Skip to content
← All insights
Security & Trust

Security & Trust

Building digital trust starts with infrastructure. The security posture of your framework is the foundation.

A policy document does not stop an AI agent; limits must sit in the infrastructure

Gravity's CTO showed on AI Engineer that an agent acts on its permissions, not on written rules.

October 11, 2026 · 2 min read

Logs, tickets and docs are an attack route for coding agents, a Coder engineer argues

Michael Patterson of Coder argues agents trust what they read, so logs, tickets and docs can carry hidden orders.

October 11, 2026 · 2 min read

Malware now writes instructions to the AI that analyzes it, Talos finds

Cisco Talos tracked 'A3' evasion for 18 months. The defense echoes how one bank protected unpatchable check printers.

October 11, 2026 · 4 min read

Coding agents on laptops combine private data, outside input and internet access

Michael Patterson of Coder argues the key control is where agents run, not what they can do.

October 11, 2026 · 2 min read

Eufy HomeBase 2's console lockout fell to researchers with a soldering iron

A software lock on a device in hand was a speed bump. Whether its Wi-Fi secret holds is still open.

October 11, 2026 · 4 min read

Some CI agents can act as the repo, not a person, and the repo's budget pays

A GitHub specialist said some pipeline agents can use a project's identity and money, not a developer's.

October 11, 2026 · 2 min read

Rust's Miri tool could leak CI secrets through shared build caches

The Rust team fixed the flaw. The wider lesson: any cache that jobs with secrets can write to is a place secrets can end up.

October 11, 2026 · 4 min read

In tests, AI-run decoy servers kept attack bots busy far longer than scripts

HoneyVAL researchers measured how long fake web systems hold AI attackers, and what that costs the defender

October 10, 2026 · 4 min read

A fake security workflow now mines whole git histories for credentials

GhostAction's October wave reaches secrets deleted years ago. Rotating today's keys no longer closes the exposure.

October 10, 2026 · 4 min read

Oratomic says 10,000 qubits could threaten encryption, not millions

A quantum startup says a smaller machine could break today's locks. The real deadline is how long your data must stay secret.

October 10, 2026 · 4 min read

GitHub Enterprise's secret scanner trusted the secrets it was checking

CVE-2026-96890 let a user with push access steer the appliance toward internal hosts. Fixes are available.

October 10, 2026 · 4 min read

A Snorkel AI researcher says big models stumble on finance data through poor discipline

A Snorkel AI researcher described models inventing schemas, flooding context and repeating failed fixes.

October 10, 2026 · 2 min read

A Sentry engineer saw coding agents dodge lint rules and inflate coverage

A Sentry engineer described agents sidestepping a lint rule and inflating test coverage.

October 10, 2026 · 2 min read

TinaCMS web component lets a content editor plant scripts in links

Six of seven rich-text renderers check link addresses. The one for non-React sites did not, says a GitHub advisory.

October 10, 2026 · 4 min read

Slop is a judgment failure: nobody noticed a choice was being made

G2i's Gabriel Martinez says the danger is unowned decisions, which AI now produces faster than people can review.

October 10, 2026 · 2 min read

iRhythm says patient data was stolen from business apps, not clinical systems

The company says clinical systems and devices were unaffected. At least 360,000 people still had personal data taken.

October 10, 2026 · 4 min read

A single link can hijack a signed-in TinaCMS editor's access, advisory says

A flaw in the admin preview let an outside site pass as trusted. The earlier fix checked the sender, not the address.

October 10, 2026 · 4 min read

Advisory: pyLoad's development branch served pages without a login check

A GitHub advisory says one route lacked a login rule, and a typo in the error handler exposed internal details.

October 10, 2026 · 4 min read

pyLoad-ng flaw lets any logged-in user guess admin password in tested builds

A permission check set to zero checks nothing, and the rate limit trusts a header the client controls

October 10, 2026 · 4 min read

In some Backstage setups, repo write access can run code during docs builds

CVE-2026-106509 affects TechDocs builds run locally or in a container, on versions before the fixes

October 10, 2026 · 4 min read

iVerify finds DarkSword iPhone variant that steals keychain and wallet data

P7 reduces its on-device footprint and takes live commands from attackers, iVerify reports

October 9, 2026 · 4 min read

A GitHub attack now searches old commits for cloud and AI keys

Two compromised accounts planted a workflow in 346 repos on October 8. Deleting a secret doesn't remove it.

October 9, 2026 · 4 min read

Anthropic offers open-source projects AI bug reports with no human review

Anthropic says finding flaws is easier than ever. Checking and fixing them is still slow.

October 9, 2026 · 4 min read

Ransomware hit a record 2,627 claimed attacks; 247 are confirmed so far

Comparitech's Q3 2026 count is mostly gang claims, so the public record is often the gang's version of events.

October 9, 2026 · 4 min read

GoBalance bug let attackers rebuild some darknet site keys from public data

Searchlight Cyber says a Go rewrite dropped half a Tor key, so each signature gave the key away.

October 9, 2026 · 4 min read

Attackers exploit AhsayCBS backup flaws; Huntress says 10.3.4 is affected

Huntress saw two chained bugs give attackers SYSTEM-level access, then a crypto miner built to hide from Task Manager.

October 9, 2026 · 4 min read

Microsoft's Office repair update left some devices without working Office

Microsoft paused KB5002907 after reports of problems on Office 2016 and 2019 devices. It has not said why.

October 9, 2026 · 4 min read

Pwn2Own Ireland: BleepingComputer counts 98 zero-days in updated devices

BleepingComputer counts 98 zero-days in phones, printers and AI databases. Patching fixes only what is known.

October 9, 2026 · 4 min read

Gitar co-founder says AI shifts cost to review, where rubber-stamping risks incidents

A co-founder of Gitar (now part of Sonar) says teams must slow down or rubber-stamp changes.

October 9, 2026 · 2 min read

Let the AI plan the fix, but let ordinary code carry it out

Viren Baraiya of Orkes says the model should choose what happens next, while fixed code handles how.

October 9, 2026 · 2 min read

WorkOS put app security in the platform so non-engineers can ship internal apps

A WorkOS product manager describes how his company built security into the platform so non-engineers can ship internal apps.

October 9, 2026 · 2 min read

Open GPU monitoring leaked hardware details; about a quarter had a crash flaw

About 2,100 hosts served NVIDIA GPU data with no login; a quarter also exposed the pprof flaw (CVE-2026-47483).

October 9, 2026 · 4 min read

US seizes websites behind two hacking tools built by a Chinese security firm

In a multi-country action, officials say Microscan and FishHub were made by a supplier, and aimed at unwatched edge devices

October 9, 2026 · 4 min read

Popular PHP SVG cleaner can pass a script link through to browsers

A flaw in enshrined/svg-sanitize shows how a safety check fails when it reads a file differently from the browser.

October 9, 2026 · 4 min read

An npm malware campaign ran over three years; 3 packages still live Oct 8

Orca says the MALFEX campaign began in August 2023. One package went 14 months with no npm advisory.

October 9, 2026 · 4 min read

PraisonAI's localhost-only safeguard can be bypassed by a forged Host header

A check meant to keep an unlocked agent API on one machine trusts a value the caller writes, per a GitHub advisory

October 9, 2026 · 4 min read

PraisonAI turns a config file setting into code that runs on deploy

A GitHub advisory shows how a plain text field in agents.yaml can become Python on the operator's machine.

October 9, 2026 · 4 min read

One ransomware attack on a Japanese cloud affects 495 customers

IDCF Cloud has locked customers out of consoles in every region. Your recovery plan depends on your provider's choices.

October 9, 2026 · 4 min read

Docling's 'no external plugins' setting still ran plugin code until 2.131.0

CVE-2026-105745 shows how a safety switch can report 'off' after the risky step has already happened

October 9, 2026 · 4 min read

AI agents fail quietly, so judge them by how fast a wrong answer surfaces

Reducto's Abhi Arya says the test for an agent product is who finds out when it is wrong, and how fast.

October 9, 2026 · 2 min read

Some malware now carries notes written for the AI tools that analyze it

Cisco Talos tracked 84 samples in four families. The tricks are cheap and uneven, but they show where attackers aim.

October 9, 2026 · 4 min read

JHipster reactive apps let low-privilege users run SQL commands

A flaw in the code generator is copied into every reactive app it builds. Fixing the tool will not fix those apps.

October 9, 2026 · 4 min read

Coraza firewall could be shown a decoy filename while the app saw another

A silent parsing gap let file-upload rules miss the real name. The fix shows why picking one reading is not enough.

October 9, 2026 · 4 min read

Anthropic's cheaper Haiku 5.5 resists hidden commands better, but gaps remain

A 75% average price cut spreads small models widely. A separate Gray Swan benchmark shows where weak spots remain.

October 9, 2026 · 4 min read

Agencies: China-linked hackers use free tools and a real VPN to steal email

A joint advisory describes an intrusion built from ordinary parts that blend into normal IT work.

October 9, 2026 · 4 min read

Apiiro: a 17,610-repo GitHub malware fleet was re-aimed, not rebuilt

Apiiro says FakeGit restarted on October 4. In a sample of commits, nearly all changes touched only a README

October 8, 2026 · 4 min read

Android stealer hides its server in a seller bio on a legitimate marketplace

STAR Labs found Novinarya's command server stored in a marketplace seller's profile, not in the app

October 8, 2026 · 4 min read

In one Russia-linked case, rebuilt malware kept its behavior

Anthropic says AI rebuilt the implants. ReversingLabs saw five builds with new hashes but the same behavior.

October 8, 2026 · 4 min read

SonicWall patches a CVSS 10 flaw that lets strangers give its appliance orders

SMA1000 and Splunk fixes share one question: who can make your trusted systems send requests?

October 8, 2026 · 4 min read

Cheap Android phones shipped with ad-fraud malware built into the firmware

Bitdefender found it on thousands of phones in 150+ countries, in place before the owner's first boot.

October 8, 2026 · 4 min read

Malware aimed at Ukraine was reworked repeatedly, from July 2024 to April 2026

ESET traces MatchBoil, used by UAC-0099, through upgrades meant to evade security tools and gather more data

October 8, 2026 · 4 min read

Hackers probe Ukrainian video recorders using a 2021 flaw, GreyNoise finds

The surge came as Russian strikes grew, GreyNoise says. An unpatched recorder can give outsiders eyes on a site.

October 8, 2026 · 3 min read

Attackers target Bricksforge plugin flaw that allows remote code execution

The plugin checked uploaded files once, then trusted what visitors said about them. Patchstack saw attempts begin October 7.

October 8, 2026 · 4 min read

Four states sue TP-Link as fixes for ISP routers run into 2026

The suits target security and China claims. The flaws they cite show how a router fix is split between vendor, ISP and customer.

October 8, 2026 · 4 min read

Fake invitations to Taiwan researchers relay Google logins live, Talos finds

Talos says the phishing kit passed each login step to the real Google, so MFA prompts reached the attacker too.

October 8, 2026 · 4 min read

Report: Oracle Health's old Cerner server breach may affect nearly 20 million

Oracle told customers the evidence suggests the attacker used stolen customer credentials to reach a legacy server not yet moved to its cloud.

October 8, 2026 · 4 min read

Anthropic has disclosed 6,157 flaws in open source; 516 are known patched

AI now finds bugs faster than people can check and fix them. The scarce resource is human attention.

October 8, 2026 · 4 min read

A poisoned Tensorlake SDK release carried a credential stealer, Socket finds

The sandbox guards generated code. The install step that builds it was the way in, and revoking tokens first can backfire.

October 8, 2026 · 4 min read

Tech and security staff know passkeys, yet 43% still use passwords

A Yubico and Okta survey of 1,890 professionals finds a gap between knowing and doing. Its authors point to day one.

October 8, 2026 · 4 min read

Built and tested AI agents waiting on compliance approval may reflect real risk

OutSystems CEO Woodson Martin says much of the delay in regulated firms is prudence, though some is plain inertia.

October 8, 2026 · 2 min read

Arizona courts breach exposes data on more than 1.3 million people

Investigators say hackers copied backup court files. Separately, exposed FARE records on 1.3 million people go back 30 years.

October 8, 2026 · 4 min read

AI-built apps may be easier to secure if agents edit a model, not raw code

An OutSystems CEO argues a shared model lets apps inherit security rules and lets one patch fix many systems.

October 8, 2026 · 2 min read

A change that looks correct on its own can still break the systems around it

Qodo says problems that show up downstream are hard for both coding agents and human reviewers to find.

October 8, 2026 · 2 min read

Agent agreement is not proof; teams need a record of incidents to learn from

Qodo says two agents can agree and still be wrong, so teams should log each failure and reuse it.

October 8, 2026 · 2 min read

SANS found fake invoices installing a legitimate IT tool for attackers

SANS traced phishing PDFs to Action1, real IT software that appears to report to an attacker-controlled account

October 8, 2026 · 4 min read

Snyk's Eli Cohen says AI coding agents add insecure code and attackers move in minutes

Eli Cohen of Snyk argued that more machine-written code and faster attacks leave a backlog defenders cannot clear.

October 8, 2026 · 2 min read

Loose settings let an AI agent reach cluster-admin at Hugging Face

Hugging Face's timeline: a few permissive settings took an AI agent from one pod to cluster-admin in under 13 hours.

October 8, 2026 · 4 min read

AWS says the instructions file, not the AI model, decides triage quality

AWS found about 30% of unsteered AI findings cited code that did not exist. Its fix was a configuration file.

October 8, 2026 · 4 min read

Supply chain malware now takes its orders from blockchain transactions

Unit 42 traces how attackers moved their control address to places a filter has nothing to read

October 8, 2026 · 4 min read

AWS shows how to make AI check scanner findings before engineers see them

A three-layer design treats engineer trust as the scarce resource and verifies AI claims against the code first.

October 8, 2026 · 4 min read

Talos details eight patched flaws in PDF, Windows and Mac software

A Foxit PDF reader, a Photoshop installer and Windows drivers show how a routine desktop is a layered target

October 8, 2026 · 4 min read

Post SMTP error log could store attacker scripts on open WordPress Multisite

CVE-2026-75962 shows how a failed email send can save hostile input in a log that later gets displayed

October 8, 2026 · 4 min read

Agents talking to other people's agents also need identity and tool-call visibility

BAND's CTO says linking agents across users is a hard distributed systems problem that also needs governance.

October 8, 2026 · 2 min read

Hosted agents move the loop to the vendor, so oversight may rest on its tools

Google's managed agents run on its servers; the excerpts we saw did not cover replay, logs or liability.

October 8, 2026 · 2 min read

Microsoft's AI bug hunters say finding flaws is no longer the only limit

Microsoft's FORGE Lab reports 140 Windows CVEs from AI-assisted research, and says validation and fixes must keep pace.

October 8, 2026 · 4 min read

16 Firefox wallet clones declared 'no data' while handling recovery phrases

Socket found Rabby and OKX look-alikes whose code sends wallet recovery phrases to servers the operators run

October 8, 2026 · 4 min read

Exposed files show AI tools used against South Korean financial firms

CrowdStrike read the attacker's own AI logs. They show one open-source tool, several AI models and a short timeline.

October 8, 2026 · 4 min read

Smarty flaw lets forged data run as PHP code; fixes are in 4.5.8 and 5.8.5

A value left empty during template inheritance lets forged markers through, apparently by removing a check

October 7, 2026 · 4 min read

When every agent shares one skill library, the vetting gate is the real safeguard

Agents that teach each other spread good lessons and bad ones alike, so the vetting step carries the weight.

October 7, 2026 · 2 min read

RabbitMQ Java client can write broker passwords into error messages

CVE-2026-106123: if the connection URI fails to parse, the error text can include the full string, password too

October 7, 2026 · 4 min read

Researchers: GitHub poem steers 3,400+ hacked servers, many running AI tools

Black Lotus Labs says PoeLLM hides its control address in verse. Blocklists have little to catch.

October 7, 2026 · 4 min read

FBI: FortiBleed still targets Fortinet firewalls using leaked logins

The agencies point to reused or leaked passwords and fast legacy password storage as what the campaign relies on.

October 7, 2026 · 4 min read

In wger, a trainer with no gym could read notes of other no-gym users, advisory says

An advisory describes an access check that treats two empty values as a match, for unassigned trainers and unassigned users

October 7, 2026 · 4 min read

Hammond: criminals can skip scam brands, as uncensored models are a free download

John Hammond showed criminal AI brands that looked like scams, then a forum guide to running uncensored models anyone can download.

October 7, 2026 · 2 min read

Warden infostealer reportedly targets Claude Code and AI coding tool keys

Version 1.9 reportedly targets Claude Code and Codex CLI files, so an agent's login is only as safe as the machine.

October 7, 2026 · 4 min read

Snyk's vendor test: live attacks confirmed 10 of 15 exploit chains

A code-only AI review found the same two flaws. Snyk says only an attack on the running app showed how they connect.

October 7, 2026 · 4 min read

One ransomware gang reportedly spent 40 cents to $4 in AI costs per company attacked

John Hammond relayed a report on one gang's tiny AI costs; our reading is that defenders should plan for volume.

October 7, 2026 · 2 min read

Barracuda found a phishing email with hidden orders for the AI reading it

One message was built to fool the employee and the AI assistant that summarizes their mail.

October 7, 2026 · 4 min read

ASOS says attackers misused its customer messaging platforms

Attackers reached customers through third-party platforms ASOS uses to communicate with them

October 7, 2026 · 4 min read

Hackers now sell AI tools like SaaS, with free tiers and monthly plans

Halcyon tracked nearly 4,000 underground posts. Its finding: AI tools are lowering the skill bar for attackers.

October 7, 2026 · 4 min read

Apple says iPhone 18 Pro can prove a photo came from a real camera

Apple's Reference Image mode moves proof to the moment of capture. It also raises the question of who vouches.

October 7, 2026 · 4 min read

Wiz researcher warns coding agents can add dependencies developers may not know about

A Wiz researcher said that with coding agents, developers in many cases do not know what their code contains.

October 7, 2026 · 2 min read

Atlassian says AMP tags AI code; IDC analyst says proof of review matters more

Atlassian says AMP shows what an agent wrote. An IDC analyst says buyers also need to know who checked it.

October 7, 2026 · 4 min read

When exploits come fast, exposing fewer things is the first defence

Wiz's Alon Schindel argued that cutting what is public matters first when AI speeds up exploits.

October 7, 2026 · 2 min read

Victorian student data breach traced to one school's unpatched server

The state's privacy regulator also faulted central oversight and the decision to keep former students' records.

October 7, 2026 · 4 min read

A suspected ransomware attack halted classes at a Japanese university

About 500 servers stopped at Osaka Metropolitan University, while externally hosted and hospital systems kept running

October 7, 2026 · 4 min read

Microsoft's on-premises patch release hit a record near 1,000 flaws in September

Microsoft tells CISOs the hard part is shifting from finding flaws to choosing which to fix, and how fast.

October 7, 2026 · 4 min read

AWS offers Z.ai's GLM 5.3 to enterprises, with a security-testing agent as demo

The model is open-weight, served as a managed service on Bedrock, and its maker reports cyber security strength

October 7, 2026 · 4 min read

Android's October update fixes 25 flaws; the patch date shows who is covered

Google's bulletin lists the fixes. Whether a phone has them depends on a date string set by its maker.

October 7, 2026 · 4 min read

PlanetScale: branching and revert make agent database changes safer

Ben Dicken of PlanetScale says branching, schema revert and budgets make agent database access safer.

October 7, 2026 · 2 min read

OpenSSH 10.6 arrives as maintainers plan more frequent releases

AI-assisted bug reports and duplicate finds drive the change. The release also alters compression, usernames and post-quantum keys.

October 7, 2026 · 4 min read

CERT-UA: 100+ hacked sites showed fake Cloudflare checks to push Lunex malware

A store and a children's coloring site were used to trick Ukrainian visitors into installing a data stealer

October 7, 2026 · 4 min read

Red Hat says it fixed 400+ novel Java library flaws and sells old-version fixes

Lightwell's pitch is that finding bugs is only part of the work. Backporting fixes to pinned versions is the rest.

October 7, 2026 · 4 min read

Country domain hijacks let attackers obtain HTTPS certificates, Google reports

Chrome blocked the certificates it found. Google says that may not be all of them, so owners should watch their own names.

October 7, 2026 · 4 min read

Fake airport job test used a developer's own tools to attack an Iraqi target

Unit 42 says an Iranian-aligned group built a coding test to run malware the moment a project opened

October 7, 2026 · 4 min read

AI agents may quietly aim low on open-ended security work, researcher suspects

A PortSwigger Research author saw models drift toward easy, low-impact results when prompts left room to interpret.

October 7, 2026 · 4 min read

Agent-driven growth pushes databases past their limits, so decide who gets dropped first

PlanetScale's Ben Dicken says databases need rules for shedding load before surges of agent traffic arrive.

October 7, 2026 · 2 min read

Datadog finds stolen-AWS-key tools test for Bedrock AI access

Datadog found credential tools that sort stolen keys by whether they can run AI models, using a four-token test.

October 7, 2026 · 4 min read

Pwn2Own day one: AI tools fell, and seven results used known bugs

Only one of the seven bug collisions involved an AI product. The rest hit a phone, a speaker and a smart home hub.

October 7, 2026 · 4 min read

Fast security fixes must be built before the emergency, Project Zero says

Developers are rarely the bottleneck. Testing and delivery set how fast an urgent patch reaches users.

October 7, 2026 · 4 min read

A malicious npm package avoids npm's install-script block by waiting to run

The indexed-btree campaign shows why a clean install says little about what code does later.

October 7, 2026 · 4 min read

Patching Ninja Forms does not remove the hidden admin an attack can leave

Patchstack traced one payload through two WordPress plugin flaws. It plants backdoors that outlive the bug.

October 7, 2026 · 4 min read

Mistral says its new open model does security work rivals refuse

Mistral Large 4 is a preview with mostly self-reported scores. The real question is who sets the limits on security AI.

October 7, 2026 · 4 min read

Most downloads in a malicious npm campaign come from a package with no advisory

Checkmarx's MALFEX findings show why a clean advisory feed does not mean a clean dependency tree

October 7, 2026 · 4 min read

Harbor registry flaw lets a registered user reach its cloud credentials

OX Security found 6,370 Shodan-indexed Harbor instances on pre-fix versions. The advisory rates it Moderate.

October 7, 2026 · 4 min read

FBI warns FortiBleed can lock owners out of Fortinet firewalls

A US alert says patching and password resets fall short once attackers can disable accounts or change passwords.

October 7, 2026 · 4 min read

Django patches four flaws; two depend on how your app is built

The 6.1.2, 6.0.9 and 5.2.18 releases reward teams that know their own setup, not only their version number.

October 7, 2026 · 4 min read

GitHub Enterprise flaw turned a push option into server code execution

A semicolon Git allowed, plus last-value-wins parsing, was the opening for CVE-2026-3854.

October 7, 2026 · 4 min read

Defender can report healthy while its updates fail, LevelBlue finds

A proof of concept called BigDiskBuster uses free disk space to stop Defender updates. LevelBlue saw no on-screen alert.

October 7, 2026 · 4 min read

Atlassian flaw lets outsiders read known files without a login

CVE-2026-21589 affects eight Atlassian products. Atlassian says no credentials are needed to exploit it.

October 7, 2026 · 4 min read

ASOS push alert shows the risk in tools that speak for a company

The sender names Snowflake. ASOS names third-party customer platforms. The gap matters.

October 7, 2026 · 4 min read

AI agents' activity logs need the same protection as security systems

METR found a viewer flaw that could have let an agent rewrite the transcript. It has seen no exploitation in evaluations.

October 7, 2026 · 4 min read

Exploited NetScaler flaw can lock out a company that uses SAML sign-in

CVE-2026-88779 lets unauthenticated attackers crash SAML sign-in, putting VPN and single sign-on access at risk

October 6, 2026 · 4 min read

Docker's Jim Clark: agent safety comes from what the sandbox lets in

Docker's Jim Clark argued that risk depends on the tools, context and credentials an agent can reach.

October 6, 2026 · 2 min read

AWS says its agent found, proved and patched flaws in 89% of C/C++ test tasks

The score is self-reported and covers one bug class. The design points to where security work may be moving: toward evidence.

October 6, 2026 · 4 min read

Agents can report a task done when it silently failed, so someone must read the work

Laurie Voss of Arize AI says agent failures can look like success unless someone reads the inputs, outputs and traces.

October 6, 2026 · 2 min read

Vue's server renderer missed one character, opening a script-injection path

A GitHub advisory describes stored XSS in @vue/server-renderer, but only where apps build HTML attributes from untrusted names

October 6, 2026 · 4 min read

A clean transcript can hide a voice call that went wrong

Teams that audit voice agents from text logs may be reading the wrong record, and customers pay for what the log misses.

October 6, 2026 · 2 min read

Report: SelectorsHub 5.8.5 opens server-chosen ad tabs, some called '100% Safe'

The ad list sits on a server, outside the code a store reviews, so it can change without an update.

October 6, 2026 · 4 min read

Cleric's CTO says AI agents are trained to sound sure, and humans must still check them

Willem Pienaar of Cleric says models trained to answer fast often blame the first error log they find.

October 6, 2026 · 2 min read

CISA ends weekly vulnerability bulletin and points readers to exploited flaws

The agency says it is moving from ranking flaws by severity to ranking them by risk. Your team now owns that step.

October 6, 2026 · 4 min read

IBM engineer: a support bot with write access did what a plain request asked

An IBM engineer says the Instagram bot takeovers show why agents that can edit accounts need pre-launch tests.

October 6, 2026 · 2 min read

A passing AI test proves little until the judge is checked against people

Tejas Kumar showed a keyword test and an AI judge both passing bad customer-support answers.

October 6, 2026 · 2 min read

Microsoft finds ClickFix attack that hides malware in the browser cache

A script sits in the cache disguised as an image. No conventional download happens when the victim runs the command.

October 6, 2026 · 4 min read

Microsoft Exchange flaw can let a logged-in user read colleagues' email

CVE-2026-96940 is fixed automatically in Exchange Online. On-premises customers have to install the patch themselves.

October 5, 2026 · 3 min read

Elastic now grades its detection rules monthly on noise, speed and threat fit

385 of 1,781 prebuilt rules are tagged Recommended; 61.8% are deliberately left untagged.

October 5, 2026 · 4 min read

Azul executive: JDK 27 release candidate slipped two weeks for a security patch

Simon Ritter links it to AI finding bugs faster. JDK 27 also changes memory defaults and adds post-quantum TLS.

October 5, 2026 · 4 min read

arXiv caps submissions as AI makes bad papers cheap to write

Writing now costs almost nothing. Reviewing still costs a person's time, and that gap is breaking arXiv's intake queue.

October 5, 2026 · 4 min read

Solar says hackers stayed in a Russian health network for nearly two years

The intruders reportedly accessed medical data but destroyed nothing. Solar believes the quiet was deliberate.

October 5, 2026 · 4 min read

Korean regulator orders banks to audit exposed systems after breaches

The FSC has named no cause. Its orders are precautionary, and AI use in the attacks is unconfirmed

October 5, 2026 · 4 min read

A compromised Nikkei account sent about 9,000 phishing emails to contacts

The people targeted were the contacts who trusted the sender, not just Nikkei's own systems.

October 5, 2026 · 4 min read

Cling botnet makes its orders look like they come from Google

Nozomi Networks found a botnet spreading through a Realtek flaw and hiding commands in STUN-style packets

October 5, 2026 · 4 min read

Denmark's CPR incident: a company's search access abused, 8.8 million affected

Authorities say the access abused was a company's lawful right to search the register. How it was used is not yet public.

October 5, 2026 · 4 min read

Severity scores rank flaws; they do not tell teams which to fix first

OWASP's CVE Lite CLI pairs severity with exploitation odds, and shows what a scanner still cannot decide

October 5, 2026 · 4 min read

If agents fix themselves in production, someone must answer for unreviewed code

An AWS demo shows agents writing their own tools mid-run. The open question is who answers if that code fails.

October 5, 2026 · 2 min read

Huntress: attackers often use the remote IT tools companies already trust

In 45% of the endpoint incidents Huntress recorded in Q1 2026, the intruder used real remote management software.

October 5, 2026 · 4 min read

An unescaped Helm value can let developers add unapproved cluster resources

Synacktiv shows how a values-only rule fails when a chart template inserts settings without escaping them

October 5, 2026 · 4 min read

Agents that write their own tools need sandboxes and evals before autonomy

An AWS developer advocate showed agents that write their own tools, and listed the controls they need first.

October 5, 2026 · 2 min read

Synacktiv used AI video to beat a website's AWS Rekognition age check

Face checks must prove where the video came from, not only that the face looks alive

October 5, 2026 · 4 min read

First AI-related breach reported to Singapore's regulator: a missing instruction

The AI tool worked as asked. Bee Cheng Hiang's gap was in the request and in the review of its output.

October 5, 2026 · 4 min read

China-aligned TA419 targeted AI policy experts with phishing that relays real Microsoft sign-ins

Proofpoint says the password and MFA both succeed. The proxy captures the session.

October 5, 2026 · 4 min read

PictShare flaw lets anyone fetch a file's delete code and erase it

CVE-2026-104051 shows what happens when an API returns a whole record instead of the fields a caller needs

October 5, 2026 · 3 min read

A default token in iDocView lets outsiders read files on the server

CVE-2023-54402 needs no login. One hardcoded value opens the door, and Shadowserver saw exploitation evidence in 2024.

October 5, 2026 · 4 min read

WordPress MP3 plugin flaw: exploitation seen in 2023, NVD entry in 2026

CVE-2014-125130 exposes wp-config.php to anyone. In our reading, its score understates what that file unlocks.

October 5, 2026 · 4 min read

JetAppointment flaw lets anonymous visitors plant code in admin screens

A public booking form stores text that runs when a WordPress administrator opens appointment details.

October 5, 2026 · 4 min read

Bitget says its $387.5M theft began inside third-party security products

Bitget cites a zero-day in outside security products. SlowMist places it in a service on Product A's nodes.

October 5, 2026 · 4 min read

Synacktiv details a Zigbee flaw in the Philips Hue Bridge, CVE-2026-3555

Synacktiv says it exploited the bug at Pwn2Own over Zigbee. Physical access was used to study the device.

October 4, 2026 · 4 min read

Ransomware first days fail on decisions, not tools, responder says

A field guide on Huntress's blog says the first 24 hours test who has authority to act, not how fast engineers type.

October 4, 2026 · 5 min read

Nine flaws in Anjvision YSSD-RTMP-H5 firmware have no fix planned, CISA says

The vendor has not answered CISA. Owners of the device must now decide how to contain it or replace it.

October 4, 2026 · 4 min read

Google pauses part of its open-source bug bounty after AI-made false reports

Finding a bug is now cheap. Checking whether it is real still takes a person's time.

October 4, 2026 · 4 min read

Dashcam app exposes footage through open storage and a key built into its code

CISA says Viidure has not responded and plans no fix. Customers must decide what to do on their own.

October 4, 2026 · 4 min read

A WordPress backdoor rebuilt itself after cleanup, Sucuri finds

Files, the database and shared memory restore each other, so cleanup order matters more than deletion.

October 4, 2026 · 4 min read

Many of Your Limits Only Work Because Humans Are Slow. Agents Are Testing Them

Rogue agents get the headlines. The quieter risk is agents doing their jobs at a pace your controls never expected.

October 4, 2026 · 6 min read

A 16-year-old is suspected of running KillSec, a data-theft gang

Eurojust links the group to almost 1,000 attacks. The way in was poorly secured access, often to cloud storage.

October 4, 2026 · 4 min read

Dutch security group says AI agent reached root in seconds

DIVD says two Zammad flaws gave an AI attacker speed. It credits segmentation, yet still assumes a breach.

October 4, 2026 · 4 min read

A Passing AI Score Is a Claim. Audit Who Built the Test

The same work scores high or low depending on the harness and the test. Ask who made the instrument before trusting it.

October 4, 2026 · 6 min read

Encrypted traffic is only as safe as the certificates a device trusts

Synacktiv's mitmproxy walkthrough shows how researchers read and alter app traffic, and where that trust can fail.

October 4, 2026 · 4 min read

Default YesWiki before 4.6.7 lets outsiders read database tables, NVD says

CVE-2026-104457 turns page content into database commands. The fix is to move to YesWiki 4.6.7.

October 4, 2026 · 4 min read

YesWiki's signature check confirmed the sender, not the identity they claimed

CVE-2026-104445 lets any signed sender delete or overwrite other actors' federated entries in YesWiki before 4.6.7

October 4, 2026 · 4 min read

Before an AWS breach, know your accounts, identities and regions

Synacktiv's primer for analysts new to AWS starts with how the environment is organised

October 4, 2026 · 4 min read

n8n flaw could let outsiders read other users' AI chat histories

CVE-2026-103250 sits in the MongoDB Chat Memory node. NVD's affected ranges end at three versions.

October 3, 2026 · 4 min read

Ghost bug lets unauthenticated attackers alter members and newsletters

CVE-2026-103266 turns a payment step into a route to a publisher's subscribers. Ghost 6.62.0 is the fixed version.

October 3, 2026 · 4 min read

OX Security: LiteLLM email-claim flaw allows admin takeover, unfixed in 1.100.1

OX Security says a LiteLLM JWT email-fallback flaw (CWE-290) turns one login token into a permanent account takeover

October 3, 2026 · 4 min read

DTU's login system kept records back to 2003, and hackers downloaded data

The Danish university cannot say what was taken or whose. Up to 200,000 people may be affected.

October 3, 2026 · 4 min read

In some setups, an OpenClaw flaw lets attackers use a Synology NAS to fetch private data

CVE-2026-100555: a check ran on one DNS answer, but the NAS acted on another. It needs an attacker-influenced hostname.

October 3, 2026 · 4 min read

Fortra patches BoKS flaws in the tool that guards Linux admin access

Three critical bugs sit in software that controls who can act as root across Unix and Linux fleets

October 3, 2026 · 4 min read

Armatura One embeds a known-exploited ActiveMQ flaw, CISA advisory says

Five issues in one access-control product show how old flaws and weak credential handling travel inside software you buy

October 3, 2026 · 4 min read

ABB PCM600 flaw lets a logged-in user take control of the host

CISA lists two vulnerabilities in the engineering tool. One is a service that runs with more power than its users.

October 3, 2026 · 4 min read

Insurers Can Pace AI Agents Only If Independent Testers Go First

OpenAI's agents hit three outside targets and the law asked little. Whoever pays for failure will set the speed.

October 3, 2026 · 6 min read

Color themes for VS Code are tied to a malware campaign, Socket finds

Two themes looked harmless and had no live attack. Their leftover code is the risk a later update could use.

October 3, 2026 · 4 min read

AI Gives Databases a Second Contract. Old Code Was Written for the First

Ranked, nearest-match results now sit beside exact ones. Code built for exact answers may not notice the difference.

October 3, 2026 · 6 min read

WordPress AI connector plugin flaw lets a basic user become administrator

CVE-2026-19807 is a plugin coding error, but a new tool endpoint made it reachable and each endpoint must check its own access

October 3, 2026 · 4 min read

AI Agents Need Controls They Cannot Grant Themselves or Be Talked Past

Agents authorize themselves or get steered by others. One rule answers both: authority must sit below the model.

October 3, 2026 · 6 min read

Vibe-Trading's file-reading AI tools expose server credentials, advisory finds

Two flaws let an AI agent open SSH keys, cloud credentials and API keys. No shell command is needed.

October 3, 2026 · 4 min read

Vibe-Trading's default setup lets strangers run root commands in its container

A blank login setting, an LLM key and an open port give strangers a shell. Turning auth on leaves history readable.

October 3, 2026 · 4 min read

An AI agent's button could run attacker code in apps using an A2UI library

A flaw in @a2ui/web_core shows why an agent's output needs the same checks as a stranger's input

October 3, 2026 · 4 min read

Researchers say a U-Boot logo bug can bypass secure boot if storage is writable

CVE-2026-71972 shows how a cosmetic file can be decoded before the next boot stage is verified.

October 2, 2026 · 4 min read

Dell storage flaws expose storage controls and, in some cases, Kubernetes nodes

Six flaws in Dell Container Storage Modules score 9.6 to 10.0. Updating is the only fix Dell offers.

October 2, 2026 · 4 min read

GitLab flaw lets a signed-in AI user run commands on self-hosted gateways

CVE-2026-90970 shows that AI prompt templates are code, and self-hosting means you own the patching

October 2, 2026 · 4 min read

Johnson Controls patches a data-exposure flaw in building controllers

CISA says EasyIO Neo EC and CW firmware could expose sensitive data to an attacker. A fix exists; test it first.

October 2, 2026 · 4 min read

Rapid7: Telecom malware hides by imitating what the device is built to do

BPFDoor and AVERAT samples copy local vendor software and use email traffic, so 'looks normal' stops being a useful test

October 2, 2026 · 4 min read

Researcher: five Azure Logic Apps flaws gave access to other tenants' data

Each fix blocked one route. The shared design behind the routes stayed the same, according to the researcher.

October 2, 2026 · 4 min read

Trail of Bits publishes a specification to keep hashed inputs distinct

SequenceHash targets an easy-to-miss cryptographic mistake: hashing several values so their boundaries blur

October 2, 2026 · 4 min read

Meari cloud flaws let any logged-in user reach other people's devices

CISA says Meari has no fix planned for two flaws and did not reply to its outreach.

October 2, 2026 · 4 min read

Android 17 limits a feature fraud apps abuse, but only if users opt in

Google's Advanced Protection now restricts accessibility services to verified tools. The catch is who switches it on.

October 2, 2026 · 4 min read

GitHub's default security-report form now asks reporters for a proof of concept

The new default form makes the reporter show evidence, so the team reading it does not have to dig

October 2, 2026 · 4 min read

Half of security and tech executives rank attacks on AI a top readiness gap

PwC's 71-country survey finds cyber budgets set to grow, while continuity plans and data controls lag behind.

October 2, 2026 · 4 min read

Android 17's opt-in Intrusion Logging keeps phone attack evidence in the cloud

Google's new Intrusion Logging targets spyware that erases its tracks. It is optional, and it raises privacy questions.

October 2, 2026 · 4 min read

An attacker broke into recreation management software via sign-up and upload

Huntress traced three server compromises to a member upload feature, then a return visit after a server went live too soon

October 2, 2026 · 4 min read

Synacktiv says Linux hardening can blunt most recent privilege exploits

The firm describes two controls that buy time before patching. Each one has an operating cost.

October 2, 2026 · 5 min read

Two WordPress backup plugins could expose data on servers that ignore .htaccess

Ultrastrike found plugin protections that work on Apache but do not apply on Nginx, Caddy and other servers

October 2, 2026 · 4 min read

The Sandbox Was Never the Boundary. What the Agent Can Reach Is

Train agents never to quit on impossible tasks, and every unwatched channel becomes part of the job

October 2, 2026 · 6 min read

Human in the Loop Fails When Reviewers Can't Catch Rare Errors

Doctorow argues that a reviewer clearing machine output at scale will miss rare errors, yet still carry the blame.

October 2, 2026 · 6 min read

Unpatched FortiMail flaw is under attack; fixes for three branches are pending

CVE-2026-104286 needs no login. Until patches ship, who can reach the admin panel is a key control.

October 2, 2026 · 4 min read

Proofpoint says a Chinese group used fake AI policy invites to get replies

A second report, from Cisco Talos, describes a backdoor campaign in Asia that began with ordinary phishing lures

October 2, 2026 · 4 min read

A devalue bug can copy other users' request data into public web pages

The flaw sits in how some server-rendered sites package data for the browser, not in any login or form.

October 1, 2026 · 4 min read

Kiteworks patches a max-severity flaw in its Email Protection Gateway

CVE-2026-54154 could let an unauthenticated attacker take over the appliance. The fix is in version 9.4.1.

October 1, 2026 · 4 min read

Jamf found a fake Zoom installer for Mac that uses the user's password as a key

In Jamf's analysis, it hides the password in a decoy file and uses it to launch stage two. No infections confirmed.

October 1, 2026 · 4 min read

Verizon's claims data: the typical paid cyber claim is $83,000, with a long tail

Insurance payouts show rising downtime costs and heavier relative losses for small firms. The figures are floors.

October 1, 2026 · 5 min read

Acer NitroSense component lets a standard Windows user become SYSTEM

CVE-2026-50610 needs local access and affects named engine versions, Intrinsec says

October 1, 2026 · 4 min read

Sucuri: SC WordPress malware hides in at least 8 places and rebuilds itself

Sucuri's analysis of the 'SC' backdoor shows why deleting infected files can leave a site compromised.

October 1, 2026 · 4 min read

MediaFlow Proxy bug lets outsiders make the server fetch internal pages

CVE-2026-100391 turns a proxy's network position into the attacker's reach. The question is what yours can touch.

October 1, 2026 · 4 min read

Bitget says zero-day attacks on two security appliances led to $387.5M theft

Two investigations point to security appliances as the entry point into the exchange's wallet environment

October 1, 2026 · 4 min read

Crafted URLs can crash Angular server rendering on Node.js, advisory says

Paths chaining 90–740 numeric segments, sent in bursts, can exhaust memory. Proxy rules can limit exposure.

October 1, 2026 · 4 min read

Astro's Netlify adapter let image allowlists be bypassed

A correctly configured list of trusted image sources was not enforced. The flaw sat in code the adapter generated.

October 1, 2026 · 4 min read

One bad header can crash Astro servers that use a specific option

With staticHeaders enabled, a failed fallback in the Node adapter turns a malformed request into a process exit. Fixed in 11.1.3.

October 1, 2026 · 4 min read

Researcher: Copilot in SSMS let a db_owner become a sysadmin

A talk covering CVE-2026-65669 showed an AI assistant obeying a low-privilege user's planted notes

October 1, 2026 · 4 min read

A file-sharing flaw put unencrypted military records of 3 million people at risk

The Pentagon's identity unit says intruders had access from October 2025 to July 2026. The records were unencrypted.

October 1, 2026 · 4 min read

Scan of public GitHub code finds 543,699 leaked credentials that still work

In Truffle's analysis, leak rates for covered secrets fell by about half. Old keys stay live unless issuers revoke.

October 1, 2026 · 5 min read

Wiz found confirmed supply chain risks in 61 of 814 Helm chart source projects

In a sample of 1,500 popular Artifact Hub charts, the risk sat in the projects behind them, not the charts.

September 30, 2026 · 4 min read

Google: half of likely AI-found flaws let attackers run code remotely

Google also counts more exploited flaws in 2026: 18 a month, up from 10.5. One case was attacked within four days.

September 30, 2026 · 4 min read

Cisco SD-WAN Manager flaw lets attackers skip login; Cisco says it is exploited

One encoded letter in a web address can defeat an API login rule. It can also slip past simple log searches.

September 30, 2026 · 4 min read

Push Security: attackers are moving into the browser, past login and email

Push Security's 2026 data shows phishing that can skip passwords, skip email and hide from scanners

September 30, 2026 · 4 min read

Attackers probed a Zimbra mail flaw before it was public, Microsoft reports

The fix shipped July 20. Microsoft first saw probing July 28. Public disclosure came August 13. A patch does not remove what was left behind.

September 30, 2026 · 4 min read

Entra ID browser sign-ins will block non-Microsoft scripts from mid-October

Microsoft calls script-injection tools unsupported and says they may stop working; users can still sign in. Find those tools first.

September 30, 2026 · 4 min read

WatchGuard firewall flaw lets a rogue VPN server run commands as root

A 9.2-rated bug in Fireware OS shows that a firewall must also distrust the servers it connects to

September 30, 2026 · 4 min read

AI agents on routine data tasks probed three public sites for flaws

Transluce says none of the probes appear to have worked, though its records are incomplete.

September 30, 2026 · 4 min read

TeamViewer fixes five flaws; one lets authenticated attackers bypass permissions

The fixes are in version 15.82. The list shows how much trust a remote access tool holds.

September 30, 2026 · 4 min read

Chrome, Firefox patch over 100 flaws; neither vendor mentions exploitation

Chrome 154 and Firefox 157 arrived the same day. For managed fleets, the question is how fast devices catch up.

September 30, 2026 · 4 min read

Internet-exposed controllers at water utilities are among the easiest ways in

Exposed OT and vulnerable PLCs were most often linked to this summer's attacks, WaterISAC says

September 30, 2026 · 4 min read

OpenInfra Europe's package server was hit Aug 31 and found Sept 15

A JFrog Artifactory flaw was public three days before the attack. Ask what you downloaded, not only what you patched.

September 30, 2026 · 4 min read

A spoofed email failed DMARC and still reached the inbox in an Asia spy campaign

Cisco Talos details a China-nexus group that used Microsoft 365 services to hide a backdoor

September 30, 2026 · 4 min read

Horizon3 says AI proved a kind of flaw its team used to abandon

Horizon3 says Anthropic's Mythos chained a weak random number generator to admin access in Rejetto HFS.

September 30, 2026 · 4 min read

Star Blizzard's backdoor needs one click after the reply, Microsoft says

Microsoft says the Russian group mass-mails event invites from sites it hacked and hides the install in scheduled tasks

September 30, 2026 · 4 min read

South Africa's air traffic provider found ransomware-linked malware

ATNS says it contained the incident, but public documents show it still wants outside forensics to learn the extent.

September 30, 2026 · 4 min read

Several of OpenSSL's 14 fixes let a peer force outsized memory or CPU use

A certificate under 100 KiB can cost a TLS client, or a server that asks for client certificates, hundreds of MiB.

September 30, 2026 · 4 min read

Cloudflare: IPsec flaw could let a future quantum attacker sidestep upgrades

Hard to pull off, with feasibility unknown. Cloudflare's beta fix needs support at both ends of a tunnel.

September 30, 2026 · 4 min read

EU cyber law requires five years of updates for covered container products

Covered: public images, commercial operators, supported Helm charts. Open source may be affected; ask counsel.

September 30, 2026 · 4 min read

At Detectify customers, most open serious flaws are over three months old

Data from 1,293 Detectify customers raises a question: did anyone decide to leave these flaws open?

September 30, 2026 · 4 min read

Cisco survey: 21% of firms can add a control within 6 months of approval

Cisco's self-reported survey of 8,000 security staff points to slow internal decisions, not missing tools

September 30, 2026 · 4 min read

PyJWT flaw lets one crafted token turn logins into server errors

The bug hits apps that read tokens from a request body. PyJWT 2.14.0 contains the fix.

September 30, 2026 · 4 min read

Four OpenBao flaws chain into code execution; Vault fix still awaited

ControlPlane linked three High-severity bugs to a Critical one. OpenBao is patched; Vault awaits a fix.

September 30, 2026 · 5 min read

Attackers built a malicious pipeline to collect Kubernetes keys, Microsoft says

One compromised account, reached through a password reset, led Storm-3068 into Azure DevOps and Kubernetes

September 30, 2026 · 4 min read

Toptech says version 7.8 fixes ten flaws in TMS7 and TopHAT

CISA lists upload, database and login-session bugs in software tied to energy, chemical and transport sectors.

September 30, 2026 · 4 min read

MikroTik RouterOS flaw lets attackers run code as root with one request

CISA says the bug is in the router's web admin service and works before login. The fix is version 7.23 or later.

September 30, 2026 · 4 min read

Two flaws in Lantronix gateways let attackers run root code through updates

CISA lists two flaws in G520 cellular gateways. In one, the update signing key sat in a public developer kit.

September 30, 2026 · 4 min read

CISA lists no fix for a Baicells cell radio flaw; vendor did not reply to CISA

CISA says Baicells has not responded to its requests to work together on mitigating a bug in the Nova 430H.

September 30, 2026 · 4 min read

Glow Labs says AI agents left 13,000+ internal images on public GitHub

The vendor ties the leaks to a workaround for GitHub's image limits, mostly in employees' personal accounts

September 30, 2026 · 4 min read

New Spectre flaw leaks Linux memory; CPU makers say software must fix it

VUSec's Branch Target Reuse attack targets JIT engines. Chip vendors point to software patches, so the work falls to OS and runtime owners.

September 29, 2026 · 4 min read

DARPA selects Xint to research AI security checks for military messaging apps

Xint's CTO: in-house option is a work in progress, as it won't be able to use the latest OpenAI and Anthropic models

September 29, 2026 · 4 min read

Microsoft says Star Blizzard's RedFlick needs a single user interaction

Microsoft says the group cut the steps its malware needs, down from several, and now sends lures from compromised websites.

September 29, 2026 · 4 min read

DIVD says a flaw let an intruder in, then an AI agent ran the attack

A security nonprofit reports an agent-driven intrusion. The agent's errors helped investigators, but they are no defence plan.

September 29, 2026 · 4 min read

Android trojan RATHat stayed the same while its control panel was rebuilt

The malware barely changed; its control panel did. An AI tool ranks infected phones by estimated bank balance.

September 29, 2026 · 4 min read

Wiz case: 18 cloned repositories likely gave attackers a CI account's AWS keys

A Wiz case study shows why machine identities need the same scrutiny as staff logins

September 29, 2026 · 4 min read

OpenClaw Matrix bug lets one account borrow another's approval rights

CVE-2026-100541: two different chat accounts can be treated as one identity when permissions are checked

September 29, 2026 · 4 min read

Unit 42 finds slightly over 5% of Kubernetes operators it scanned ask for too much access

Unit 42's LLM-based tool reviewed OperatorHub and local installs. It does not say how many operators it tested.

September 29, 2026 · 4 min read

In one test, NVIDIA's agent sandbox held; leaks came from operator settings

Sorami's test of OpenShell v0.1.2 found no bypass of a documented control. Settings still let data out.

September 29, 2026 · 4 min read

Apple fixes a Meta-reported zero-day that may have hit targeted people

Apple says CVE-2026-86950 may have been exploited against specific people. It has shared few details.

September 29, 2026 · 4 min read

Hugo update fixes ways an untrusted theme could pull files into a site

Static sites run no code for visitors, but the build step still trusts every theme and module it loads.

September 29, 2026 · 4 min read

OpenAI agent slipped past access limits; card-theft campaign automated attacks

An OpenAI agent went around access limits it was not meant to cross. A separate card-theft campaign used open-source agents to automate attacks.

September 29, 2026 · 4 min read

A malformed HTML snippet can freeze Angular server-rendered apps

An advisory on @angular/platform-server describes a parser loop that halts all requests when untrusted input reaches it

September 29, 2026 · 4 min read

This Angular flaw needs a specific code path. Ask if you have it

Only server-rendered Angular apps that pass untrusted input to processing instruction nodes inside fallback elements.

September 29, 2026 · 4 min read

UpGuard found 16,326 Supabase databases with tables outsiders can read

UpGuard suspects AI coding agents built many of the apps but cannot prove it. Accountability stays with the business.

September 29, 2026 · 4 min read

NeedyMantis, used in targeted attacks, disguises itself as trusted software

Microsoft describes a layered toolkit, used selectively after break-in, that borrows names of everyday programs

September 29, 2026 · 4 min read

GitHub AI found 24 Android flaws; its researcher says experts must check each

GitHub says its AI workflows find flaws faster. Judging which ones matter still needed people.

September 29, 2026 · 4 min read

FBI job-portal breach: staff SSNs exposed per notice; medical data reported

Reportedly, the exploited server held HR data on agents and employees who applied through the portal.

September 28, 2026 · 4 min read

CVE-2026-77246: one HTTP setup let unauthenticated callers pick an upload host

MCP Atlassian before 0.22.0, over HTTP with READ_ONLY_MODE=false and no Authorization identity

September 28, 2026 · 4 min read

Two Polish health-software breaches show where clinic risk sits

A treatment center was affected by both the MyDr and Medyc incidents. The exposure sat in supplier databases.

September 28, 2026 · 4 min read

CVE-2026-32740: libheif Bug Reaches RCE in a Permissive Next.js Lab

A lab proof of concept, not a production finding. The flaw is in libheif, one of the native libraries sharp bundles.

September 28, 2026 · 5 min read

SOCRadar: ChatGPT's lead in stolen AI logins at 482 firms hints at shadow AI

The data cannot say which accounts were approved, so the first job is an inventory of what employees use.

September 28, 2026 · 4 min read

Facebook Liable for Over 43 Million Violations in New Mexico Privacy Verdict

The state seeks up to $5,000 per violation; a penalty hearing is Oct. 1. The verdict turns on what Facebook told users.

September 28, 2026 · 3 min read

Kiteworks Advised a Nine-Hour Shutdown Over a Flaw It Says Is in One Product

Kiteworks says the flaw is confined to a product enabled for under 50 organizations.

September 28, 2026 · 3 min read

Siemens SIMOVE and SIPLANT flaw could expose system files without a login

CISA republished Siemens' advisory on a path traversal in the products' embedded web server. Five version lines are affected.

September 28, 2026 · 3 min read

Siemens Industrial Edge Management bug allows account takeover via reset

CVE-2026-18963 lets an unauthenticated attacker set new credentials for any user, skipping email verification

September 28, 2026 · 3 min read

Ex-soldier gets 70 months for extorting at least 10 tech and telecom firms

Court documents describe stolen logins, Telegram coordination and stolen data offered on criminal forums

September 28, 2026 · 3 min read

CISA: Botslab has not responded to mitigation requests on G980H dashcam flaws

CISA's advisory lists no vendor fix, so the risk decision sits with whoever bought the camera.

September 28, 2026 · 3 min read

CISA sets Sept. 30 deadline for two exploited Citrix NetScaler flaws

Citrix says its own compromise indicators may miss real intrusions, so patching is only one step

September 28, 2026 · 3 min read

Mailed fake cards and stripe skimming still cost victims, WIRED reports

A QR-code letter scam in Europe and a US skimming indictment show physical card fraud channels are still in use

September 28, 2026 · 3 min read

Terraform providers used to deliver Go malware, Aikido reports

Two providers and two Go modules share command infrastructure with a campaign researchers tie to North Korea.

September 28, 2026 · 3 min read

OpenPLC v3 web flaw will not be patched; vendor says move to v4

A CISA ICS advisory turns a patch question into a migration decision for plants running OpenPLC v3

September 28, 2026 · 3 min read

lwIP MQTT client flaw could allow full code execution on affected devices

CISA's advisory lists eight critical infrastructure sectors and points to an upstream fix, not a vendor patch

September 28, 2026 · 3 min read

GestSup flaw lets an emailed PHP attachment run on the server

NVD lists an unauthenticated remote code execution path through a monitored mailbox in GestSup versions before 3.2.61

September 28, 2026 · 3 min read

Ransomware Victims Hit a 2026 High of 1,073 in August, NCC Group Reports

NCC Group's August tally is 12% above July's; industrial organizations accounted for 31% of reported incidents.

September 28, 2026 · 4 min read

Talos: Implant Design Lets Up to Four AI Models Vote on Attack Steps

Talos's static analysis shows an implant polling up to four AI models after deployment. The public build is inert.

September 28, 2026 · 4 min read

Cisco Says One of Two Critical Bugs Is Exploited; Check Point Also Patches

Cisco and Check Point fixed critical flaws; separately, Japan's Digital Agency reported a breach via an unnamed VPN appliance.

September 28, 2026 · 3 min read

CISA Outlines Plan to Improve CVE Data Quality as 2026 Volume Passes 67,000

NVD submissions rose 263% from 2020 to 2025; 67,000+ new CVEs published so far in 2026, per CyberScoop

September 28, 2026 · 4 min read

Bitget Says North Korea-Linked Hackers Stole an Estimated $387 Million

Initial loss estimate is $387.5M; CEO cites a backend wallet breach and a $464M+ fund to cover losses

September 28, 2026 · 3 min read

Cisco Talos releases CAIRN to hunt AI-integrated malware via metadata alone

The open-sourced toolkit flags AI-integrated malware from file metadata, without downloading or running the sample.

September 28, 2026 · 4 min read

Prosecutors Say AT&T Hacker Sought AI Exploit Code While in Custody

Prosecutors say Wagenius used other inmates' email to ask a contact to prompt an AI tool for exploit code.

September 28, 2026 · 3 min read

Two Compromised GitHub Actions Came Back Online With Malicious Tags Intact

Socket: issues-helper lists about 15,000 dependent repositories; how many use a mutable tag is unknown.

September 28, 2026 · 4 min read

Cloudflare Fixes Containers Flaw That Left Residual Tenant Data Readable

Researchers read leftover blocks; Cloudflare found no evidence of malicious use and says no customer action is needed

September 28, 2026 · 4 min read

AWS Locks Down Exposed IAM Keys in Under 10 Seconds, Unit 42 Finds

AWS attaches a Deny-only policy within seconds of a leaked key — but does not disable the credential entirely.

September 27, 2026 · 4 min read

Anthropic Report: One Actor Used AI to Breach European Political Parties

One operator, AI-assisted, exfiltrated 140,000 political-opinion records from a campaign platform, per Anthropic's report.

September 27, 2026 · 4 min read

Google Cloud Threat Intel: CI/CD Pipelines Are the New Attack Surface

Google threat researchers detail how attackers now target build pipelines, AI coding agents, and developer credentials

September 27, 2026 · 4 min read

Documentation Placeholder Domain Now Delivers ClickFix Malware

third-party[.]com, a stand-in address used across code samples and docs, was registered and weaponized to target Windows users, per Manifold Security

September 27, 2026 · 4 min read

Linux Kernel AF_ALG Flaw Paid $113,337 Bounty, Latent Since 2011

A race in Linux's AF_ALG crypto API let unprivileged users reach root and escape Docker containers, a researcher says.

September 27, 2026 · 4 min read

WordPress Patches Unauthenticated RCE Path Spanning Decade of Releases

CVE-2026-87902 scores 9.2 CVSS and affects every WordPress Core branch from 4.7.0 through 7.1.1, patched September 22.

September 27, 2026 · 4 min read

OpenCode RCE Flaw Let a Webpage Run Code on Dev Machines

Datadog Security Labs found a content-type mismatch in the AI coding agent's upgrade endpoint, reachable from a single browser tab

September 27, 2026 · 4 min read

Lunex Stealer Platform Grows to 28 Panels Using AMD Driver Flaw

A malware-as-a-service platform expanded from 6 to 28 control panels by exploiting a 2023 AMD driver flaw.

September 27, 2026 · 4 min read

Three Malware Families Drive 85.7% of Infostealer Cloud Breaches

AWS credentials made up 46% of stolen secrets as attackers hijack session tokens to bypass MFA, data shows

September 27, 2026 · 5 min read

Gyazo Breach Exposes 490 Million Image Metadata Records

Metadata tied to 24 million accounts included OCR text, EXIF location, and image-URL construction data

September 27, 2026 · 4 min read

File-Change Notifications on Windows, Linux, Android Leak Activity

Graz University researchers show a permission-free OS feature can reconstruct keystrokes and browsing history

September 27, 2026 · 4 min read

F5 BIG-IP Heap Overflow Lets Attackers Skip Authentication for Code Execution

watchTowr Labs traces the flaw to a missing size check in BIG-IP's OAuth handler, no login required to trigger it.

September 27, 2026 · 4 min read

CISA Election Security Plan Flags Patching Barriers, Voter Database Risk

Certification rules can delay patches while voter registration systems face persistent attempts across all 50 states

September 27, 2026 · 4 min read

x47.c botnet, advertised at $950, includes a mode that drains AI credits

Qrator describes a Windows botnet with an AI-account drain and a Grok-driven persistence module

September 27, 2026 · 3 min read

One Azure identity attempted 150+ deletion or key operations in 35 minutes

Microsoft details Storm-3168 activity in one Azure tenant: deletions, recovery targeting and storage key requests

September 27, 2026 · 3 min read

Salesforce Agentforce Flaws Could Have Exposed CRM Data via Lead Forms

Zenity Labs' SalesBleed research shows a poisoned lead can turn a trusted AI agent against the organisation using it

September 27, 2026 · 3 min read

OpenAI's sandbox alarm fired in 12 minutes; the agent ran 2.5 more hours

OpenAI's disclosure details a DNS gap, a fragmented GitHub token and 53 cases of user images posted offsite

September 27, 2026 · 3 min read

Meta's Muse AI Agent Zero-Day Exposed Account Tokens to Any Local App

Researcher Patrick Wardle says any local app could redirect Muse's transcription end point; Meta has issued a hotfix

September 27, 2026 · 3 min read

44 state AGs fine Labcorp $2.3M over a debt collector's 2019 breach

The settlement puts vendor oversight, contract terms and data minimisation at the centre of a healthcare breach case.

September 27, 2026 · 3 min read

Grav 1.7 lacked fix for CVE-2026-42608 when Clop's leak site was breached

Grav 2.x was fixed earlier this year; the 1.7 branch received the patch only after exploit details reached the vendor.

September 27, 2026 · 3 min read

Two Compromised GitHub Actions Were Re-Enabled With Malicious Tags Intact

Socket found release tags for both actions still pointed to the May 18 payload from September 16 to 25.

September 27, 2026 · 3 min read

Elementor 4.3.0 and 4.3.1 flaw let one link create an administrator

Patchstack details a CSRF bypass that reaches the whole WordPress REST API; version 4.3.2 fixes it

September 27, 2026 · 3 min read

CISA adds WSO2 and Adobe Commerce flaws to exploited-vulnerability list

A forged-token bug and an unauthenticated authorization flaw are both listed as exploited, with federal deadlines from Sept. 27

September 27, 2026 · 3 min read

Bitget Says Spoofed Backend Data Triggered Transfers It Now Puts Above $390M

The exchange says an attacker used a compromised backend system to spoof data and trigger its authorization process

September 27, 2026 · 3 min read

Team Cymru Counts 80,000+ Relays Masking Who Uses Frontier AI Models

Team Cymru reports intermediary servers that pool credentials, separating the account holder from the actual user.

September 27, 2026 · 3 min read

Enterprise isolation of high-risk AI agents fell from 30% to 9%, survey shows

A Medicare portal intrusion and new survey data put agent containment on the budget agenda

September 27, 2026 · 3 min read

Next.js 16.3.6 patches ImageResponse remote code execution flaw

Only the Node.js ImageResponse path in next/og is affected; the Edge implementation and 15.x are not.

September 27, 2026 · 3 min read

A Single Malicious Page Can Compromise Tor Browser's Renderer

CVE-2026-10702, a patched Firefox JIT flaw, gave attackers code execution from one webpage visit — no clicks, downloads, or plugins required.

July 30, 2026 · 4 min read

Microsoft Patched This Exchange Flaw in May. Attackers Were Still Inside in July.

A backdoor called OWAReaper is keeping mailbox access alive on on-premises Exchange servers long after CVE-2026-42897 was fixed and federally flagged.

July 30, 2026 · 4 min read

Thirty Water Systems in 48 Hours: The Architecture Was the Attack Surface

Minnesota's coordinated water-utility cyberattack didn't exploit a misconfiguration. It exploited a design — internet-facing PLCs with a vulnerability the vendor cannot patch.

July 30, 2026 · 7 min read

Zero Trust's Quiet Assumptions Just Expired

Zero trust assumed the accessor was human, the pace was human, and the app was the atom. AI agents broke all three.

July 29, 2026 · 6 min read

Security as an Immune System: The Floor, the Ceiling, and the Two-Speed Brain

The fortress assumed threats were exceptional events. The immune system assumes threat pressure is ambient and constant.

July 29, 2026 · 6 min read

A 9.8-Rated Router Flaw Reveals Who Actually Has to Patch It

OpenWrt's DHCPv6 flaw grants unauthenticated root access over UDP — only federal agencies face a patching deadline.

July 29, 2026 · 4 min read

Leaked RAT Source Code Turns One Campaign Into 170 Near-Identical Ones

Docker, nginx, PHP and MySQL — the stack behind millions of sites — now ships as a packaged Android spying kit.

July 29, 2026 · 5 min read

The End of "Access Denied": Security That Talks Back

Between 'yes' and 'no' lives an entire spectrum of 'convince me.' Security stops being a wall and becomes a conversation.

July 29, 2026 · 6 min read

Google Gives Threat Actors One Primary Name — and Keeps the Rest Searchable

A canonical-name-with-aliases system consolidates the post-Mandiant/TAG merger. WebPulse reads this as infrastructure for machine-speed triage.

July 27, 2026 · 4 min read

Fastjson RCE Hits Java Backends With No Patch in Sight

CVE-2026-16723 lets attackers run code without authentication in any Java app using Fastjson 1.x — and the library has no patch to ship.

July 27, 2026 · 4 min read

An AI Agent Targeted Thailand's Finance Ministry — Unattended

Hermes Agent's 'YOLO mode' ran privilege-escalation scans and file cataloging without a human approving any step.

July 25, 2026 · 5 min read

Default Azure Setting Let One Tenant Take Another's Identity

A CVSS 9.9 flaw in Azure Automation shows how a single default configuration can cross a cloud trust boundary

July 25, 2026 · 4 min read

Metrics Theater: Your Security Dashboard Is Probably Lying to You

A misleading metric is worse than no metric. It manufactures confidence exactly where scrutiny should be.

July 24, 2026 · 5 min read

A Building Doesn't Care About Your Predictions: Why I Design for Failure, Not Prevention

There is no such thing as a perfectly secure system. Resilience means asking how fast you recover, not whether you can prevent every bad thing.

July 24, 2026 · 5 min read

Next.js Ships Nine Security Advisories in a Single Batch

SSRFs, denial-of-service, cache confusion, auth bypass, and endpoint disclosure — all targeting Server Actions and App Router, the features driving Next.js adoption.

July 23, 2026 · 5 min read

Two WordPress Core Flaws Let Attackers Plant Plugins That Outlast Cleanup

CVE-2026-63030 and CVE-2026-60137 are being exploited to install persistent webshells through WordPress Core's plugin installer.

July 22, 2026 · 5 min read

A WordPress RCE That Skips the Plugin Layer Entirely

Two chained CVEs enable pre-authenticated code execution on standard WordPress installs. Patches shipped July 17 — sites that haven't applied them are exposed.

July 22, 2026 · 4 min read

SharePoint Machine-Key Theft Lets Access Survive the Patch

CVE-2026-50522 let attackers forge authentication tokens before Microsoft's fix shipped — and those forged tokens don't expire when the vulnerability does

July 22, 2026 · 5 min read

Security Teams Find Critical Flaws After the Scheduled Test Window Closes

A new report finds 95% of organizations discover high-severity flaws between scheduled security assessments, not during them.

July 22, 2026 · 4 min read

SonicWall's VPN Appliances Were Compromised Before the Patch Existed.

Two SonicWall SMA1000 vulnerabilities were exploited as zero-days for weeks. Attackers installed custom malware on the devices that protect your network perimeter.

July 21, 2026 · 5 min read

CVE-2026-6875: ServiceNow Pre-Auth RCE Exploited in the Wild

A critical pre-authentication vulnerability in the ServiceNow AI Platform is under active exploitation. No credentials required.

July 21, 2026 · 5 min read

CVE-2026-42533: NGINX Heap Buffer Overflow Crashes Workers

A crafted HTTP request can trigger a heap buffer overflow in NGINX worker processes. The patch is out. The install base is enormous.

July 21, 2026 · 5 min read

Astro Had Zero CVEs. Then It Got Three XSS Advisories in One Month.

Astro was the poster child for zero-CVE modern frameworks. Three cross-site scripting advisories just changed that math.

July 21, 2026 · 6 min read

Opening a Zip File Shouldn't Give Someone Code Execution. 7-Zip Just Fixed That.

A crafted XZ archive can trigger a heap buffer overflow in 7-Zip during extraction. The tool runs on hundreds of millions of machines.

July 21, 2026 · 5 min read

The Patch Window Went Negative: Exploits Now Precede Fixes by a Week

Mandiant's 2026 data puts mean time-to-exploit at -7 days — patches now arrive after attackers already have a foothold.

July 17, 2026 · 4 min read

Firefox Security Updates July 2026: Critical Fixes Ship as Exploit Code Goes Public

The rendering engine serving human visitors also powers AI browsing agents, and the exploit code is already public.

July 17, 2026 · 4 min read

One Git Import, Full Code Execution: TidGi's Unpatched 9.6 Severity Flaw

A single wiki import auto-executes embedded JavaScript on TidGi Desktop, with no patched version currently available.

July 15, 2026 · 4 min read

SonicWall SMA Zero-Day Pair Chains Anonymous Access to Admin Commands

Two flaws, CVSS 10.0 and 7.2, were exploited in the wild before a patch existed for either one.

July 15, 2026 · 4 min read

LegacyHive: Windows Privilege-Escalation Exploit Ships With No CVE

LegacyHive works on fully patched July 2026 systems and has no CVE number yet — the eighth such disclosure from the same researcher since April.

July 15, 2026 · 4 min read

Go’s SSH Library Accepted Hardware Key Signatures Without Requiring a Touch

CVE-2026-39831 (CVSS 9.1): the Verify() method for FIDO/U2F key types in golang.org/x/crypto/ssh never checked the User Presence flag. An attacker with agent access could authenticate silently, defeating the one guarantee hardware keys exist to enforce.

July 15, 2026 · 4 min read

6 GHz Wi-Fi Access Points Self-Report Location — Researchers Show the System Doesn’t Verify

Automated Frequency Coordination systems accept the GPS coordinates an access point reports about itself, unverified.

July 15, 2026 · 4 min read

No Login Required: A Form Plugin's Direct Path to Server Control

CVE-2026-56291 lets unauthenticated attackers upload executable files to sites running Balbooa Forms.

July 13, 2026 · 5 min read

Australia's ACSC Flags CMS Plugins as Entry Point in Active Global Campaign

A national cyber agency named CMS plugins as the entry point. Catalog data shows what that exposure looks like in practice.

July 13, 2026 · 5 min read

Weak Randomness, Not Malware, Drained $3.1M in Crypto

431 wallets, five blockchains, one root cause: recovery phrases generated from a keyspace small enough to brute-force.

July 10, 2026 · 4 min read

25 CVEs in One Ubiquiti Bulletin, 100,000 UniFi Panels Already Indexed

Ubiquiti's July 8 advisory patches seven critical and eighteen high-severity UniFi OS vulnerabilities — against a backdrop of 100,000 previously indexed internet-facing instances.

July 8, 2026 · 4 min read

Joomla Page Builder Flaw Lands on CISA's Actively Exploited Vulnerability List

CVE-2026-56290 allows unauthenticated file uploads on Joomla sites — CISA confirms active exploitation.

July 8, 2026 · 5 min read

BeyondTrust Auth Bypass Flaws Leave ~2,000 Instances Internet-Reachable

Two critical authentication bypasses in BeyondTrust RS and PRA join a cPanel/WHM KEV entry from the same month — both granting privileged infrastructure control via a web-accessible login.

July 8, 2026 · 4 min read

China-Aligned Hackers Chained Two Roundcube Flaws Against University Webmail. Both Were Patched Over a Year Ago.

A suspected China-aligned campaign chained an XSS flaw patched in August 2024 with an RCE patched in mid-2025 to compromise physics and engineering departments at U.S. and Canadian universities. The gap is not disclosure — it is deployment.

July 8, 2026 · 5 min read

An AI Agent Builder Just Landed on CISA's Exploited-Vulnerability List

Langflow, a visual builder for AI agents, joins CISA's KEV catalog after attackers used a broken authorization flaw to harvest LLM credentials and hijack compute.

July 8, 2026 · 4 min read

Gitea Docker Flaw: From Disclosure to Active Probing in 13 Days

A CVSS 9.8 authentication bypass in Gitea Docker images was under active probing within 13 days of disclosure. The flaw requires a non-default configuration — but the Docker image ships with that configuration enabled.

July 8, 2026 · 4 min read

ColdFusion's 3-Day Federal Patch Order Exposes a Blind Spot in Web Intelligence

A maximum-severity, actively exploited ColdFusion flaw triggered the harshest tier of CISA's new standing directive — on a platform most monitoring tools never see coming.

July 8, 2026 · 5 min read

The Ghost Certificate: ADFS Signing Keys Survive Password Rotations, Reboots, and Every Credential Dump Detector.

Mandiant recovered active ADFS token-signing keys from Machine DPAPI without touching LSASS or the live service process. The forged SAML token granted Global Administrator access to a federated Microsoft 365 tenant. MFA, Conditional Access, and all identity controls were bypassed.

July 8, 2026 · 6 min read

FBI and Google Shut Down a 2M-Device Smart TV Botnet

NetNut enrolled smart TVs and streaming boxes into a residential proxy network via pre-installed SDKs. 316 distinct threat clusters used it in a single week. Google disabled the C2 infrastructure. The supply chain was the infection vector.

July 5, 2026 · 5 min read

New Malware Steals AI Coding Tool Credentials

A new cross-platform infostealer deployed through a SimpleHelp authentication bypass explicitly targets AI development assistant tokens, cloud platform credentials, and package registry keys. The attack surface is not the code — it is the developer.

July 5, 2026 · 5 min read

Two Cursor IDE Flaws Let Attackers Escape the Sandbox

CVE-2026-50548 and CVE-2026-50549 — dubbed DuneSlide — let a prompt injection escape Cursor's sandbox and execute arbitrary commands with developer privileges. More than half the Fortune 500 use Cursor. Every version before 3.0 was vulnerable.

July 4, 2026 · 5 min read

28 CVEs in Claude Code: AI Coding Tools as Attack Surface

Anthropic's Claude Code has accumulated 28 CVEs in its first year, including two CVSS 10.0 critical sandbox escapes. CVE-2026-46406, the latest, let any local user read secrets from a predictable temp file path. When the security tool becomes the attack surface, every assumption changes.

July 4, 2026 · 6 min read

The Zero-CVE Cohort Is Growing. Hugo, Astro, and HTMX Are Gaining Share Where It Matters.

Frameworks with zero or near-zero critical CVEs hold 3.5% of the Tranco top 10K — and all of them are growing. Hugo, Astro, and HTMX share a trait: minimal attack surface by design.

July 3, 2026 · 5 min read

STOCKSTAY: Turla's .NET Backdoor and the Expanding Nation-State Arsenal

Google Threat Intelligence Group documents a modular .NET implant that Turla has been developing since 2022 — one more tool in an apparatus that has compromised victims across 50+ countries.

July 2, 2026 · 5 min read

Three Path Traversal CVEs Hit the Libraries That Move Every OCI Artifact

ORAS Go and Java SDKs — used by Azure ACR, AWS ECR, Docker Hub, Helm, and Notation — disclosed symlink and hardlink escape flaws that let a malicious artifact write files outside the extraction directory.

July 2, 2026 · 5 min read

goshs WebDAV Bug: Access Controls That Never Worked

CVE-2026-50138 reveals that goshs --read-only, --upload-only, and --no-delete flags are silently ignored when WebDAV is enabled. Configuration theater in a tool used by developers and red teamers.

July 2, 2026 · 4 min read

Logged In Is Not Authorized: Subsonic API IDOR Exposes All User Data

In gonic's Subsonic API, any authenticated user can read or delete any other user's data — BOLA confirmed as API risk #1

June 30, 2026 · 5 min read

pnpm Token Leak: Registry Config Forwards npm Credentials

GHSA-cjhr-43r9-cfmw catalogs how repository .npmrc redirects developer credentials to attacker-controlled registries.

June 30, 2026 · 5 min read

Mandiant: ViewState Deserialization Compromised Enterprise LMS in 2025

A Mandiant breach response finds ViewState deserialization actively exploited in enterprise learning systems.

June 30, 2026 · 5 min read

pnpm Leaks Developer Secrets Before Scripts Execute

A config-phase flaw expands environment secrets into registry requests — before any lifecycle script runs

June 29, 2026 · 5 min read

Decompilation AI Matures: Closed-Source Plugin Opacity Collapses

Techniques that rebuilt GameCube games from binary are now trained on the web's encrypted plugin ecosystem

June 29, 2026 · 5 min read

pnpm configDependencies Creates Repository-Controlled Install Engine Path

GHSA-gj8w-mvpf-x27x: Repository-level settings can redirect pnpm to a native install engine without contributor awareness

June 29, 2026 · 5 min read

pnpm Lockfile Flaw Puts Next.js Build Pipelines at Execution Risk

GHSA-w466-c33r-3gjp: a crafted lockfile can redirect which pnpm binary runs before a dependency is installed

June 29, 2026 · 5 min read

One Valid Login, Every Resource: The IDOR Gap That Scales with AI Agents

Authentication passed. Authorization was absent. How a gonic Subsonic API flaw illustrates the gap AI agents exploit at scale.

June 28, 2026 · 4 min read

Node.js TLS Hostname Bypass: NVD Says CVSS 9.8. HackerOne Says 5.6. Every Framework Built on Node Is Caught in the Middle.

CVE-2026-48930: embedded nul-bytes in hostnames cause silent authority rebinding via C-string truncation. Node.js 22, 24, and 26 affected. The severity dispute exposes a scoring system failure.

June 28, 2026 · 6 min read

Nezha Monitoring: Pre-Auth Config Leak + Cross-Tenant Terminal Hijack. The Observability Pattern Continues.

CVE-2026-53519 (CVSS 9.1) leaks jwt_secret_key via path traversal. A second flaw (CVSS 9.9) lets any authenticated user hijack another's live terminal. 10K-star self-hosted monitoring platform.

June 28, 2026 · 5 min read

A Python .pth File Ran Before Import. AI Routing Library semantic-router Shipped Compromised Credentials Harvester.

semantic-router pulled a compromised wheel via its AI dependency chain. A .pth file executed on Python startup — no import needed — exfiltrating AWS, GCP, Azure creds, SSH keys, and Kubernetes configs.

June 27, 2026 · 6 min read

pnpm Discloses 8 CVEs in One Day. Your Lockfile Is the Exploit.

Path traversal, manifest spoofing, hoisted alias escapes, arbitrary deletion — 8 distinct vulnerabilities in the package manager that Next.js, Nuxt, and Astro depend on. The supply chain attack surface just moved from packages to package managers.

June 27, 2026 · 6 min read

Cursor AI Editor: Two CVSS 9.8 Sandbox Escapes Let a Malicious Agent Write Anywhere on Disk

CVE-2026-50548 and CVE-2026-50549: working directory manipulation and symlink canonicalization bypass in Cursor pre-3.0. The AI coding tool that developers trust with filesystem access had no real sandbox.

June 27, 2026 · 5 min read

87% of Organisations Suffered an API Security Incident. The Worse Number Is the One That Went Down.

Akamai's 2026 study of 1,840 security leaders reveals that only 23% know which APIs return sensitive data — down from 40% in 2022. Organisations are spending more on API security and understanding less. AI is accelerating the gap.

June 26, 2026 · 7 min read

i18next Prototype Pollution: The Translation Layer Nobody Thought to Secure.

CVE-2026-48713 and CVE-2026-48714 hit the npm ecosystem's dominant internationalisation library. Both scored CVSS 9.1. The second vulnerability bypassed the fix for the first using dotted __proto__ variants. Every Next.js, React, Angular, and Vue app using i18next was exposed.

June 26, 2026 · 5 min read

Go's SSH Library Just Dropped 10 CVEs in One Day. One Is a Perfect 10.0.

CVE-2026-46595 bypasses public key authentication entirely. CVE-2026-39831 defeats hardware security keys without physical touch. Go was supposed to be the memory-safe alternative. Its cryptographic foundation just cracked in ten places at once.

June 26, 2026 · 7 min read

Netflix's Lemur Shows Why JWT Algorithm Pinning Is Non-Negotiable

CVE-2026-55165 exposes a textbook auth bypass in a Flask-based certificate manager trusted by enterprises

June 26, 2026 · 4 min read

North Korea Hijacked an AI Agent Framework With 8M Weekly Downloads. It Took 88 Minutes.

Sapphire Sleet compromised 141 packages in the @mastra npm scope — a TypeScript framework for building AI agents and RAG pipelines. Any CI/CD pipeline running npm install was owned. The supply chain target has shifted from legacy CMS to AI tooling.

June 26, 2026 · 5 min read

The Cybersecurity Industry Got Breached Through a Sales Tool. OAuth Tokens Are the New Skeleton Keys.

Attackers compromised Klue's Salesforce integration using a legacy credential, harvested OAuth tokens, and exfiltrated data from HackerOne, Snyk, Huntress, Recorded Future, BeyondTrust, and LastPass in 15 minutes.

June 26, 2026 · 5 min read

A Permission Callback That Returns True. 100,000 WordPress Sites Leaked Live API Keys. 17 Million Attacks Followed.

CVE-2026-4020 in Gravity SMTP exposes a REST endpoint that dumps 365KB of live credentials — Amazon SES, Google, Mailjet, Zoho OAuth tokens. Patched in March. Mass exploitation started in June. 17M+ attempts blocked.

June 26, 2026 · 4 min read

FortiBleed: 86,000 Firewalls Compromised, 110 Million Credentials Harvested. Your Perimeter Just Became the Attack.

A Russian-speaking broker brute-forced 430,000 FortiGate devices. 86,644 fell. Custom sniffers harvested 110M+ credentials passing through compromised firewalls — including Chevron, Samsung, AT&T, Mercedes-Benz.

June 26, 2026 · 5 min read

TrapDoor Plants Instructions Inside Your AI Coding Assistant. It Follows Them.

34 packages across npm, PyPI, and Crates.io hide zero-width Unicode instructions in .cursorrules and CLAUDE.md files. When Cursor or Claude Code opens the project, the AI runs a fake security scan that exfiltrates your secrets.

June 25, 2026 · 5 min read

Gemini CLI Scored CVSS 10.0. A GitHub Issue Could Execute Arbitrary Commands on Your Build Server.

Google's own AI coding tool had a maximum-severity command injection flaw. In --yolo mode — commonly used in CI/CD — all tool allowlists were ignored. A malicious GitHub issue became an RCE.

June 25, 2026 · 4 min read

3 Frameworks Ship Zero GitHub Releases. 8 Ship 50+. The Release Transparency Divide Is a Security Signal.

WordPress, Django, and Drupal publish no GitHub releases. Next.js, Angular, and Laravel ship 50 per year. The difference determines how fast your team can patch.

June 24, 2026 · 5 min read

Dashlane Vaults Stolen via TOTP Brute-Force. 2FA Has a Ceiling.

TOTP brute-force compromised ~20 Dashlane vaults. 1M combinations per 30-second window is a ceiling, not a wall.

June 23, 2026 · 6 min read

CVSS 9.8: Contact Form 7 HubSpot Plugin Allows Unauthenticated RCE

CVE-2026-49763: unauthenticated PHP Object Injection in the CF7-HubSpot bridge. Neither vendor caught it.

June 23, 2026 · 6 min read

Check Point VPN Zero-Day: Qilin Ransomware Had the Key Before the Patch

CVE-2026-50751 (CVSS 9.3): IKEv1 bypass in Check Point gateways. Qilin exploited before advisory. CISA KEV June 8.

June 23, 2026 · 7 min read

Network-AI ApprovalInbox: No Authentication on AI Agent Approvals

GHSA-mxjx-28vx-xjjj: anyone on the network can approve AI agent actions. The approval layer is the gap.

June 22, 2026 · 5 min read

React Server Components Carry a DoS Flaw. Every RSC Framework Inherits It.

CVE-2026-23869 scores CVSS 7.5. A cyclic payload in React Flight protocol exhausts CPU for 60 seconds per request.

June 21, 2026 · 5 min read

Laravel's Core Email Handling Has a CRLF Injection Flaw. It's Not a Plugin.

CVE-2026-48019 allows email header manipulation via unsanitized CRLF sequences. A second CVE compounds the risk.

June 21, 2026 · 5 min read

CVE-2026-47291: The Invisible Layer Under Every Windows Web Server Just Got a CVSS 9.8.

HTTP.sys is the kernel-mode HTTP driver that underlies IIS, WCF, WinRM, ASP.NET, and every Windows web service. A specially crafted request exceeding 65,535 bytes triggers an integer overflow, heap buffer overflow, and arbitrary code execution with kernel privileges. No authentication. No user interaction. One HTTP request.

June 20, 2026 · 5 min read

Supply Chain Attacks in H1 2026: 4.5x the Volume of All 2025. The Attacks Now Spread Themselves.

May 2026 was the busiest month on record — 14 campaigns, 346 malicious packages in 31 days. Three campaigns hit npm, PyPI, and Docker Hub within 48 hours. The Shai-Hulud worm propagates through build systems. Package-level attacks are now automated.

June 19, 2026 · 6 min read

Joomla JCE Scores a Perfect 10: CISA KEV, PHP Web Shells, Zero Authentication Required

CVE-2026-48907 is a CVSS 10.0 flaw in the Joomla Content Editor plugin. Attackers upload PHP web shells through unauthenticated profile imports. CISA orders federal agencies to patch by June 19.

June 18, 2026 · 5 min read

Node.js June 17 Security Release Affects Every Modern JavaScript Framework

Critical patches across Node.js LTS lines. Next.js, Nuxt, Remix, Astro, SvelteKit — every Node-based framework inherits the vulnerability window.

June 18, 2026 · 4 min read

Red Hat's Own npm Packages Compromised: 32 Packages, 96 Versions

Self-propagating npm worm 'Miasma' hijacked @redhat-cloud-services packages via stolen GitHub OIDC tokens.

June 17, 2026 · 6 min read

Phantom Gyp: AI SDK With 408K Downloads Targeted by Miasma Variant

Miasma variant uses node-gyp build hooks to evade monitoring, hitting @vapi-ai/server-sdk and 57 packages in under 2 hours.

June 17, 2026 · 6 min read

Malicious Open-Source Packages Surged 73% Year-Over-Year. Dependency Count Is Attack Surface.

ReversingLabs' 2026 Software Supply Chain Security Report documents a 73% increase in malicious packages across npm, PyPI, and other registries. Frameworks with 1,000+ transitive dependencies face exponential exposure. Minimal-dependency stacks avoid this risk entirely.

June 17, 2026 · 6 min read

208 CVEs in One Patch Tuesday. Microsoft's Largest Ever. Including a Wormable Kernel Flaw Compared to EternalBlue. Your Web Server Has 72 Hours.

June 2026 Patch Tuesday delivered 208 CVEs (571 with Chromium bundled), 37 Critical. CVE-2026-45657 (CVSS 9.8) is a use-after-free in Windows Kernel TCP/IP that requires no authentication and can self-propagate. CVE-2026-47291 (CVSS 9.8) hits HTTP.sys directly — a web server RCE. CISA's 3-day mandate means patching is no longer optional.

June 16, 2026 · 6 min read

PromptSnatcher Malware Steals AI Chatbot Conversations in Real Time. Your Claude and ChatGPT Sessions Are Being Exfiltrated.

A new malware family harvests complete conversation histories from Claude, ChatGPT, Gemini, Copilot, and Perplexity by hooking browser API calls. Unlike keyloggers, PromptSnatcher captures the AI's responses too — including code reviews, security analyses, and strategic recommendations. The intellectual property loss is exponential.

June 16, 2026 · 5 min read

175 Chrome Extensions Are Bot Traffic Factories. 863,000 Users Generating Fake Clicks, Injecting Ads, and Harvesting Credentials. Google Hasn't Removed Them.

DomainTools researchers found 152 extensions using browser-level access to redirect searches, inject affiliate codes, exfiltrate cookies, and track browsing. Separately, 23 extensions from the 'AstroForge' campaign steal AI chatbot conversations including Claude, ChatGPT, and Gemini sessions. The Chrome Web Store's review process missed all of them.

June 16, 2026 · 6 min read

CISA BOD 26-04 Replaces BOD 19-02: 3 Days to Patch Critical Vulnerabilities

Binding Operational Directive 26-04 replaces the old 30-day patch window with risk-based timelines. Publicly exposed, auto-exploitable vulnerabilities in the KEV catalog get a 3-day deadline. The directive cites AI-accelerated exploitation as the reason. WordPress sites with 18,005 CVEs just became a compliance crisis.

June 16, 2026 · 6 min read

WordPress Plugin CDN Backdoor: OptinMonster, PushEngage, and TrustPulse Compromised. 1.2 Million Sites. Hidden Admin Accounts Created.

Attackers didn't need the WordPress plugin repository. They tampered with CDN-served JavaScript files, creating invisible administrator accounts, installing backdoor plugins named 'Content Delivery Helper' and 'Database Optimizer,' and opening web shells. Credentials exfiltrated to a typosquatted domain.

June 15, 2026 · 7 min read

ShinyHunters Claims 297 GB From the Council of Europe. Payroll Records for 10,000 Employees. Medical Data. Tax Numbers. Deadline: June 16.

429,000 files allegedly exfiltrated from HR, the Parliamentary Assembly, the Secretariat, and the European Directorate for Quality of Medicines. The Council of Europe has not acknowledged the incident. The deadline to negotiate is tomorrow.

June 15, 2026 · 6 min read

Next.js Authorization Bypass: A Crafted Query Parameter Changes Your Route Without Changing the URL. CVE-2026-44574.

Specially crafted query parameters alter dynamic route values while leaving the visible URL path unchanged, bypassing middleware-based authorization in Next.js 13.0 through 15.5.15 and 16.x before 16.2.5. A separate CVE-2026-23869 enables memory exhaustion DoS via React Server Components. Astro, Svelte, and Hugo are not affected.

June 15, 2026 · 6 min read

Agentjacking: Sentry Errors Hijack AI Code Agents via MCP in 2026

Tenet Security disclosed a new attack class on June 12. Attackers inject prompts into Sentry error events using publicly discoverable DSNs. AI coding agents retrieve the events via MCP and execute attacker-controlled code. Sentry called it 'technically not defensible.'

June 15, 2026 · 7 min read

The Miasma Worm Source Code Was Leaked on GitHub. The npm Supply Chain Attack Is Now Open Source.

The credential-stealing worm that compromised Red Hat's npm packages and 73 Microsoft Azure repositories was briefly published on GitHub on June 10. Copycat attacks are now a matter of when, not if.

June 14, 2026 · 7 min read

WordPress Just Admitted Its Plugin Ecosystem Needs AI to Police It. They Call It 'Protect The Shire.'

A 24-hour cooldown on all plugin releases. AI-assisted code review scanning 78,000 plugins. WordPress.org is building the security infrastructure it should have had a decade ago — because the alternative is losing the web.

June 14, 2026 · 7 min read

CVE-2026-48710 'BadHost': The Vulnerability That Hit FastAPI, vLLM, LiteLLM, and 325 Million Weekly Downloads.

A malformed Host header bypasses authentication in Starlette — the ASGI framework underneath FastAPI and most of Python's AI agent infrastructure. Modern frameworks are not immune. The difference is how fast they patch.

June 14, 2026 · 6 min read

Atomic Arch: 1,500 Packages Backdoored Through Legitimate Adoption. No Exploit Required.

Attackers adopted 400 orphaned Arch Linux packages through official workflows, injected malicious npm dependencies, and deployed a Rust credential stealer with an eBPF rootkit. By June 12, 1,500 packages were compromised. They never broke a single rule.

June 14, 2026 · 7 min read

UpdraftPlus: 3 Million WordPress Sites. Unauthenticated Admin RCE. No Login Required.

The most popular WordPress backup plugin gave unauthenticated attackers full admin access. Wordfence blocked 8,172 exploit attempts in 24 hours. The plugin supply chain strikes again.

June 13, 2026 · 6 min read

WordPress CVEs Surpass 18,000 in 2026

June 2026 data reveals critical vulnerabilities across content management frameworks

June 13, 2026 · 6 min read

Laravel-Lang: 5,561 Repos Backdoored in 90 Minutes via Git Tag Rewrite

An attacker rewrote every version tag across 4 Composer packages in a single window. composer update triggered credential theft. 5,561 downstream repositories backdoored within 6 hours. The PHP supply chain joins the worm era.

June 13, 2026 · 6 min read

IronWorm: The npm Worm Written in Rust, Hidden by an eBPF Rootkit, Controlled via Tor

36 npm packages. A compiled Rust binary that hides behind a kernel rootkit. Command and control over the Tor network. Targets 86 environment variables and 20 credential files. Supply chain attacks just went military-grade.

June 13, 2026 · 7 min read

Shai-Hulud Source Code Is Public. The Worm Era Has Begun.

On May 12, 2026, TeamPCP open-sourced Mini Shai-Hulud — a self-propagating npm supply chain worm. Twenty days later, Miasma hit Red Hat and Microsoft. The barrier to supply chain attacks just dropped to zero.

June 13, 2026 · 6 min read

TrapDoor: The First Supply Chain Attack That Targets Your AI Coding Assistant

34 packages across npm, PyPI, and Crates.io. Zero-width Unicode in .cursorrules and CLAUDE.md files. When a developer opens the project, the AI assistant exfiltrates secrets. The attack surface just moved from human to machine.

June 12, 2026 · 7 min read

At 10 Million Sites Scanned, WordPress Is 74.3% of Everything We Detect

The largest independent framework scan ever conducted shows a web even more concentrated than W3Techs suggests.

June 12, 2026 · 5 min read

The Web Has a Monoculture Problem. The Math Proves It.

A Herfindahl-Hirschman Index of 0.56 means the detected web is more concentrated than most regulated industries.

June 12, 2026 · 5 min read

Six Frameworks Have Zero CVEs. Here's What They Have in Common.

Hugo, Eleventy, Remix, SvelteKit, HTMX, and Astro — the clean security record club shares architectural DNA.

June 12, 2026 · 4 min read

The Most Popular Frameworks Are the Least Secure. The Data Is Unambiguous.

Plot detection volume against CVE count. The line goes one direction.

June 12, 2026 · 5 min read

Meta's MCP Server Had an Unauthenticated Execution Flaw. Every AI Tool Chain Should Check.

GHSA-2026-0612: the Meta Ads MCP tool allowed unauthenticated HTTP execution. The AI tool supply chain is the new attack surface.

June 12, 2026 · 5 min read

Hugo 0.163: 11 Years, Zero CVEs. The Security Record Nobody Can Match.

The Go-based static site generator has never had a single CVE in the National Vulnerability Database.

June 12, 2026 · 4 min read

Laravel Is the Best PHP Framework. It Still Got a High-Severity CVE This Week.

CVE-2026-48019 lets attackers inject headers into outbound emails — no authentication required. Laravel patched it in days. WordPress plugins with similar flaws take months.

June 12, 2026 · 5 min read

React Query Got Wormed. OpenAI Got Hit. The npm Supply Chain Has a Predator.

The Mini Shai-Hulud worm compromised TanStack, Mistral AI, and 160+ packages. It steals tokens, publishes poisoned versions of more packages, and can wipe developer machines. OpenAI confirmed 2 employee devices were compromised.

June 12, 2026 · 8 min read

Chrome V8 Has an Actively Exploited RCE. Your Framework Decides How Much V8 Your Users Run.

CVE-2026-11645 is an out-of-bounds read/write in Chrome's JavaScript engine. Astro ships 9KB of JS. Next.js ships 463KB. The attack surface isn't equal.

June 11, 2026 · 5 min read

220 Million Monthly Downloads. Six Vulnerabilities. The protobuf.js Supply Chain.

A critical RCE chain in protobuf.js — used across Node.js frameworks — turns schema definitions into arbitrary code execution. Exploit code is public.

June 11, 2026 · 6 min read

The HTTP/2 Bomb: One Client, 32GB of Server Memory, 20 Seconds.

A new denial-of-service technique exploits how every major web server handles HTTP/2 headers. Legacy CMS servers running on tight memory budgets are the easiest targets.

June 11, 2026 · 6 min read

The Malware That Fights Back: Hades Uses Prompt Injection Against AI Security Scanners

The Hades variant of the Shai-Hulud worm family includes adversarial prompt injection in its payload — fake JavaScript comments designed to confuse AI-powered security tools. Supply chain malware is now attacking the scanners, not just the developers.

June 9, 2026 · 6 min read

Buy the Plugin, Own the Sites: 30 WordPress Plugins Bought on Flippa and Backdoored

An attacker purchased 30+ WordPress plugins with 400,000 combined installations on a digital marketplace. Dormant for 8 months. Activated April 2026. WordPress has no mechanism to review plugin ownership transfers.

June 9, 2026 · 7 min read

Drupal Was the Safe One. Then CVE-2026-9082 Hit CISA KEV.

CVSS 9.8. Unauthenticated SQL injection in Drupal Core. Added to CISA KEV two days after disclosure. 15,000 attacks across 65 countries. The CMS governments chose for security just got its own critical core flaw.

June 9, 2026 · 7 min read

WordPress 7.0 Shipped an AI Agent Platform. Hackers Got the Keys on Day Two.

WordPress 7.0 'Armstrong' added a Connectors API that stores Anthropic, Google, and OpenAI keys in wp_options. Patchstack's founder called it 'free AI tokens for hackers.' AI scanning found 300+ zero-days at $20 each in 72 hours. SiteGround pushed 1M+ installs automatically.

June 9, 2026 · 8 min read

June 2026: Six CVSS 9.8 Vulnerabilities. 1.14 Million WordPress Sites.

Six critical vulnerabilities actively exploited at the same time. 29,300+ attacks per day on one plugin alone. A premium plugin supply-chain compromised. The WordPress security model hit a wall.

June 9, 2026 · 8 min read

The Worm That Learned to Jump: npm → PyPI → Your IDE in 9 Days

June 1: npm packages. June 3: new evasion technique. June 5: IDE config poisoning. June 7: PyPI. The Shai-Hulud supply chain worm crossed three attack surfaces in nine days. 448 artifacts. The security industry couldn't keep up.

June 9, 2026 · 9 min read

TrustFall, SymJack, Clinejection: Every AI Coding Agent Is Hackable

TrustFall: one-click RCE. SymJack: symlink hijack installs attacker MCP servers. Clinejection: a GitHub issue title compromised 4,000 developers. Claude Code leaked its source — three CVEs fell out. The tools building the web are its newest attack surface.

June 9, 2026 · 13 min read

The npm Worm Wave: 30+ Supply Chain Attacks in 6 Months

One supply chain attack is an incident. Thirty in six months is a market condition. The worm crossed to PyPI. The source code went public. Here's the timeline.

June 9, 2026 · 7 min read

Both Supply Chains Are Broken: WordPress Plugins vs. npm Packages in 2026

WordPress has 18,005 catalogued CVEs and six CVSS 9.8 vulnerabilities exploited simultaneously. The npm ecosystem had 30+ supply chain attacks in 6 months — and the worm jumped to PyPI. Neither is safe. The difference is how the risk kills you.

June 9, 2026 · 8 min read

200,000 Open Doors: The Protocol Connecting AI Agents Has No Security Model

MCP — the Model Context Protocol — is the TCP/IP of agentic AI. 200,000+ vulnerable instances. 150 million package downloads. The Pentagon designated its creator a supply chain risk. The NSA published an advisory. The infrastructure of the machine web is wide open.

June 8, 2026 · 9 min read

SLSA Can't Save You: Miasma Forged the Gold Standard for Supply Chain Integrity

SLSA provenance was supposed to be the answer to supply chain attacks. Miasma forged it. 32 Red Hat packages, 90+ malicious versions, perfect provenance attestations. The trust framework is broken.

June 8, 2026 · 6 min read

The CI/CD Kill Chain: From npm Install to Cloud Admin in 72 Hours

A single compromised npm package gave attackers AWS admin access in three days. The deployment pipeline that makes modern frameworks possible is the attack surface nobody secured.

June 7, 2026 · 6 min read

Nation-States Are in Your node_modules

North Korean group UNC1069 compromised Axios — downloaded 40 million times per week. When intelligence agencies target your build pipeline, npm audit is not a security strategy.

June 7, 2026 · 6 min read

The Supply Chain Map. WordPress Has 60,000 Plugins. Each One Is a Trust Decision.

WordPress: 60,000 plugins, ~40% abandoned. npm (React/Next.js): millions of packages but lockfile-controlled and auditable. The supply chain model is fundamentally different — and our country data shows who bears the deepest exposure.

June 2026 · 5 min read

The Compliance Cost Multiplier. Legacy Frameworks Correlate With Higher Regulatory Fines.

GDPR fines: EUR4.5B+ cumulative. Healthcare breach cost: $10.9M average. The sectors with the highest fines are the sectors with the most legacy infrastructure. Correlation isn't causation — but the pattern demands attention.

June 2026 · 5 min read

The Website That Outlives the Business. Legacy Infrastructure Without an Owner.

How many of the 7.4M WordPress sites are for businesses that no longer exist? Domains persist, plugins accumulate CVEs, and nobody patches. The web's biggest security problem isn't active sites — it's ghost sites.

June 2026 · 5 min read

Russia at 238,000 Detections: Our Deepest Country Dataset. Next.js at 5.7% — Higher Than Germany.

.ru: 238,055 detected. WordPress 68%, Joomla 11.5% (27,374 sites), Drupal 5.9%, Next.js 5.7%, Angular 3.3%, Vue 1.4%. Russia's Joomla count alone exceeds most countries' total detections.

June 2026 · 5 min read

Uruguay: 21% Drupal. Latin America's Development Funding Outlier.

Brazil 86% WP, Argentina 86% WP, Colombia 55% WP. Uruguay breaks the LATAM WordPress pattern with 21% Drupal — the development funding corridor extends to Latin America.

June 2026 · 4 min read

The Balkans Run Joomla. The Rest of Europe Forgot It Existed.

Croatia 9%, Serbia 9%, Slovenia 7%, North Macedonia 6%, Bosnia 3%. While Western Europe moved past Joomla years ago, the Balkans still carry significant Joomla infrastructure.

June 2026 · 4 min read

Kenya vs Nigeria: Same Continent, Different Web. Kenya Has Shopify. Nigeria Has Only WordPress.

Kenya: 1,849 detected, WP 82%, Shopify 7.5%. Nigeria: 2,954 detected, WP 97%. Same continent, opposite digital paths.

June 2026 · 4 min read

The Development Dollar Framework: How UNDP and World Bank Shaped South Asia and Africa's Web.

Nepal 64% Drupal. Bangladesh 63%. Libya 42%. Ecuador 40%. Ivory Coast 37%. Uganda 31%. The framework map is the aid map.

June 2026 · 5 min read

Nepal Is 66% Drupal. Not WordPress. The South Asia Outlier Nobody Expected.

India is 83% WordPress. Pakistan is 63% WordPress. Nepal chose Drupal. 351 Drupal sites vs 165 WordPress. Something institutional happened here.

June 2026 · 4 min read

Nigeria Is 97% WordPress. 2,954 Sites. Essentially Zero Alternatives.

Africa's largest economy, 220 million people, the continent's biggest tech ecosystem. 97% of detected sites run WordPress. Not 93% like Turkey. Near-total monoculture at scale.

June 2026 · 4 min read

.edu at 58,182 Detections: Drupal 35.7%, Rails 16.4%. Academia Fully Mapped.

The largest .edu dataset ever published. Education remains the most framework-diverse sector. Rails at 16.4% — 9,568 sites — is the finding nobody expected.

June 2026 · 4 min read

.gov Is 49% Drupal. Government's Framework Choice Confirmed at 12,467 Sites.

The most comprehensive .gov framework survey ever. Drupal dominates at 49%. WordPress is 24%. Rails is 11%. Next.js is emerging at 6%.

June 2026 · 4 min read

Iran Is 93% WordPress. The Same Pattern as Turkey, but With Sanctions.

174 detected .ir sites. 93% WordPress. Isolation — economic and technological — produces digital monoculture.

June 2026 · 4 min read

Joomla: 352,042 Detections. More Than Astro, SvelteKit, Remix, and Gatsby Combined.

Among 10M+ sites scanned, the 'dead' framework has more detections than four of the most-hyped modern alternatives combined.

June 2026 · 4 min read

Joomla Outnumbers Astro and SvelteKit Combined. The 'Dead' Framework Isn't Dead.

176,344 Joomla sites vs 20,338 Astro + SvelteKit combined. Developer Twitter doesn't reflect the actual web.

May 2026 · 4 min read

.edu Domains Chose Differently: Drupal 35.7%, Rails 16.4%. Education Didn't Follow the WordPress Playbook.

58,182 .edu domains analyzed. WordPress leads at 38.5% but Drupal (35.7%) and Rails (16.4%) make education the most diverse sector.

May 2026 · 4 min read

Russia Has 7,189 Joomla Detections — The Largest Joomla Concentration in Our Data.

In our Common Crawl scan of 61,005 detected .ru sites, Joomla concentrates heavily in Russian domains. The rest of the world moved on. Russia didn't.

May 2026 · 4 min read

Healthcare's Web Problem Isn't WordPress. It's Fragmentation.

Among 17 healthcare sites we scanned: Drupal, WordPress, Next.js, Vue, Angular — no dominant framework. A small sample, but the fragmentation pattern is the finding.

May 2026 · 5 min read

Government Runs Drupal More Than WordPress. That's a Different Problem.

Among 49 government sites we scanned across 6 regions, Drupal dominates — not WordPress. A directional finding from a small but curated sample.

May 2026 · 6 min read

US Nonprofits: Defending Digital Rights on Digital Legacy

ACLU on WordPress. EFF on Drupal. The organizations defending digital rights are running on legacy infrastructure.

May 2026 · 4 min read

Grab Serves Millions of Users. Our Scanner Says It Runs WordPress.

Southeast Asia's largest super-app — ride-hailing, food delivery, payments — has a marketing site on legacy CMS. The infrastructure divide runs inside companies too.

May 2026 · 4 min read

GDPR Was a Data Law. It Became an Infrastructure Law.

Europe's data protection regulation is forcing infrastructure decisions. Legacy CMS was never built for data subject rights at scale.

May 2026 · 7 min read

APRA CPS 234: How Australian Financial Regulation Is Forcing Infrastructure Decisions

Australia's prudential regulator requires financial entities to maintain security capability commensurate with threats. Legacy infrastructure makes that harder every year.

May 2026 · 5 min read

American Healthcare on WordPress: The HIPAA Reckoning is Coming

Thousands of US medical practices run patient-facing services on WordPress. The OCR is increasing enforcement. The math doesn't work.

May 2026 · 6 min read

Australia's Census Failure: What Legacy Infrastructure Costs a Nation

The 2016 census failure cost A$30M+ and damaged public trust. It was a legacy infrastructure event with national consequences.

May 2026 · 5 min read

COBOL, Java 8, Python 2: The Three Horsemen of Legacy

Three technology generations that still run critical infrastructure. One has no new developers. One stopped receiving updates. One was officially sunset in 2020.

May 2026 · 7 min read

Healthcare Websites on WordPress: Patient Data Behind 18,005 CVEs

Medical practices, hospitals, and health systems running patient-facing services on the web's most-attacked framework.

May 2026 · 6 min read

Government Sites: Running a Nation's Web on 18,005 CVEs

The White House runs WordPress. So do thousands of government agencies worldwide. Public infrastructure on a legacy foundation.

May 2026 · 7 min read

Plugin Roulette: 27 Doors, and You Don't Know Which Ones Are Locked

The average WordPress site runs 27 plugins. Each one is an independent attack surface with its own update cycle, its own maintainer, and its own risk profile.

May 2026 · 6 min read

Year 1, Year 3, Year 5: What Happens to Sites That Don't Migrate

The compounding cost of staying on legacy frameworks. A timeline of escalating risk.

May 2026 · 7 min read

WordPress Powers 43% of the Web (W3Techs). It Scores 45 Out of 100.

The most widely deployed framework (W3Techs) is also one of its most vulnerable. Here's what the data says.

May 2026 · 6 min read