This is not just another catalog update. CISA is effectively telling defenders that these flaws have crossed from known problem…
In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely…
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including…
This moved from important to urgent fast. CrowdStrike is pointing to a live exploitation or incident path that should be…
The latest LiteLLM fallout matters because the issue is no longer just a package-security anecdote: teams may still have long-lived…
DeadLock is an emerging ransomware operation that pairs double extortion with decentralized recovery and leak infrastructure, giving the actor a…
Attackers are actively exploiting CVE-2026-59310, a CVSS 9.8 directory-traversal flaw in VMware vCenter, and incident responders are seeing successful compromise…
Attempts to exploit CVE-2026-71362 in Adobe Commerce and Magento have already been detected, and the flaw appears to let attackers…
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation…
Atlassian Rovo is showing exactly why AI assistants deserve the same trust-boundary thinking as connectors and privileged apps: attacker-controlled content…
CISA added Progress Kemp LoadMaster flaw CVE-2026-8037 to the KEV catalog after repeated exploitation attempts, turning a load balancer bug…
CISA's latest KEV update is only useful if it changes what defenders do next. This one adds three actively exploited…