Common Vulnerabilities and Exposures (CVE) stories
FIRST conference highlights AI & CVE disclosure push
Today
#
iot security
#
application security
#
supply chain
FIRST conference in Scottsdale draws 500-plus as security leaders and AI firms debate vulnerability disclosure, CWE's role and CVE's future.
Splashtop launches unified IT platform for endpoints
3 days ago
#
endpoint protection
#
digital transformation
#
it automation
Splashtop bets on AI-assisted patching and security alerts in a single console as it targets lean IT teams and MSPs with a new endpoint platform.
Forrester says Anthropic AI could break patch playbook
4 days ago
#
hybrid cloud
#
digital transformation
#
application security
Forrester warns Anthropic's Project Glasswing could overwhelm vulnerability management, as AI uncovers flaws faster than patching teams can respond.
Intruder adds container image scanning to cloud platform
Last week
#
virtualisation
#
devops
#
hybrid cloud
Intruder expands cloud security platform with registry-level container image scanning for AWS, Google Cloud and Azure users.
Qualys warns attackers exploit flaws before disclosure
Last week
#
firewalls
#
vpns
#
network security
Qualys says attackers are exploiting flaws before disclosure as remediation backlogs swell, with edge devices facing the highest risk.
Percona & Chainguard launch supported database images
Last month
#
virtualisation
#
devops
#
digital transformation
Percona teams up with Chainguard to offer supported, hardened container images for MySQL, PostgreSQL and MongoDB databases.
Rapid7 warns exploited software flaws more than double
Last month
#
firewalls
#
ransomware
#
network security
Rapid7 warns exploited high and critical software flaws more than doubled in 2025, as attackers compress disclosure-to-attack windows.
FIRST announces 2026 cyber security conference trio
Last month
#
application security
#
advanced persistent threat protection
#
socs
FIRST to host three cybersecurity conferences in 2026 as it predicts annual CVE disclosures will surpass 50,000 for the first time.
GitHub backs Alpha-Omega with fresh open source funds
Last month
#
siem
#
hyperscale
#
application security
GitHub joins tech giants in a USD $12.5 million Alpha-Omega push, boosting AI-powered defences for critical open source software.
Microsoft patches major SQL Server flaw in March update
Last month
#
firewalls
#
network security
#
mfa
Microsoft's March Patch Tuesday fixes 77 flaws, including a severe SQL Server bug that could grant attackers sysadmin rights remotely.
Wireless CVEs surge, exposing hidden risks for AI centres
Last month
#
uc
#
firewalls
#
surveillance
Wireless flaws have surged 230-fold since 2010, as Bastille warns AI data centres and critical infrastructure face escalating unseen risks.
AI-driven phishing surge as Acronis warns MSPs at risk
Fri, 20th Feb 2026
#
malware
#
ransomware
#
cloud security
Acronis warns AI is turbocharging phishing, email attacks and ransomware in 2025, with MSPs and collaboration tools under rising fire.
Simbian unveils AI agent for continuous pentesting
Fri, 20th Feb 2026
#
data protection
#
devops
#
application security
Simbian launches an AI Pentest Agent that runs continuous, adaptive penetration tests, promising faster, context-aware vulnerability detection.
Data-only extortion surges as remote access abused
Wed, 18th Feb 2026
#
data protection
#
dr
#
vpns
Data-only extortion soars 11-fold as attackers 'log in instead of break in', abusing remote access tools for faster, stealthier raids.
Endor Labs buys Autonomous Plane for container security
Fri, 13th Feb 2026
#
virtualisation
#
cloud security
#
application security
Endor Labs acquires Autonomous Plane to add reachability-led container image analysis, promising fewer false positives for security teams.
Cybersecurity teams brace for surge in global CVEs in 2026
Thu, 12th Feb 2026
#
siem
#
cloud security
#
socs
Cyber group FIRST warns CVE disclosures could smash records in 2026, topping 50,000 and potentially surging towards six figures.
Black Kite unveils tool to analyse third-party software risk
Thu, 8th Jan 2026
#
saas
#
supply chain
#
risk & compliance
Black Kite launches Product Analysis tool to expose hidden risks in third-party software, from SaaS subdomains to SBOM dependencies.
Codific predicts nine key cybersecurity shifts for 2026
Wed, 24th Dec 2025
#
data protection
#
digital transformation
#
encryption
Codific sees 2026 cybersecurity shaped by shadow AI, passwordless logins, tighter regulation and a sharper focus on software supply chains.
Minimus launches Image Creator for custom container images
Thu, 20th Nov 2025
#
hyperscale
#
cloud security
#
application security
Minimus unveils Image Creator, enabling enterprises to build secure, custom container images with enhanced compliance and reduced vulnerabilities.
Gaining control: The human role in AI-driven automation
Wed, 19th Nov 2025
#
firewalls
#
network infrastructure
#
network security
Many network owners fear AI automation may disrupt vital systems; experts urge human-centred control to ensure safety and trust in AI-driven operations.