IncidentNVD Stops Enriching Most CVEs: Teardown
What Happened On April 15, 2026, NIST announced that the National Vulnerability Database (NVD) would stop providing comprehensive enrichment for most Common Vulnerabilities and Exposures (CVEs). Inste
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened On April 15, 2026, NIST announced that the National Vulnerability Database (NVD) would stop providing comprehensive enrichment for most Common Vulnerabilities and Exposures (CVEs). Inste
IncidentOverview of the Issue In August 2019, W3Techs scanned websites and found jQuery running on 73% of them. Snyk s security research revealed that 83.4% of those jQuery installations used the 1.x release
IncidentIn early 2026, the timeline between discovering a vulnerability and its exploitation shrank dramatically—from days or weeks to mere hours. Security teams accustomed to a predictable patching schedule
IncidentWhat Happened AIR , a security research organization, deployed a fake AI agent skill marketed as a landing page builder tool. The skill passed security validation from Cisco, Nvidia, and skills.sh sca
Get weekly security insights and compliance updates delivered to your inbox.
What Happened JFrog researchers discovered CVE-2026-8461 , a heap out-of-bounds write vulnerability in FFmpeg s MagicYUV decoder. They demonstrated remote code execution on Jellyfin and Nextcloud by u
IncidentWhat Happened LastPass disclosed that attackers accessed customer data in its Salesforce environment using compromised OAuth tokens from Klue, a market intelligence platform. The breach exposed standa
IncidentWhat Happened OpenAI and Trail of Bits launched Patch the Planet, an AI-assisted vulnerability research program targeting critical open-source projects. The program used AI models and Codex Security t
IncidentWhat Happened A user named abdrizak published three malicious npm packages disguised as legitimate PostCSS tools: aes-decode-runner-pro , postcss-minify-selector , and postcss-minify-selector-parser .
IncidentWhat Happened Between late 2025 and early 2026, attackers discovered they could chain two vulnerabilities in LiteLLM—an open-source AI gateway used to route requests across multiple LLM providers—to a
IncidentWhat Happened ShapedPlugin, a vendor of premium WordPress plugins, experienced a supply chain attack that injected backdoor code into official releases of multiple Pro plugins. This affected Product S
IncidentWhat Happened On June 18, 2024, GitHub announced a security update to actions/checkout v7 to prevent workflows from executing unreviewed code from forked pull requests. This change addresses a recent
IncidentA vulnerability chain in Microsoft s AutoGen Studio allowed attackers to execute arbitrary code through malicious webpages. This flaw affected developers who built the framework from GitHub source dur
IncidentOn June 18, 2026, GitHub updated actions/checkout to prevent fetching fork pull request code when triggered by pull_request_target or workflow_run events. This change addresses an attack pattern where
IncidentOn December 11, 2019, security researcher Daniel Ruf disclosed a vulnerability that allowed any malicious npm package to overwrite arbitrary files on your system during installation. No exploit code w
IncidentYour organization has just deployed its first AI agent into production. It authenticates through your existing identity provider (IdP), accesses your cloud storage, and queries your databases — the sa
IncidentWhat Happened On February 6, 2020, the Node.js project released emergency patches for versions 10.x, 12.x, and 13.x to address one critical and two high-severity vulnerabilities. The critical flaw, tr