Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

Cloudflare has deployed new Web Application Firewall (WAF) protections for two critical vulnerabilities affecting WordPress. The protections address an Unauthenticated Remote Code Execution (RCE) vulnerability in WordPress's REST API and a related SQL Injection vulnerability. The WordPress security team disclosed the vulnerabilities to Cloudflare before public release so that we could prepare protections for customers.

Resolve: One-Click Patching from Aurora Vulnerability Management

Vulnerability discovery is only half the story; remediation is where breach potential gets reduced. Resolve, part of Arctic Wolf's Aurora Vulnerability Management, brings one-click patch deployment across Windows, Mac, and Linux so security teams can move from "we found it" to "we fixed it" without the manual overhead. In this overview, see how Resolve turns vulnerability data into action: one-click patch orchestration, flexible scheduling, and clear visibility into remediation status — all inside the Aurora platform.

Vulnerability Exploitability: Is That Critical CVE Reachable?

A high CVSS score tells you how bad a vulnerability could be in theory, and EPSS tells you how likely it’s being exploited somewhere in the world, but neither knows anything about your environment. True vulnerability exploitability depends on reachability: whether the vulnerable code is actually loaded and called at runtime, whether it’s exposed on the network, and whether existing controls already block the path.

Benchmarking 13 AI models on rediscovering known CVEs

TL;DR Every frontier model launch now comes with the same cybersecurity claim: it finds vulnerabilities. But does it work on a real bug in a real repository, or just on a curated example? Of the dozen models you could pick, which is worth trusting with code review? And since the strongest models cost ten times or more per run than the cheapest, what does that extra spend actually buy you in bugs found?

Emerging Threat: (CVE-2026-56164) SharePoint Server Privilege Escalation via Missing Authentication

CVE-2026-56164 is a privilege escalation vulnerability in on-premises Microsoft SharePoint Server, caused by a missing authentication check on a critical function (CWE-306). An unauthenticated attacker can exploit it over a network, with no credentials and no user interaction required. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium), and Microsoft rates it Moderate.

SonicWall SMA1000 vulnerabilities in active exploitation

On July 14, 2026, SonicWall disclosed two vulnerabilities in SonicWall SMA1000 appliances. Models 6210, 7210, and 8200v are affected. CVE-2026-15409 is a critical (CVSS score of 10.0) unauthenticated server-side request forgery (SSRF) flaw that allows an attacker to force the appliance to make requests to unintended destinations.

How to Patch Vulnerabilities and Reduce Risk with Aurora Vulnerability Management and Resolve

Learn how to identify, prioritize, and remediate vulnerabilities using Aurora Vulnerability Management and the Resolve integration. This demo walks through filtering and targeting high-risk vulnerabilities, deploying patches across assets, and tracking patch jobs to reduce risk more efficiently.

How Aikido Intel detects malware and vulnerabilities first

TL;DR: Aikido Intel is a real-time supply chain intelligence feed. It detects both malware and vulnerabilities in open-source ecosystems. Aikido's world-class researchers maintain our LLM-powered pipeline to find malware and validate the most malicious cases by hand. The vulnerability detection system monitors package changes across ecosystems to catch and document vulnerabilities that don’t have CVEs assigned.

Finding Just Got Free: That's Why Fixing Is the Only Game That Matters

When Anthropic revealed Claude Mythos and Project Glasswing, the industry did what the industry always does with a frontier-AI story: it reached for the alarm. The headlines, Reddit threads, and back-channel conversations all focused on the same things: All of that is real, and none of it is the part that should keep a security leader up at night. Here is the part that should.