IncidentApache Tika's CVSS 10.0 XXE Flaw
Your application code passes every security review. Your internal XML parsing follows OWASP ASVS v4.0.3 guidance. But when Apache Tika 2.9.2 shipped with CVE-2025-66516—a CVSS 10.0 Critical XXE vulner
Expert perspectives on application security, compliance, and emerging threats
IncidentYour application code passes every security review. Your internal XML parsing follows OWASP ASVS v4.0.3 guidance. But when Apache Tika 2.9.2 shipped with CVE-2025-66516—a CVSS 10.0 Critical XXE vulner
IncidentWhat Happened Eight packages on Packagist , the primary PHP package repository, contained malicious code that downloaded and executed a Linux binary from GitHub. The attack bypassed PHP files by inser
GeneralMicrosoft has released Rampart and Clarity as open-source projects, offering new ways for organizations to enhance AI agent security. These tools address a critical issue: AI agents now execute code,
IncidentIntroduction: The Need for Continuous Adversarial Testing ASAPP, an enterprise AI provider, identified a significant gap in their security strategy: traditional pre-deployment testing couldn t keep up
Get weekly security insights and compliance updates delivered to your inbox.
IncidentIncident Overview In the Shai-Hulud incident, attackers published malicious npm packages containing hidden exfiltration scripts. These packages bypassed initial security checks and infiltrated product
IncidentWhat Happened CVE-2026-9082 , a SQL injection vulnerability in Drupal Core with a CVSS score of 6.5, moved from patch release to active exploitation faster than most security teams could deploy fixes.
IncidentAn attacker pushed 5,718 malicious commits across 5,561 GitHub repositories in just six hours. This campaign, known as Megalodon, didn t rely on a zero-day or novel vulnerability. Instead, it exploite
ResearchYou found a Google API key in a public GitHub repo. You deleted it immediately. Your work is done, right? Not for the next 23 minutes. Aikido Security s research confirms that deleted Google API keys
IncidentWhat Happened Between late 2024 and early 2025, TrendAI and CHT Security used an AI-driven static analysis system to scan WordPress plugins. This system uncovered over 300 critical zero-day vulnerabil
IncidentOn January 15, 2025, GitHub disclosed that attackers accessed internal repositories and exfiltrated source code. Days later, Grafana Labs confirmed a similar breach. Both incidents traced back to a su
GeneralThe Conventional Wisdom Security teams are excited about Microsoft s release of Clarity and RAMPART, viewing them as transformative for AI security. The idea is straightforward: integrate these open-s
IncidentWhat Happened Between May 15 and May 21, 2025, CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation. CVE-2025-34291, an origin valid
IncidentWhat Happened In December 2024, state-sponsored attackers exploited a PostgreSQL SQL injection zero-day to infiltrate the US Treasury. This vulnerability allowed them to bypass authentication controls
IncidentOverview of the Vulnerability ChromaDB versions 1.0.0 through 1.5.8 have a critical vulnerability allowing unauthenticated remote code execution. The flaw, tracked as CVE-2026-45829, exploits a race c
IncidentAn AI agent you deploy to automate customer support queries suddenly starts leaking API keys to an external server. Your incident response team traces it back to a helpful skill you installed three we
IncidentIntroduction Google s integration of CodeMender, an AI-powered vulnerability remediation agent, into the Gemini Enterprise Agent Platform marks a strategic shift in AI security governance. This move d