Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Copilot RCE, Entra SSRF, and SharePoint Zero-Day: Critical Vulnerabilities in Microsoft's July 2026 Advisory

AI assistants are quietly becoming one of Microsoft’s largest attack surfaces. In its July 2026 advisory, Microsoft patched a command injection vulnerability in Copilot. Crafted prompts can trigger unintended actions through this flaw. The advisory also included a critical SSRF vulnerability in Entra’s identity provisioning service. It carries the among the highest severity score in the entire release. Both point to the same shift.

Oracle's July 2026 CPU: Critical Unauth Vulnerabilities in PeopleSoft, WebLogic, and E-Business Suite

Oracle released its July 2026 Critical Patch Update (CPU) on July 21, delivering 1,449 security fixes across 1,235 unique CVEs, the largest CPU in the company’s history. The release spans 32 product families, with the heaviest concentration in Oracle E-Business Suite, Oracle Fusion Middleware, Oracle Communications, and PeopleSoft. Nine of these CVEs received a perfect CVSS 10.0 score.

The 2026 Buyer's Guide to Open Source Vulnerability Remediation

How to evaluate your options, price the status quo, and make a decision your executive team will actually approve. A note on the numbers. The salaries, headcounts, and costs in this guide are illustrative. They're drawn to be realistic so the math works the way it does in a real budget meeting - but they're examples, not benchmarks. Replace them with your own.

Find and stop vulnerable code at runtime - Secure App in Splunk Observability Cloud

Secure App brings runtime application security into Splunk Observability Cloud using the same OpenTelemetry instrumentation as your APM traces to surface the vulnerabilities actually running in production, prioritize them by real-world exploit risk, and catch live attacks. TOC.

From External Exposure to Closed Risk: Seemplicity + IONIX

Modern exposure management has evolved beyond vulnerability scanning and alert volume into a discipline focused on measurable risk reduction. As the exposure management market matures, security leaders are adopting cyber exposure management platforms that unify signals across vulnerability, cloud, application, and attack surface tools to prioritize what truly matters.

The Attacker Never Sleeps, Neither Can Your Testing

A few months ago, I wrote that AI is building your attack surface faster than you can test it. I stand by every word I wrote then. But in the months since, after more than a hundred conversations with CISOs, CIOs, and CTOs across nearly every industry and geography, I've watched the picture get sharper, and a lot more urgent. The attack surface was only half the story, because the attacker profile has changed too.

What Claude Mythos Means for Vulnerability Management Programs

If you've been following the cybersecurity conversation over the last several weeks, you've heard some version of the phrase “Claude Mythos changes everything.” It’s dominated the industry news cycles since early April. While the capabilities these stories tout are very much real, I have an issue with the framing being wrong when it comes to vulnerability management. There’s a narrative that Mythos and other frontier models will find too many vulnerabilities to deal with.

Secure at Inception: Announcing the Snyk Studio Integration for Snowflake Cortex Code

Building on our initial partnership that brought Snyk’s security intelligence into the Snowflake AI Data Cloud, we are taking the next step in securing the future of data-driven development. This new collaboration integrates Snyk Studio directly with Snowflake Cortex Code, ensuring that as organizations move their application logic to where their data lives, security remains an inherent part of the process rather than a secondary hurdle. Play Video: YouTube video 1.

CVE-2026-56164: Unauthenticated SharePoint Zero-Day Grants Farm Administrator Access

Microsoft released patches for over 570 vulnerabilities in its July 2026 Patch Tuesday, the largest security update in the company’s history, including two zero-days already under active exploitation. Among them, one stands out for how it is being exploited right now: an unauthenticated vulnerability in SharePoint Server that allows an unauthenticated attacker to elevate privileges to Farm Administrator.

Top Vulnerability Scanner Tools Open Source 2026

Running a vulnerability scan is the easy part. The hard part starts when your queue fills with duplicate findings, stale CVEs, and reports that don't tell you what's exposed in production. If you're trying to build a practical vulnerability scanner tools open source stack in 2026, the key question isn't which scanner exists, it's which scanner fits your environment and feeds cleanly into your SIEM/XDR workflow so you can prioritize what matters.

America's New Security Doctrine: Hardening Digital and Supply Chain Borders

In the span of six weeks this summer, the United States government issued three separate security directives that, on the surface, appear to address completely different problems. One tightens how federal agencies patch software vulnerabilities. Another creates a government-industry clearinghouse to triage AI-discovered bugs. The third restructures how defense contractors source the raw materials that go into missiles, aircraft, and military electronics. Different agencies. Different languages.

Don't Wait for a Crisis: Rehearse Your Zero-Day Response

How do you prepare for a zero-day attack before one impacts your organization? In this video, Daniel dos Santos explains why security teams should use past vulnerabilities and real-world attack scenarios to rehearse response plans. By testing decisions, controls, communications, and recovery actions—not just documentation—organizations can build confidence and improve readiness for future threats.

The Generator Can't Be the Validator: What OpenAI's Hugging Face Incident Proves About AI Security

Every so often, an industry gets a moment that quietly redraws where the line is — not because anything was said, but because something was proven. AI security had one of those moments last week, and it's worth being direct about that before getting into the details: this wasn't an incremental data point. It was the moment a risk that security and safety researchers had described in theory for years showed up, fully formed, in a disclosed incident report.

Why ESG Data Security Is Becoming a Business Priority

As businesses increasingly focus on their environmental, social, and governance (ESG) performance, the data behind these efforts is becoming as important as financial information. This shift, along with using AI to analyse and report on sustainability metrics, has introduced new cybersecurity risks. Protecting this sensitive data isn't just an option anymore; it's a core part of corporate responsibility and managing risk. With AI involved, the potential for sophisticated data manipulation introduces AI as an emerging risk dimension that security teams need to deal with.

Emerging Threat: (CVE-2026-10818) WPForms Pro Arbitrary File Upload Leading to Remote Code Execution

CVE-2026-10818 is an arbitrary file upload vulnerability in WPForms Pro, the paid edition of a widely deployed WordPress form builder plugin. It was published on July 25, 2026, with Wordfence as the assigning CNA. The flaw sits in the ajax_chunk_upload_finalize function, which handles the final step of a chunked file upload. File type validation runs after the chunk metadata and the file contents have already been written to disk, and the assembled file is not deleted when that validation fails.

What Is AI Pentesting and How Does It Works?

AI pentesting (AI penetration testing) is the use of reasoning-capable AI models to autonomously find, exploit, and validate security vulnerabilities in running applications — especially the context-dependent flaws, such as broken authorization and business-logic abuse, that traditional scanners cannot detect.

Securing Your Data Pipeline from Internal Threats

When organisations design security strategies, they often focus on building a fortress to keep external threats out. However, some of the biggest risks to data integrity don't come from outside; they start within. Securing a data pipeline, the complex system that moves information from source to destination, needs strong defences against internal threats, whether they're intentional or accidental.

Bad Things Also Come in Small Packages: A 38-byte DoS in fflate (CVE-2026-45820)

We discovered this new vulnerability as part of our abandoned-packages research. Despite what seems like a 2-year hiatus, fflate is one of the few popular npm packages that released a fix for the vulnerabilities we found merely using Sonnet-4.6, giving its 50M+ users a chance to upgrade to a safe version.

Build the Zero-Day Playbook Before the Next Crisis

In this video, Daniel dos Santos, VP of Research, explains why organizations should establish a zero-day containment playbook before a crisis occurs. A well-defined playbook connects response actions to assets, critical services, and business functions while outlining decision-making, impact validation, and crisis communication processes. When a real-world zero-day strikes, there is no time to create a plan from scratch. Preparation helps teams respond faster, align stakeholders, and reduce uncertainty during high-pressure situations.

CVE-2026-6875: ServiceNow Sandbox Escape Leads to Pre-Auth RCE in AI Platform

ServiceNow AI Platform (the enterprise PaaS formerly branded in the Now Platform) contains a critical, unauthenticated remote code execution vulnerability tracked as CVE-2026-6875. The vulnerability allows a remote attacker to escape ServiceNow’s JavaScript execution sandbox. No credentials or user interaction are required, and the attacker achieves full code execution on the underlying instance.

How Anthropic's Claude Mythos Escaped a Secure Environment and What It Means for SMBs

SecuritySenses and BCA, an IT services company in Spokane, team together to help small and midsize businesses turn frontier-AI security news into controls they can actually implement. During an internal evaluation, Anthropic gave Claude Mythos Preview access to a restricted computer and instructed it to find a way out. The model discovered a weakness, bypassed its technical restrictions and contacted the researcher overseeing the test.

Finding eight high-severity vulnerabilities in NodeBB in six hours

TL;DR While improving our AI Pentest, we ran a whitebox assessment on NodeBB, a forum software powered by NodeJS. The result? Eight high-severity vulnerabilities that would all be exploitable on default instances of NodeBB. This includes Cross-Site Scripting (XSS), two of which require interaction with a custom Federation server that the AI agent had to set up itself. Another affects practically every input on NodeBB due to a template injection.

WP2Shell: WordPress Core SQLi + REST API Chain to Pre-Auth RCE

A newly disclosed WordPress exploit chain, nicknamed “WP2Shell,” lets unauthenticated attackers achieve remote code execution (RCE) on any WordPress Core installation, no plugins required. Disclosed on July 17, 2026, the chain combines two vulnerabilities: CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API batch-route confusion).

SQL injection isn't dead

Oops! A SQL injection bug just forced an emergency WordPress core patch last week. On July 17, WordPress shipped an emergency release to fix an unauthenticated remote code execution flaw in the core, reachable via a SQL injection that an anonymous attacker can exploit on a stock install. WordPress.org even turned on forced auto-updates because of how severe it is. Searchlight Cyber, who reported it, estimates over 500 million sites run WordPress.

Why Reachability Changes Vulnerability Response

When a critical vulnerability is announced, the first response is often urgency—and sometimes panic. But not every vulnerable asset presents the same level of risk. In this video, Daniel dos Santos, VP of Research, explains how reachability helps security teams move beyond broad vulnerability hunting and focus on the assets that are both vulnerable and exposed in ways that matter to the business. By understanding reachability, organizations can prioritize response efforts, reduce noise, and bring structure to vulnerability management.

Security Strategies That Help Minimize Data Breach Risks

Data compromises happen daily, creating massive headaches for companies of all sizes. Cyber criminals constantly find fresh entry points into modern networks. Smart business leaders focus on proactive defense methods to stay ahead of bad actors. Simple systemic upgrades can keep sensitive customer records safe from harm.

Don't trust your eyes - ANSI escape injection in the skills CLI by vercel-labs

In a previous post we looked at the skills CLI by vercel-labs/skills and ways for a malicious skill to overwrite an existing trusted skill by using homoglyph names or abusing weird CLI behaviors. This post will delve into an OSC-8 escape injection we found in the skills add command, which lets a skill author write arbitrary text to the console and clickable links as if it's part of the CLI's output.

Emerging Threat: (CVE-2026-54159) PrestaShop Remote Code Execution via ps_facetedsearch Object Injection

CVE-2026-54159 is a PHP object injection vulnerability in ps_facetedsearch, the layered navigation module bundled with PrestaShop, that lets an unauthenticated attacker run arbitrary code on the storefront. The vulnerability carries a CVSS v3.1 base score of 10.0 (Critical).

80% of New Code is AI-Generated - But 40-50% Has Vulnerabilities Find out Why

Is your organization generating up to 80% of its new code with AI? You might be proud of the speed — but are you ready for the security risks? In this video, we reveal the hidden danger: multiple studies show that **40-50% of AI-generated code changes contain vulnerabilities**. Discover why AI coding is accelerating development faster than ever — and why traditional security approaches are no longer enough.

Protecting Vulnerable and Poorly Configured Network Devices

On July 13, 2026, NSA, CISA, the FBI, and co-sealing partners from twelve other countries published AA26-194A, a joint Cybersecurity Advisory (CSA) warning that Center 16 of Russia's Federal Security Service (FSB) continues to exploit vulnerable and poorly configured network devices across the defense industrial base, communications, energy, financial services, government facilities, and healthcare sectors. The advisory does not reference new exploits.

Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware

During June 2026, Arctic Wolf Labs investigated multiple intrusions during which threat actors exploited CVE-2026-0257 as a consistent initial access vector, rapidly transitioning from perimeter compromise to domain-wide Qilin ransomware encryption across distinct victim environments.

The First Hour of a Zero-Day: Why Preparation Must Start Before Disclosure

The window between vulnerability disclosure and exploitation is shrinking. As exploit development accelerates, organizations can no longer afford to wait for a vulnerability to be disclosed or a patch to become available before taking action. Daniel dos Santos, VP of Research, explains why effective zero-day response depends on preparation that happens before an incident occurs.

OpenAI's Sol, Terra, Luna Explained: Which One Should You Use?

-OpenAI has completely overhauled its model naming system with the release of GPT-5.6, introducing three distinct tiers: Sol, Terra, and Luna. In this video, we put OpenAI's new flagship model, GPT-5.6 Sol, to the ultimate test. Using the Codex extension in VS Code, we throw our classic "Build me a secure notes app or I get fired" prompt at Sol. Watch as we break down the pricing and reasoning differences of the new tiers, run a full security audit using Snyk, and see if Sol's $5/$30 price tag is truly production-ready or if a small local CSRF bug gets us "fired" first.

Emerging Threat: (CVE-2026-63030, CVE-2026-60137) WordPress Core Unauthenticated RCE via wp2shell

wp2shell is the name given to an unauthenticated remote code execution attack against WordPress core. It is not a single bug. It is a chain of two separately tracked flaws that, combined, let an anonymous attacker run code on a default WordPress installation with no plugins, no valid account, and no user interaction. The first flaw, CVE-2026-63030, is a REST API batch-route confusion issue in WP_REST_Server::serve_batch_request_v1().

Unauthenticated RCE in WordPress core (wp2shell)

SQL injections are still among us. On July 17, WordPress released an emergency security update. Version 7.0.2 fixes an unauthenticated remote code execution flaw in WordPress core that an anonymous attacker can trigger against a stock install with no plugins involved. If your site runs an affected version, update today. WordPress.org has turned on forced auto-updates for affected sites because of how severe this is. We are tracking this vulnerability in Aikido Intel.

Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

Cloudflare has deployed new Web Application Firewall (WAF) protections for two critical vulnerabilities affecting WordPress. The protections address an Unauthenticated Remote Code Execution (RCE) vulnerability in WordPress's REST API and a related SQL Injection vulnerability. The WordPress security team disclosed the vulnerabilities to Cloudflare before public release so that we could prepare protections for customers.

Resolve: One-Click Patching from Aurora Vulnerability Management

Vulnerability discovery is only half the story; remediation is where breach potential gets reduced. Resolve, part of Arctic Wolf's Aurora Vulnerability Management, brings one-click patch deployment across Windows, Mac, and Linux so security teams can move from "we found it" to "we fixed it" without the manual overhead. In this overview, see how Resolve turns vulnerability data into action: one-click patch orchestration, flexible scheduling, and clear visibility into remediation status — all inside the Aurora platform.

Vulnerability Exploitability: Is That Critical CVE Reachable?

A high CVSS score tells you how bad a vulnerability could be in theory, and EPSS tells you how likely it’s being exploited somewhere in the world, but neither knows anything about your environment. True vulnerability exploitability depends on reachability: whether the vulnerable code is actually loaded and called at runtime, whether it’s exposed on the network, and whether existing controls already block the path.

Benchmarking 13 AI models on rediscovering known CVEs

TL;DR Every frontier model launch now comes with the same cybersecurity claim: it finds vulnerabilities. But does it work on a real bug in a real repository, or just on a curated example? Of the dozen models you could pick, which is worth trusting with code review? And since the strongest models cost ten times or more per run than the cheapest, what does that extra spend actually buy you in bugs found?

Emerging Threat: (CVE-2026-56164) SharePoint Server Privilege Escalation via Missing Authentication

CVE-2026-56164 is a privilege escalation vulnerability in on-premises Microsoft SharePoint Server, caused by a missing authentication check on a critical function (CWE-306). An unauthenticated attacker can exploit it over a network, with no credentials and no user interaction required. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium), and Microsoft rates it Moderate.

SonicWall SMA1000 vulnerabilities in active exploitation

On July 14, 2026, SonicWall disclosed two vulnerabilities in SonicWall SMA1000 appliances. Models 6210, 7210, and 8200v are affected. CVE-2026-15409 is a critical (CVSS score of 10.0) unauthenticated server-side request forgery (SSRF) flaw that allows an attacker to force the appliance to make requests to unintended destinations.

How to Patch Vulnerabilities and Reduce Risk with Aurora Vulnerability Management and Resolve

Learn how to identify, prioritize, and remediate vulnerabilities using Aurora Vulnerability Management and the Resolve integration. This demo walks through filtering and targeting high-risk vulnerabilities, deploying patches across assets, and tracking patch jobs to reduce risk more efficiently.

How Aikido Intel detects malware and vulnerabilities first

TL;DR: Aikido Intel is a real-time supply chain intelligence feed. It detects both malware and vulnerabilities in open-source ecosystems. Aikido's world-class researchers maintain our LLM-powered pipeline to find malware and validate the most malicious cases by hand. The vulnerability detection system monitors package changes across ecosystems to catch and document vulnerabilities that don’t have CVEs assigned.

Finding Just Got Free: That's Why Fixing Is the Only Game That Matters

When Anthropic revealed Claude Mythos and Project Glasswing, the industry did what the industry always does with a frontier-AI story: it reached for the alarm. The headlines, Reddit threads, and back-channel conversations all focused on the same things: All of that is real, and none of it is the part that should keep a security leader up at night. Here is the part that should.

8 Fleet Cybersecurity Metrics Worth Tracking

Running a modern fleet involves far more technology than it did a decade ago. Vehicles now connect with GPS devices, mobile apps, cloud platforms, maintenance software, and outside service providers. Those tools make routine work easier, but every connection also creates another place where credentials, equipment, or sensitive information could be exposed.

JADEPUFFER: How an Agentic Ransomware Attack Unfolded

In early July 2026, researchers at Sysdig published an analysis of what they assess to be the first documented case of agentic ransomware. The threat actor, which Sysdig calls JADEPUFFER, launched an extortion attack driven end to end by a large language model (LLM) rather than a conventional human-operated toolkit.

Why You Must Still Review AI Code

In this video, we break down why skipping code reviews is a massive mistake that will ultimately slow you down, leave you vulnerable, and compromise your system's accountability. We dive into three concrete reasons why reviewing AI-generated pull requests actually makes you a faster, safer developer, including a real-world story of a production bug caught in under 90 seconds. Resources Chapters.

Emerging Threat: (CVE-2026-56291) Balbooa Forms Remote Code Execution via Unauthenticated File Upload

CVE-2026-56291 is an unauthenticated arbitrary file upload vulnerability in Balbooa Forms, a commercial drag-and-drop form builder for Joomla installed as the com_baforms component. The flaw is classified as CWE-434, unrestricted upload of a file with a dangerous type. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical). It has also been assigned a CVSS v4.0 base score of 10.0 (Critical), with an exploitation maturity of “attacked.”

CVE-2026-48282: ColdFusion RDS Vulnerability Actively Exploited

Enterprises running Adobe ColdFusion often carry legacy development features forward long after the original use case is gone. Remote Development Services (RDS) is a good example: a convenience feature that lets an IDE talk to a live ColdFusion server, left switched on from an old dev workflow years after anyone remembers why.

Symlinks Are Still Scary (And Yes, You Can Commit Them to Git)

Here's a genuinely unsettling way to lose control of your laptop in 2026. You clone a normal-looking repo, ask your AI coding assistant to "set it up," and it writes an attacker's SSH key into your ~/.ssh/authorized_keys -- without ever really telling you that's what it did. No memory corruption, no zero-day, nothing clever. Just a file in the repo that wasn't the file it claimed to be. That attack is real, it's this week's news, and I'll walk through it. But the trick underneath is decades old.

Vulnerability Assessment: Definition, Types, Process, Cost, and Benefits

Vulnerability assessment is a systematic process that finds, assesses, and prioritises vulnerabilities in a system or application. Vulnerability assessment is considered a part of a larger family of vulnerability management. Vulnerability management is related to vulnerability analysis to identify conditions that lead to decision-relevant outcomes.

Emerging Threat: (CVE-2026-40138 & CVE-2026-40139) BeyondTrust Remote Support Authentication Bypass

CVE-2026-40138 and CVE-2026-40139 are two pre-authentication vulnerabilities in the authentication subsystem of BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA), stemming from improper validation and processing of authentication data. Both carry a CVSS v3.1 base score of 9.2 (Critical).

Emerging Threat: (CVE-2026-57517) Control Web Panel Remote Code Execution via SQL Injection

CVE-2026-57517 is a blind SQL injection vulnerability in Control Web Panel (CWP), caused by insufficient sanitization of the userRes POST parameter submitted to the panel’s user endpoint before the value is used to build a SQL query. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

How to Prioritize Vulnerability Remediation Based on Validated Active Risk Exposure

Prioritizing based on exploitability scores alone no longer works. AI has made that signal too unreliable, turning vulnerability prioritization into a guessing game. True vulnerability triage requires more than a score: it needs exploit validation in your specific environment, clear ownership of the fix, and a defined remediation path. That’s exactly what Seemplicity’s AI Analysts deliver, so your team can respond to the right findings, fast.

Protecting Sensitive Documents from Digital Threats

In our increasingly digital lives, we handle a vast number of documents, from personal financial statements and contracts to sensitive business reports. We often focus on securing our networks and devices, but the security of the documents themselves is frequently overlooked. Protecting these files from digital threats isn't just an IT department's problem; it's a personal responsibility for anyone creating, sharing, or storing information.

Zero-Day Minus the Scramble: A Better Approach to Vulnerability Risk Management

SCA tools are good at identifying vulnerabilities in your dependencies. They’re not built for the harder part of vulnerability risk management: telling you whether those vulnerabilities are actually reachable in your application, or which assets are running an affected component the moment a zero-day drops. Seemplicity’s SCA Analyst solves both problems inside a single centralized vulnerability management platform.

5 Biggest Challenges of AI in Cybersecurity

IBM’s 2025 Cost of a Data Breach Report found that 97% of organizations that experienced an artificial intelligence (AI)-related security incident lacked proper access controls on AI systems. The same report highlighted that 63% of organizations lacked governance policies to manage AI or prevent shadow AI. Despite those statistics, AI is now deeply embedded in workflows across critical business functions. Employees are using public AI tools to work faster.

NIST and CVE Grading - The 443 Podcast - Episode 377

This week on the podcast, we take a look at the impact of the US National Institute of Standards and Technology (NIST) backing away from their previous role of enriching vulnerability CVE records. Before that, we discuss Huntress's insider threat drama before ending with an AI-assisted vulnerability discovery in the Front Gate Tickets platform.

Authentication Bypass in the default configuration phpBB

June 10th, we announced a critical vulnerability in phpBB that lets attackers bypass authentication, now known as CVE-2026-48611. This post is a follow-up, containing technical details that explain exploit scenarios and detection methods. To get you up to speed, phpBB is an old forum software that's still being used today by various technical communities. phpBB's Site Showcase alone has over 6 million members.

CVE-2026-46817: Oracle EBS Payments Vulnerability Under Active Exploitation

Oracle E-Business Suite (EBS) sits at the center of finance, procurement, and payment operations for many large enterprises. When a critical vulnerability surfaces in a module like Oracle Payments, the impact reaches well past IT. It touches financial data, transaction integrity, and regulatory exposure. CVE-2026-46817 is exactly that kind of vulnerability, and it is now being actively exploited.

CVE-2026-33017: Langflow RCE Deploys Monero Miners on AI Servers

Enterprises are standing up AI application frameworks like Langflow faster than security teams can review them. These platforms let teams build and automate generative AI workflows in days instead of months, but that speed comes with a cost: many instances go live with default settings, get exposed to the internet, and never make it onto a security team’s radar. CVE-2026-33017 shows exactly what happens next.

SAST False Positives Are Breaking Your Vulnerability Remediation Workflow

SAST scanners do their job well. The problem is their job stops at flagging vulnerable functions, not confirming whether those functions are reachable in your application. The result is a vulnerability remediation workflow full of findings that developers spend sprint cycles investigating, only to conclude they aren’t exploitable. Seemplicity’s Code Analyst closes that gap before the finding ever hits the queue. Security tools are supposed to make developers’ jobs easier.

OWASP Top 10 for Agentic Applications 2026: What It Means for Enterprise AI Security

OWASP, the Open Worldwide Application Security Project, has published Top 10 lists for over two decades to help security teams prioritize the risks that matter most. The original OWASP Top 10 for web applications became the industry’s default checklist for application security. When large language models moved into production, OWASP followed with the Top 10 for LLM Applications, addressing risks like prompt injection and sensitive information disclosure in single-turn model responses.

A Framework for Vulnerability Mitigation

Vulnerability management has long been seen as one of the most straightforward areas in security. Scan your assets, identify vulnerabilities, prioritize the findings, and patch what you can. On paper, it looks like a repeatable process. But in reality, vulnerability mitigation is anything but simple. Environments are constantly changing. Assets come and go. New integrations, temporary exceptions, and incomplete inventories make it hard to know what is truly at risk.

DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE

Cato AI Labs has discovered two critical remote code execution (RCE) vulnerabilities in Cursor IDE, the popular development environment which, according to Cursor, is used by over half of the Fortune 500. Both RCE vulnerabilities, which we refer to as “DuneSlide,” achieved a 9.8 CVSS score, and involve breaking out of the IDE’s sandbox environment and were assigned CVE IDs CVE-2026-50548 and CVE-2026-50549.

Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon & AI agent phishing [335]

Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly. Subscribe wherever you listen.

Emerging Threat: (CVE-2026-55957) Apache Tomcat Authentication Bypass via JNDIRealm GSSAPI Binds

CVE-2026-55957 is a missing critical step in authentication in Apache Tomcat, present when the JNDIRealm is configured to authenticate binds using GSSAPI. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), based on network attack vector, low attack complexity, no privileges required, and no user interaction.

AI Just Shrank the Time Hackers Need to Weaponize Your Vulnerabilities

The Five Eyes intelligence alliance—NSA, CISA, GCHQ, Australia's ASD, Canada's Cyber Centre, and New Zealand's GCSB—just issued a joint warning: AI has compressed the window between vulnerability discovery and exploitation from years to months. Adrian breaks down what the "AI Shift in Cyber Risk" statement actually means for patching timelines and attacker sophistication—and why most organizations aren't moving fast enough to keep up.

Why Your Asset Counts Are Wrong (And What to Do About It)

If you've ever pulled an asset count from one tool and compared it to another, you've probably noticed they don't match. The discrepancy isn’t minor, either. The difference is likely to be substantial. One scanner says you have 4,200 assets. Your CMDB says 3,800. Your cloud inventory says 1,100. None of them agree, and none of them are right. That's not a data hygiene problem you can solve with a spreadsheet cleanup.

Where Severity Scores Go Wrong: "Just Add Prototype Pollution"

At JFrog, our Security Research team continuously monitors and analyzes newly disclosed CVEs across the open-source ecosystem. Throughout our research, we have repeatedly observed cases where the assigned severity score does not accurately reflect a vulnerability’s real-world impact or exploitability. In fact, during 2025, JFrog researchers reassessed NVD critical-severity vulnerabilities and concluded that 96% warranted a lower severity rating.

RubyGems supply chain attack: malware used as a credential exfiltration dead drop

Package registries have a well-known abuse pattern: attackers upload malicious packages, and unsuspecting developers install them. Our researchers just found the pattern working in reverse, in a RubyGems supply chain attack that turns the registry into a place to stash stolen data rather than deliver it.