Microsoft patched CVE-2026-62815 on August 11. CVSS 9.
Microsoft and the Zero Day Initiative looked at the same vulnerability this week and reached very different conclusions.
Progress patched CVE-2026-8037 on June 4th with a two-line diff. One line changed malloc() to calloc().
Broadcom's security advisories tend toward the corporate neutral — "we recommend applying the latest update at your earliest convenience.
N-able patched an authentication bypass in N-central back in April.
Palo Alto Networks just published the most detailed look yet at what happens when someone deliberately weaponizes an AI coding agent.
Wiz Research just publicly disclosed CosmosEscape, a vulnerability chain that let any Azure subscriber escalate from a standard Gremlin database to full...
Ruflo is one of those projects that grew fast enough to skip the security review.
Someone uploaded a profile picture. The server responded with a valid image — 400×300 pixels of what looked like static noise.
A security researcher pointed Kimi K3 at a Redis 8.8.
Last Monday, the Next.js team shipped patches for nine security vulnerabilities across v15.
A developer running WSL2 to test a container has the same VMSwitch code loaded as a production Hyper-V cluster hosting hundreds of tenants.
Prompt injection stopped being a content problem the moment someone typed a sentence into an AI agent and calc.exe opened on the host machine.
Every network has a DHCP server. Most teams treat it like plumbing — invisible until it breaks.
Microsoft pushed Malware Protection Engine version 1.1.
Adobe shipped patches for eleven ColdFusion vulnerabilities on June 30. Six hit the maximum CVSS score of 10.
Somewhere around late May, an attacker pointed a browser at a SimpleHelp server, submitted a self-signed JWT to the OIDC callback endpoint, and walked away...
CISA gave federal agencies until July 4 to patch CVE-2026-45659 — a SharePoint Server deserialization flaw that's been actively exploited in the wild.
Netlogon was supposed to be a solved problem.
SQL injection was supposed to be a solved problem. Parameterized queries have existed for decades.