GeneralDependency Scanning Won't Save You
The Conventional Wisdom Your security team runs dependency scanners in CI/CD. You ve configured Dependabot, Snyk, or another tool. When a pull request comes in, the scanner checks for known vulnerabil
Expert perspectives on application security, compliance, and emerging threats
GeneralThe Conventional Wisdom Your security team runs dependency scanners in CI/CD. You ve configured Dependabot, Snyk, or another tool. When a pull request comes in, the scanner checks for known vulnerabil
IncidentWhat Happened Between 2016 and 2017, the number of published vulnerabilities across tracked open-source ecosystems jumped 83 percent. The npm and Maven Central repositories — essential for JavaScript
IncidentWhat Happened In September 2018, the maintainer of event-stream —an npm package downloaded 2 million times per week—transferred ownership to a new contributor after months of social engineering. Withi
IncidentWhat Happened In 2024, the National Institute of Standards and Technology (NIST) s National Vulnerability Database (NVD) reduced its CVE enrichment operations, analyzing fewer vulnerabilities in depth
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened Attackers are exploiting CVE-2026-45659 , a remote code execution vulnerability in Microsoft SharePoint. This flaw allows an authenticated user with low privileges to execute arbitrary c
IncidentWhat Happened On December 3, 2018, the Kubernetes security team disclosed CVE-2018-1002105 , a critical vulnerability that allowed any authenticated user to escalate privileges and execute arbitrary c
ResearchYour endpoint detection just blocked another phishing email. Your web proxy flagged a suspicious download. But ClickFix attacks don t look like traditional malware delivery—they mimic legitimate troub
IncidentWhat Happened Microsoft SharePoint Server contains a deserialization vulnerability (CVE-2026-45659, CVSS 8.8) that allows authenticated attackers to execute arbitrary code remotely. CISA added this vu
IncidentWhat Happened Between late 2024 and early 2025, Anthropic s Claude Mythos Preview AI system identified 1,596 verified vulnerabilities in open-source projects through OSS-Fuzz over a nine-week period.
IncidentWhat Happened Threat actors have exploited publicly accessible AI endpoints that lacked authentication controls. These endpoints—serving large language models, image generation systems, and other AI c
IncidentWhat Happened In June 2026, attackers compromised the Mastra AI framework s npm publishing workflow. This breach allowed adversaries to control the package distribution mechanism, affecting the pipeli
IncidentWhat Happened Cato AI Labs discovered two critical vulnerabilities in Cursor, the AI code editor used by more than half the Fortune 500. Both flaws—CVE-2026-50548 and CVE-2026-50549, each rated 9.8 ou
IncidentWhat Happened In early 2021, an attacker modified a single line in Codecov s Bash Uploader script. This change caused the script to exfiltrate environment variables to an external server before execut
IncidentWhat Happened Adobe released emergency patches for seven vulnerabilities with CVSS scores of 10.0 across ColdFusion and Campaign Classic. These flaws, including CVE-2026-48286, represent the maximum s
IncidentOverview of the Vulnerabilities Adobe has released patches for seven maximum-severity vulnerabilities in ColdFusion and Campaign Classic. These vulnerabilities enable remote code execution through att
IncidentIncident Overview An attacker exploited AI coding agents using a technique called Agentjacking. This attack involves submitting fake bug reports with embedded instructions. The AI agent processes thes