Skip to main content

Vulnerability Management

Security architect analyzes network data on tablet and laptop in network operations center.

AI Compresses Exploit Timelines, Exposes Prioritization Flaws

The arrival of AI models like Anthropic's Mythos is compressing exploit timelines, shrinking the window to patch vulnerabilities from weeks to just days or even hours. This acceleration exposes flaws in traditional prioritization methods, where only a handful of findings truly matter - out of 50,000, only a dozen make the cut.

Analyst 207
Cybersecurity researcher working at a desk with laptop and papers.

AI-Discovered Vulnerabilities See Similar Exploitation Rates as Traditional Ones

New research reveals that vulnerabilities discovered using AI tools are being exploited at almost the same rate as those found through traditional methods, with a 1.3% exploitation rate for AI-discovered vulnerabilities. This challenges alarmist predictions of an impending AI-driven security crisis.

Analyst 207
Cluttered coding workspace with computer, papers, and manuals, hinting at a Git project.

Gitea Flaw Lets Writers Run Shell Commands via Git Hook

A newly discovered vulnerability in Gitea, rated 9.8 in severity, allows ordinary repository writers to execute shell commands as the Gitea service account by exploiting a remote code execution bug via a cleverly planted Git hook. This critical flaw, tracked as CVE-2026-60004, puts Gitea users at risk of a devastating attack.

Analyst 207
Mathematician works at desk with laptop and papers, surrounded by cryptic symbols and equations on chalkboard in soft…

AI Models Expose Vulnerabilities in Historic Cryptographic Algorithms

Can AI models uncover weaknesses in centuries-old cryptographic algorithms? A new benchmark, CryptanalysisBench, puts large language models to the test, challenging them to discover real cryptanalytic attacks against historical and contemporary schemes.

Analyst 207
Researcher in lab setting with laptop and papers, surrounded by math references.

AI Model Exposes Weaknesses in Key Encryption Algorithms

An AI system has made a groundbreaking discovery, uncovering significant weaknesses in key encryption algorithms that even the experts didn't know existed. By working together with a human researcher, the AI was able to find a mathematical shortcut that halves the effective strength of HAWK, a digital-signature scheme being considered for post-quantum cryptography.

Analyst 207
Researcher working at a lab bench with technology and security tools, surrounded by notes and diagrams.

AI-Assisted Tools Discover More Vulnerabilities, But Exploitation Rate Remains Steady

AI-assisted tools are supercharging vulnerability discovery, uncovering over 1,000 new defects in just six months, yet the rate of exploitation remains surprisingly steady, with only 1.3% of AI-discovered vulnerabilities being exploited in the wild. This finding challenges the notion that AI-discovered vulnerabilities are inherently more attractive to attackers.

Analyst 207
High-performance computing equipment and server setup in a laboratory.

Claude AI Exposes Faster Attacks on Post-Quantum Cryptography Scheme HAWK, AES

Anthropic's Claude AI has made a groundbreaking discovery, cracking a post-quantum cryptography scheme in just three hours and 42 minutes on a 96-core server. The AI, specifically Mythos Preview, uncovered a hidden symmetry that paved the way for a direct key-recovery path.

Analyst 207
Minimalist lab setting with computer workstations and equipment, large screen displaying abstract code representation.

AI Agents Outperform Solo Models in Bug Hunting with 90% Success Rate

AI agents are revolutionizing bug hunting, outperforming solo models with a staggering 90% success rate, and uncovering critical security holes in widely used open-source code. This breakthrough has significant implications for cybersecurity, with leading agentic systems like Wiz's Project Atlas and Microsoft's MDASH achieving double-digit gains over single-model competitors.

Analyst 207
Researcher's workstation with laptop, books, and notes, under bright lighting, with a focused yet inactive atmosphere.

AI-Assisted Bug Discovery Falls Short of Expected Exploit Wave

The hype around AI-assisted bug discovery may have been overstated, as a recent analysis found that only 1.3% of vulnerabilities identified with AI have been confirmed as exploited in the wild. This surprisingly low rate suggests that AI-assisted discovery may not be the silver bullet for uncovering easily exploitable vulnerabilities.

Analyst 207
Laboratory workstation with computer, monitor, and technical equipment.

AI-Assisted Research Exposes Linux Kernel Zero-Day Flaw

Researchers have uncovered a long-standing vulnerability in the Linux kernel, known as CVE-2026-53264, which allows a local user to gain root privileges by exploiting a flaw in the packet-scheduling code. This zero-day flaw was identified with the help of AI-assisted research and has since been patched.

Analyst 207
Rows of computer servers and management interfaces in a data center or server room.

IPMI Vulnerability Exposes 24,650 Server Management Interfaces

A recent security researcher found that over 30% of server management interface passwords can be easily cracked using common wordlists and factory default patterns, exposing a massive 24,650 interfaces to potential threats. This startling vulnerability, CVE-2013-4786, allows hackers to gain unauthorized access to sensitive server management hardware.

Analyst 207
Model repository and cards on a clean, neutral-colored table in a lab or tech workspace.

Flaws in Hugging Face Diffusers Bypass Code Safeguards

Researchers uncovered a disturbing vulnerability in Hugging Face's diffusers library, where three high-severity flaws allowed hackers to secretly execute malicious code through model repositories, bypassing built-in safeguards designed to prevent such threats. This alarming exploit highlights the urgent need for enhanced security measures in AI repositories.

Analyst 207
A network router sits on a clean surface with a blurred background, conveying vulnerability.

OpenWrt Fixes Critical DHCPv6 Flaw That Exposes Root Code Execution Risk

OpenWrt has patched a critical DHCPv6 flaw, known as CVE-2026-53921, that could allow an unauthenticated attacker to execute root code by sending a crafted request to the DHCPv6 server. This severe vulnerability, rated 9.8 out of 10, highlights the importance of updating your OpenWrt setup to prevent potential security breaches.

Analyst 207
Server room with rows of equipment and a highlighted BMC module on a rack.

Decades-Old BMC Flaw Exposes 24,000 Servers to Password Cracking

A decades-old security flaw in Baseboard Management Controller (BMC) interfaces is putting over 24,000 internet-exposed servers at risk of password cracking, thanks to a vulnerability that allows attackers to capture and crack authentication responses. This two-decade-old weakness, tracked as CVE-2013-4786, is a pressing concern for server administrators.

Analyst 207
Modern office workstation with Linux computer setup on a clutter-free desk.

AI-Assisted Linux Exploit Turns Local Users into Root

Researchers have uncovered a significant Linux exploit, CVE-2026-53264, that can turn local users into root users, highlighting the importance of human judgement in AI-assisted security work. This flaw, patched in June 2026, shows AI still has limitations, emphasizing the need for human oversight.

Analyst 207
Outdated computer equipment sits alongside modern technology in a dimly lit factory room.

Legacy Technology Exposes Nations to Growing Cyber Risk

The clock is ticking: with legacy technology, organisations know the risks, but lack a mechanism to spark change, leaving nations vulnerable to growing cyber threats. As exploits and AI evolve at breakneck speed, the window for protection is shrinking fast.

Analyst 207
Minimalistic workspace with computer screen and futuristic circuit board, brightly lit with daylight.

Microsoft Unveils AI Model Boosting Vulnerability Detection to 95.95% at Lower Cost

Microsoft's new AI model, MAI-Cyber-1-Flash, paired with GPT-5.4, has achieved a remarkable 95.95% vulnerability detection rate at nearly half the cost of its previous system. This game-changing tech, integrated into MDASH, is revolutionizing cybersecurity with faster and more affordable threat detection.

Analyst 207
Blurred Windows domain authentication screen on a computer terminal in a corporate office setting.

Certighost Exploit Hijacks Windows Domains With Authenticated Attacks

Beware of the Certighost exploit, a sneaky attack that lets hackers hijack Windows domains by manipulating machine account attributes and snagging authentication certificates. This vulnerability, tracked as CVE-2026-54121, was patched in July 2026, but not before security researchers publicly disclosed its technical details.

Analyst 207
Sleek computer terminal with futuristic security props on minimalist background.

Microsoft Unveils AI-Powered Security Model to Outperform Rivals

Microsoft just unveiled a game-changing AI-powered security model that has achieved a remarkable 95.95 percent success rate in identifying vulnerabilities, leaving the competition in the dust. This innovative model, combined with the MDASH harness, is poised to revolutionize bug hunting and cybersecurity.

Analyst 207
Technicians work in a modern server room with rows of computer servers and networking equipment.

Exploit for Patched vBulletin Flaw Disclosed

A newly disclosed exploit for a patched vBulletin flaw shows how an unauthenticated request can be used to execute code on an unpatched forum server, putting vulnerable sites at risk. This security threat was made public on July 27, highlighting the importance of keeping software up to date.

Analyst 207
Laptop screen displays workflow editor in a tidy home office surrounded by notes and technical books.

n8n Flaw Lets Authenticated Editors Run OS Commands

A security flaw in n8n allows authenticated editors to run OS commands, thanks to two overlooked vulnerabilities that let them break free from the platform's protective sandbox. This weakness was uncovered by Security Joes' research team, who found that the flaws could be exploited to execute operating-system commands as the n8n process.

Analyst 207
System administrator inspects Linux servers in a server room with one server displaying a maintenance screen.

Microsoft Defender for Endpoint update cripples Linux protection

A recent update to Microsoft Defender for Endpoint has caused a major hiccup, crippling Linux protection and potentially leaving some devices vulnerable. The issue affects specific Linux versions, and a simple upgrade or reinstall followed by a reboot could be the culprit behind a disabled Defender service.

Analyst 207
Brightly-lit computer server room with rows of equipment and a central node.

NodeBB Fixes Flaws Exposing Admin Access, Private Chats

NodeBB has patched eight high-severity security flaws that left its forum platform vulnerable to admin access and private chat exposure, affecting all versions prior to 4.14.0. Admins should install the fixes immediately to safeguard their sites.

Analyst 207
Modern software development facility with workstations and computer equipment, and a blurred laptop screen in the foreground.

Oracle Releases 1,449 Security Patches Amid AI-Driven Vulnerability Surge

Oracle's recent release of 1,449 security patches may seem alarming, but experts say it's largely a reflection of the company's massive software ecosystem and its cutting-edge use of AI to supercharge vulnerability detection. This huge number is also a testament to Oracle's proactive approach to staying on top of security threats.

Analyst 207