IncidentGoogle Bans AI Bug Reports From Its VRP
What Happened Google has announced it will no longer accept AI-generated submissions to its Open Source Software Vulnerability Reward Program (VRP). This decision follows a trend of low-quality report
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened Google has announced it will no longer accept AI-generated submissions to its Open Source Software Vulnerability Reward Program (VRP). This decision follows a trend of low-quality report
IncidentThe XM Cyber threat research team identified eight distinct attack vectors in AWS Bedrock environments. None of these exploits rely on zero-days or novel techniques. They all hinge on a single point o
IncidentWhat Happened On August 27, 2026, ServiceNow disclosed four vulnerabilities in its AI Platform, with three rated at the highest severity level, CVSS 10.0. These flaws allow attackers to execute arbitr
IncidentServiceNow disclosed three critical vulnerabilities in its AI Platform on January 14, 2025. All three received CVSS scores at maximum severity. The flaws, CVE-2026-18885 (code injection), CVE-2026-188
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened ServiceNow patched three critical vulnerabilities in its AI Platform that allowed unauthenticated attackers to execute arbitrary code and SQL statements without user interaction. The vul
IncidentIn April 2026, NIST reclassified roughly 30,000 vulnerabilities in the National Vulnerability Database as Not Scheduled. If your team relied on NVD as your single source of truth, you just lost visibi
IncidentAn unauthenticated attacker just created an admin account on a nonprofit s WordPress site. They didn t need credentials or exploit a complex chain. They sent a single HTTP request to a donation form.
IncidentThe Threat Landscape In 2025, financial services organizations blocked 893 malicious packages from entering their development environments. By mid-2026, they d intercepted 572 more. These packages wer
IncidentWhat happened On July 27, Gitea released version 1.27.1 to patch CVE-2026-60004, a critical remote code execution vulnerability in its diffpatch API endpoint. This flaw allows attackers to execute arb
IncidentWhat Happened In early 2024, security researchers disclosed EchoLeak, a zero-click prompt injection vulnerability in Microsoft 365 Copilot with a CVSS score of 9.3. This flaw allowed attackers to mani
IncidentOn April 17, 2025, Vercel shipped emergency patches for Next.js after discovering two critical vulnerabilities that let unauthenticated attackers execute arbitrary code on affected servers. One exploi
IncidentA coordinated operation by the Australian Federal Police has led to the arrest of two individuals linked to TeamPCP, a hacking group responsible for supply-chain attacks that compromised over a thousa
IncidentThe Australian Federal Police charged two men with 14 offenses tied to TeamPCP, a cybercrime group that compromised multiple open-source security tools to distribute malware through trusted channels.
IncidentWhat Happened Australian Federal Police arrested two individuals linked to TeamPCP, a cybercrime group that compromised at least 3,800 GitHub repositories. The group deployed Shai-Hulud, a self-propag
IncidentIn April 2026, cyber threat assessment firms discovered malicious code in open-source npm packages. By the time Australian Federal Police and the FBI arrested two alleged members of TeamPCP, over 1,00
IncidentA prompt injection flaw in Amazon s Kiro IDE allowed attackers to exfiltrate source code and credentials through a feature meant to assist developers. Disclosed by Mindgard in late 2024, the vulnerabi