A critical vulnerability in LMCache could allow unauthenticated remote attackers to execute arbitrary code on exposed ...
The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, published today its second risk monitoring report of 2026, setting out the main risks and ...
Read how How Microsoft Security's FORGE Lab is scaling vulnerability research from Windows to the Linux kernel.
Adversa AI researchers say a booby-trapped web page can trick GitHub Copilot CLI into reading local secrets such as .env ...
The companies also announced the general availability of Lightwell Clearinghouse, which allows enterprise customers to submit specific open source software dependencies for priority review and ...
Your vulnerability scanner is sorting by the wrong signal. How to use CVSS, EPSS, and local context to prioritize remediation ...
GTIG investigated vulnerability disclosure and exploitation statistics and found that AI is measurably changing the pace of vulnerability discovery, exploitation, and the types of vulnerabilities ...
A critical security flaw in the official MCP Python SDK could allow a malicious MCP server to steal OAuth credentials used to log in to real services, ...
MCP Python SDK flaw can let malicious servers redirect OAuth exchanges and steal credentials; fixes are in 1.30.0 and 2.2.0.
When this AI security researcher confirmed an unauthenticated remote code execution vulnerability in OpenMed, the finding was not just another security bug. It showed how AI can help vulnerability ...
A Chinese threat actor has been targeting vulnerable ZyXEL GS1900 switches worldwide for sensitive information exfiltration, threat intelligence firm GreyNoise warns. Tracked as CVE-2026-7273 (CVSS ...
AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws. A tidal wave of vulnerabilities ...