IncidentNVD Stops Enriching Most CVEs: Teardown
What Happened On April 15, 2026, NIST announced that the National Vulnerability Database (NVD) would stop providing comprehensive enrichment for most Common Vulnerabilities and Exposures (CVEs). Inste
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened On April 15, 2026, NIST announced that the National Vulnerability Database (NVD) would stop providing comprehensive enrichment for most Common Vulnerabilities and Exposures (CVEs). Inste
IncidentOverview of the Issue In August 2019, W3Techs scanned websites and found jQuery running on 73% of them. Snyk s security research revealed that 83.4% of those jQuery installations used the 1.x release
IncidentIn early 2026, the timeline between discovering a vulnerability and its exploitation shrank dramatically—from days or weeks to mere hours. Security teams accustomed to a predictable patching schedule
IncidentWhat Happened AIR , a security research organization, deployed a fake AI agent skill marketed as a landing page builder tool. The skill passed security validation from Cisco, Nvidia, and skills.sh sca
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened A user named abdrizak published three malicious npm packages disguised as legitimate PostCSS tools: aes-decode-runner-pro , postcss-minify-selector , and postcss-minify-selector-parser .
IncidentWhat Happened Between late 2025 and early 2026, attackers discovered they could chain two vulnerabilities in LiteLLM—an open-source AI gateway used to route requests across multiple LLM providers—to a
IncidentWhat Happened On June 18, 2024, GitHub announced a security update to actions/checkout v7 to prevent workflows from executing unreviewed code from forked pull requests. This change addresses a recent
IncidentA vulnerability chain in Microsoft s AutoGen Studio allowed attackers to execute arbitrary code through malicious webpages. This flaw affected developers who built the framework from GitHub source dur
IncidentOn June 18, 2026, GitHub updated actions/checkout to prevent fetching fork pull request code when triggered by pull_request_target or workflow_run events. This change addresses an attack pattern where
IncidentWhat Happened On February 6, 2020, the Node.js project released emergency patches for versions 10.x, 12.x, and 13.x to address one critical and two high-severity vulnerabilities. The critical flaw, tr
IncidentA developer at a Fortune 100 technology company opened their AI coding assistant one morning. Within minutes, an attacker was executing code on their machine—no credential theft, no malware download,
IncidentWhat Happened On February 20, 2020, CNVD published details of CVE-2020-1938—a vulnerability affecting Apache Tomcat versions 6 through 9. Discovered by Chaitin Tech on January 3rd, the flaw exploited
IncidentWhat Happened A denial of service vulnerability was present in urllib3 , a widely-used Python HTTP library, between versions 1.25.2 and 1.25.8. This flaw allowed attackers to exhaust resources through
IncidentWhat Happened On June 2, 2020, security researcher Robert McLaughlin discovered a Regular Expression Denial-of-Service (ReDoS) vulnerability in the websocket-extensions package using an automated tool
IncidentWhat Happened On March 27, 2020, Danny Thomas disclosed CVE-2020-7599 , a vulnerability in Gradle s plugin-publish plugin that exposed pre-signed AWS URLs in log output. Every version below 0.11.0 was
IncidentWhat Happened The Snyk Research Team discovered an arbitrary code execution vulnerability in Grunt, a widely-used JavaScript task runner that automates development tasks. The vulnerability, CVE-2020-7