IncidentAI Found 8 Admin Bypasses in 6 Hours
On a Tuesday afternoon, Aikido Security deployed their AI pentest agents on NodeBB, a federated forum platform. Six hours later, they identified eight high-severity vulnerabilities, including direct a
Expert perspectives on application security, compliance, and emerging threats
IncidentOn a Tuesday afternoon, Aikido Security deployed their AI pentest agents on NodeBB, a federated forum platform. Six hours later, they identified eight high-severity vulnerabilities, including direct a
IncidentOn July 13, 2026, ServiceNow released patches for CVE-2026-6875, a critical vulnerability in its AI Platform that allows unauthenticated remote code execution. Five days later, researchers observed ac
IncidentWhat Happened On July 8, 2026, the Python Package Index (PyPI) implemented a significant change. You can no longer upload new files to a release that s more than 14 days old. If you need to add a Pyth
IncidentWhat Happened Anthropic s Mythos Preview announcement marked a turning point in how your security team should approach threat mitigation. It wasn t about a breach or vulnerability disclosure. Instead,
Get weekly security insights and compliance updates delivered to your inbox.
IncidentBetween July 12 and 13, 2026, attackers compromised ten Packagist packages tied to a legitimate PHP developer s account. They injected 583 malicious GitHub Actions workflow files across those packages
IncidentIn 2025, security teams faced 48,185 newly published CVEs, a 20.6% increase over 2024. That s 130 vulnerabilities disclosed every day. If your team tried to patch everything, you d never ship code aga
IncidentAn attacker sent a phishing link. The victim clicked it while logged into ChatGPT. Four clicks later, an autonomous AI agent was installed in their OpenAI workspace with persistent access to Outlook,
IncidentA critical vulnerability in Windmill s workflow platform lets attackers read any file on your server without logging in. If you re running an unpatched instance, they ve likely already done it. What H
IncidentOn the day Mozilla released 18 security patches for Firefox, Anthropic s red team used Claude Mythos Preview to analyze them. Within an hour, the AI had reverse-engineered the first patch into working
IncidentThe Problem: Overwhelming Vulnerability Alerts A Fortune 100 financial enterprise was overwhelmed by vulnerability alerts. Their scanning tools flagged about 40 million potential vulnerabilities acros
IncidentWhat s Happening? Cisco has introduced Antares, a family of AI models with 350 million, 1 billion, and 3 billion parameters. These models aim to help your security team identify vulnerable code by pro
IncidentA security assessment of AI-generated codebases revealed a consistent pattern: each repository contained an average of 15 vulnerabilities. This finding emerged from analyzing production code written b
IncidentBetween August 13 and October 10, 2025, a package named Newtonsoftt.Json.Net appeared on NuGet . It mimicked Newtonsoft.Json, a popular JSON library in .NET, but it was a trojan targeting the Digitain
IncidentWhat Happened Between December 2025 and early January 2026, attackers exploited two chained vulnerabilities in WordPress core to achieve unauthenticated remote code execution. The exploit chain, dubbe
IncidentWhat Happened On July 17, 2025, attackers exploited critical vulnerabilities in WordPress s REST API batch-processing feature to install webshells and malicious plugins on unpatched sites. SearchLight
IncidentWhat Happened Microsoft patched CVE-2026-50522 in their January 2025 security update, but attackers quickly exploited it. The vulnerability, discovered by DEVCORE researchers, allows an attacker with