipes because that is what the market demands of me.


Tell me about your baking school, coffeeandcake.org

As much as I loved my cookbooks and in-person classes, I knew there was a more modern way to reach people who wanted to cook with me, especially since so many cooking schools had closed. I retired the day I got my first Social Security check. But…as I was warned by my friends who knew me better than I did…I was bored, and wanted a new project. I heard about online classes through other teachers who were having success. I found an online course specifically for cooking classes (Cooking Class Business School at HiddenRhythm.com), got the nuts and bolts down, and I finally entered the 21st century!


How do you decide which recipes to teach?

I felt there were plenty of other places to learn how to make chocolate chip cookies and banana bread-just take a look on YouTube alone. I had a specialty of Austro-Hungarian baking thanks to my Kaffeehaus book, so I decided to niche into that category. I have branched out to a few other locations, but my goal is to expose students to something new and out of the ordinary. I also survey my students on what they would like me to teach, and those answers are amazing. People are truly interested in the more difficult desserts. Perhaps it is because so many people discovered baking as a hobby during the pandemic?


For students who have your cookbooks, what are the advantages of taking an online class?

There is no substitute for seeing a cook in action. Plus you get to answer questions during class. In a recent class, I made six-layer Dobos Torte in two hours' real-time to prove that you can do it without giving up a week of your life. And we don't have to travel to each other to be "together." My classes are videotaped so you can watch them at your convenience.


What are some highlights of your upcoming schedule of classes?

Honey cake
Honey cake

In October, I am teaching virtually all Hungarian desserts, things that will be new to most people. I am making one of my absolute favorites, FlĂłdni, which is a Jewish bar cookie (almost a cake) with layers of apple, poppy seeds, and walnuts between thin sheets of wine-flavored cookie dough. San Franciscans in particular will be happy to see a master class that I am teaching with the delightful Michelle Polzine, owner of the late and lamented 20th Century Cafe and author of Baking at the 20th Century Cafe. We will be making her (in)famous 12-layer honey cake on two coasts, with me doing the heavy lifting in New Jersey and Michelle guiding me from the west coast. That is going to be fun! In November and December, I am switching over to holiday baking and a few savory recipes for Thanksgiving, including my fail-proof turkey and gravy, which I have made over 300 times in classes over 30 years' worth of teaching. It ought to be perfect by now




Head to Coffee and Cake to sign up for classes or learn more.






05 Oct 2021 3:56pm GMT

03 Dec 2014

feedVincent Caut




!!!



Changement d'adresse !

Maintenant, ça se passe ICI



!!!

03 Dec 2014 8:12pm GMT

16 Jul 2014

feedVincent Caut

16 juillet 2014

16 Jul 2014 6:08pm GMT

14 Jul 2014

feedVincent Caut

14 juillet 2014

Après presque un mois et demi d'absence, deux bouclages d'albums et plein de projets, je trouve enfin le
temps de poster quelque chose sur ce blog ! Ces jours-ci, je vais avoir pas mal de choses Ă  vous montrer !
On commence tranquille avec un petit dessin aux couleurs estivales.

14 Jul 2014 4:25pm GMT