IncidentMythos Exposed a 55-Day Remediation Gap
What Happened When Anthropic disclosed the Mythos vulnerability in their Claude AI platform, security teams faced a familiar issue: they knew what was broken but couldn t fix it quickly. The vulnerabi
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened When Anthropic disclosed the Mythos vulnerability in their Claude AI platform, security teams faced a familiar issue: they knew what was broken but couldn t fix it quickly. The vulnerabi
IncidentWhat Happened Pillar Security discovered sandbox escape vulnerabilities in multiple AI coding agents, including Cursor, OpenAI s Codex, Google s Gemini CLI, and Antigravity. These vulnerabilities didn
IncidentYour machine learning pipeline just stopped. The model checkpoints your team spent three months training? Encrypted. The curated datasets you ve been building for two years? Inaccessible. The ransom n
IncidentOn January 14, 2025, WordPress disclosed two chained vulnerabilities that allowed unauthenticated attackers to achieve remote code execution on any WordPress Core installation. Within hours, WordPress
Get weekly security insights and compliance updates delivered to your inbox.
IncidentIn March 2026, the TeamPCP attack compromised Trivy, Checkmarx, LiteLLM, and dozens of npm packages. Security teams knew about the vulnerabilities. They d logged tickets, assigned severity scores, and
IncidentWhat Happened On July 15, F5 patched CVE-2026-42533, a heap buffer overflow in nginx that allows remote attackers to crash worker processes and potentially execute arbitrary code. The vulnerability af
IncidentWhat Happened Attackers have found a way to spoof OAuth client IDs to bypass Microsoft Entra ID sign-in logs. By using a fake OAuth client ID during authentication, the sign-in event either doesn t ap
IncidentWhat Happened In the past 18 months, security teams have noticed a shift in how attackers probe their systems. SQL injection vulnerabilities that sat dormant in quarterly scan reports for years are no
IncidentWhat Happened In early 2026, Searchlight Cyber discovered two critical remote code execution vulnerabilities in WordPress Core, tracked as CVE-2026-63030 and CVE-2026-60137. These vulnerabilities, kno
IncidentOn January 29, 2025, the WordPress security team disclosed two high-severity vulnerabilities affecting WordPress 6.9 and the 7.1 beta release. Both issues, tracked as CVE-2026-60137 and CVE-2026-63030
IncidentOn July 18, 2026, WordPress released emergency patches for versions 6.9 and 7.0 to fix a critical remote code execution vulnerability. The flaw, known as wp2shell, combines CVE-2026-63030 and CVE-2026
IncidentWhat Happened Between March and June 2026, OWASP CVE Lite CLI went from initial release to Lab Project status in just three months. The tool accumulated 621 GitHub stars, over 100 forks, and more than
IncidentBetween June 29 and July 3, 2026, a threat actor published seven malicious npm packages targeting developers using Vite, a popular frontend build tool. Checkmarx discovered the campaign, dubbed ViteVe
IncidentA Go-based botnet named NadMesh has been actively scanning for exposed AI services and harvesting cloud credentials. Research from QiAnXin s XLab reveals that the botnet s operator claims to have coll
IncidentWhat Happened OpenAI s automated red-teaming system, GPT-Red, successfully attacked a production AI agent and convinced it to reprice inventory. Items normally priced above $100 were marked down to $0
IncidentWhat Happened Bugcrowd recently revised its submission policies after a surge of low-quality, AI-generated vulnerability reports. Researchers submitted findings that looked polished but lacked proof t