GeneralLLM Observability for Security Teams
Your AI service just returned an empty response. No error code. No stack trace. The model simply decided not to answer. Traditional debugging assumes deterministic behavior — same input, same output.
Expert perspectives on application security, compliance, and emerging threats
GeneralYour AI service just returned an empty response. No error code. No stack trace. The model simply decided not to answer. Traditional debugging assumes deterministic behavior — same input, same output.
IncidentWhat Happened A critical remote code execution vulnerability in Gogs , a self-hosted Git service, remains unpatched more than two months after Rapid7 reported it to the project maintainer. The vulnera
IncidentWhat Happened A critical authorization bypass vulnerability in Next.js middleware allowed attackers to circumvent authentication checks by manipulating HTTP headers. CVE-2025-29927, with a severity sc
IncidentWhat Happened Sonatype Nexus Repository versions using OrientDB faced CVE-2026-3199 , an authenticated remote code execution vulnerability with a CVSS score of 9.4. An attacker with valid credentials
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened On March 17, 2026, Rapid7 researcher Jonah Burgess disclosed a critical remote code execution vulnerability in Gogs , a self-hosted Git service used by development teams. The flaw, rated
IncidentWhat Happened On May 26 at 14:00 UTC, CrowdStrike coordinated the takedown of GlassWorm, a malware operation distributing malicious packages through public repositories. The operation initially seemed
IncidentWhat Happened Sonatype researchers discovered 176 malicious npm packages exploiting dependency confusion to compromise developer environments and CI/CD systems. Attackers published packages with names
IncidentSummary of Findings Cisco researchers tested AI models from OpenAI, Google, Amazon, and Anthropic against two attack patterns: single-prompt jailbreaks and multi-turn conversation attacks. The testing
IncidentWhat Happened Token Security researchers exploited a free Zapier account to gain write access to critical SDK packages on NPM. The attack didn t require zero-day vulnerabilities—just five known anti-p
IncidentWhat Happened A zero-day remote code execution (RCE) vulnerability in Gogs allows authenticated users to execute arbitrary commands on servers running versions 0.14.2 and 0.15.0+dev. Security research
IncidentIn a single day, attackers pushed 5,718 malicious commits across 5,561 public GitHub repositories in roughly six hours. SafeDep, the security firm that discovered the campaign, named it Megalodon. Thi
IncidentWhat Happened Between July 2025 and February 2026, attackers exploited a deserialization vulnerability in KnowledgeDeliver LMS to install the Godzilla web shell on customer systems. The vulnerability,
IncidentOverview of the Vulnerability A source-code audit by X41 D-Sec revealed CVE-2026-48710, an authentication bypass vulnerability in Starlette , the ASGI framework used by FastAPI. This flaw allows attac
IncidentWhat Happened Since October 2025, the Glassworm botnet has been targeting developers through software supply-chain attacks. Unlike traditional botnets that rely on centralized command-and-control (C2)
IncidentIntroduction Anthropic has released a security-guidance plugin for Claude Code that runs vulnerability checks during active development. This tool is transforming how teams manage vulnerabilities by i
IncidentWhat Happened GlassWorm infected developer workstations through malicious packages and browser extensions, using stolen credentials to poison over 300 GitHub repositories. The malware compromised deve