Incident61% of AI Vulnerabilities Go Unpatched
The Growing Security Debt in AI Organizations rushing to deploy AI features are creating a security backlog they cannot manage. According to Cobalt s AI and Pentesting Pulse Report 2026, AI and LLM ap
Expert perspectives on application security, compliance, and emerging threats
IncidentThe Growing Security Debt in AI Organizations rushing to deploy AI features are creating a security backlog they cannot manage. According to Cobalt s AI and Pentesting Pulse Report 2026, AI and LLM ap
IncidentThe Issue at Hand Between 2017 and 2018, ReDoS (Regular Expression Denial of Service) vulnerabilities in npm packages surged by 143%. This wasn t an isolated incident but a widespread issue across the
IncidentUnderstanding the Vulnerability On February 11, 2019, security researchers disclosed CVE-2019-5736 , a critical vulnerability in runC that allows a malicious container to overwrite the host s runC bin
IncidentWhat Happened Between June 18 and June 28, 2025, attackers exploited CVE-2026-12569 in PTC s Windchill and FlexPLM platforms to achieve unauthenticated remote code execution. PTC confirmed active expl
Get weekly security insights and compliance updates delivered to your inbox.
IncidentThe Growing Threat of Third-Party Library Vulnerabilities Between 2022 and 2024, vulnerabilities in application libraries surged by 88%. This isn t just a story of breaches—it s about the growing tech
IncidentThe Hidden Risk in Your Dependency Tree Snyk s analysis of over one million open source projects revealed a significant supply chain issue: 78% of vulnerabilities exist in indirect dependencies—the pa
IncidentOn May 25, 2026, attackers uploaded compromised npm packages that exploited Visual Studio Code to deploy InvisibleFerret, a Python-based information stealer. The attack targeted developers on Windows,
IncidentOn March 26, 2019, version 3.2.0.3 of the bootstrap-sass package was published to RubyGems, containing a backdoor that enabled remote command execution on any server that installed it. With over 28 mi
IncidentWhat Happened On April 18, 2019, security researchers disclosed a CRLF injection vulnerability in urllib3 , a Python HTTP client library foundational to over 500 open-source libraries. This vulnerabil
IncidentOverview The official Node.js Docker image from Docker Hub contains 567 vulnerable system libraries in its base layer. This is not due to an exploit or breach—it s the default state of one of the most
IncidentWhat Happened On July 2, 2019, Snyk published CVE-2019-10744 , a prototype pollution vulnerability affecting every version of lodash. This library, used by 4.35 million projects on GitHub and download
IncidentOverview of the Issue A security analysis of the .NET ecosystem has highlighted a significant concentration of critical vulnerabilities that require immediate attention from your security team. Remote
IncidentThe Issue at Hand The jQuery team released version 3.4.0 to address a prototype pollution vulnerability in the library s object extension functionality. Researcher Olivier Arteau identified the flaw,
IncidentOn April 25, 2019, Docker Hub discovered unauthorized access to a database containing user data. Approximately 190,000 accounts were affected, exposing usernames, hashed passwords, and GitHub and Bitb
IncidentWhat Happened A malicious npm package named electron-native-notify targeted users of Komodo s Agama cryptocurrency wallet. A GitHub user, sawlysawly, disclosed the threat via a public commit, triggeri
IncidentWhat Happened An attacker compromised the maintainer account for the Ruby gem strong_password and published version 0.0.7 containing remote code execution capabilities. Rubygems.org reported 537 downl