IncidentColdFusion Exploit Caught in Two Hours
On the same day Adobe disclosed CVE-2026-48282 , a critical vulnerability in ColdFusion, attackers were already probing for vulnerable servers. KEVIntel s honeypots captured exploitation attempts with
Expert perspectives on application security, compliance, and emerging threats
IncidentOn the same day Adobe disclosed CVE-2026-48282 , a critical vulnerability in ColdFusion, attackers were already probing for vulnerable servers. KEVIntel s honeypots captured exploitation attempts with
IncidentIn December 2021, your team scrambled to patch Log4Shell. You identified every instance of the vulnerable Log4j library, applied updates, and documented the remediation. Three months later, a routine
ResearchYour security team is evaluating AI systems that don t just analyze threats but conduct their own research, generate tools, and make operational decisions. Before you deploy autonomous AI in productio
GeneralThe Conventional Wisdom Your team reviews every pull request before it merges. Someone checks the logic, scans for obvious errors, and looks for security holes. You ve built this into your software de
Get weekly security insights and compliance updates delivered to your inbox.
GeneralMicrosoft has introduced Microsoft Execution Containers (MXC), a policy-driven execution layer that runs AI agents in isolated environments on Windows and WSL. If your team is deploying autonomous age
GeneralSecurity teams often treat AI agents like advanced APIs, but they re not. The recent Zscaler research revealing indirect prompt injection vulnerabilities in four models highlights a critical issue: yo
ResearchYour AI coding agent just installed a new skill from the marketplace. The static scanner gave it a clean bill of health. Three days later, you re investigating why production data is leaving your netw
IncidentA development team deployed a customer dashboard that let authenticated users view any account by changing a URL parameter. The vulnerability sat in production for three months before a penetration te
GeneralScope This guide explains how to manage AI security tools as supply chain dependencies requiring formal risk management. It covers: Identifying critical AI dependencies in your security workflow Build
IncidentWhat Happened A financial services company with 2,800 employees spent 18 months feeding vulnerability data into their exposure management platform. Their dashboard showed 847 critical findings. The se
GeneralYou can t audit what you can t define. When your LLM returns a user profile, incident report, or configuration change, you need to know exactly what fields you re getting, what types they are, and whe
IncidentWhat Happened Capital One s AI Foundations group developed a reinforcement learning system to identify effective jailbreak techniques against large language models. They tested it using the WildJailbr
GeneralYou ve probably seen the demos: type a single command, watch an AI agent probe your infrastructure, generate exploits, and produce a vulnerability report. Lyrie, the open-source autonomous pentesting
IncidentInconsistent Results from LLM Security Reviews Snyk conducted 250 identical security reviews using Claude on the same JavaScript codebase. The outcome was startling: 80 of 161 unique findings appeared
GeneralThe Conventional Wisdom Security teams often treat AI coding agents like advanced code generators. The typical approach: let the agent generate code, then scan the output. This includes static analysi
IncidentA Wake Forest University research team analyzed 444 iOS apps with LLM features and found 282 exposing exploitable credentials. These were plaintext API keys and authentication tokens visible in networ