Atlassian Rovo is showing exactly why AI assistants deserve the same trust-boundary thinking as connectors and privileged apps: attacker-controlled content…
CISA added Progress Kemp LoadMaster flaw CVE-2026-8037 to the KEV catalog after repeated exploitation attempts, turning a load balancer bug…
CISA's latest KEV update is only useful if it changes what defenders do next. This one adds three actively exploited…
In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely…
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including…
Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively…
Microsoft's August 2026 Patch Tuesday is not just a volume story. Teams should start with the actively exploited AFD.sys zero-day,…
Unit 42 and Siemens detailed a three-CVE exploit chain in Siemens ROX II OT switches that can move an attacker…
CISA added CVE-2026-20316 to the Known Exploited Vulnerabilities catalog after active exploitation. The flaw affects Cisco Secure Firewall Management Center…
CISA is telling federal agencies to move within three days on actively exploited flaws in IBM Langflow, N-able N-central, and…
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage…
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates.…