Tag: cve
32 articles

Vulnerability Management Scrambles to Keep Pace with AI-Driven Discovery
The National Vulnerability Database (NVD) is undergoing a major overhaul as it struggles to keep up with a staggering 30,000 reclassified vulnerabilities, now marked as "Not Scheduled" for further analysis, amid a surge in AI-driven discoveries. This change aims to help manage the overwhelming backlog through selective processing and automation.

AI-Driven Vulnerability Discovery Surges, Threatens Software Security
The AI-driven vulnerability discovery surge is alarming, with OpenClaw, a popular AI project, ranking 12th in Q2 for most vulnerabilities discovered and published, with over 200 CVEs registered. This sharp increase in registered vulnerabilities is largely driven by AI adoption in both application development and vulnerability discovery.

AI Coding Tools Expose Open Source to Supply Chain Attacks
New research reveals a shocking vulnerability in AI coding tools: many suggested package names don't exist or point to outdated or compromised packages, leaving open-source projects open to supply chain attacks. This alarming gap in code-generation models highlights a pressing need for better safeguards.

NATO, AI Startup Gain Power to Track Software Vulnerabilities
The cybersecurity landscape just got a major boost: NATO's Cyber Security Centre and AI startup AISLE have joined forces with ENISA to supercharge vulnerability management, bringing the total number of CVE numbering authorities to 20. This powerful collaboration aims to revolutionize the way we track software vulnerabilities and stay one step ahead of cyber threats.

AI-Generated Patches Found Flawed in Testing
Researchers put AI-generated patches to the test and found that ChatGPT and Claude only succeeded in fixing high-impact vulnerabilities about 47% of the time, leaving a significant gap in remediation. This surprisingly low success rate raises important questions about the reliability of AI-generated solutions for critical security flaws.

Fake Vulnerabilities Flood CVE Pipeline via AI-Generated Reports
The CVE pipeline is being flooded with fake vulnerability reports generated by AI, which are then assigned scores as high as 9.8, only to be later debunked as non-existent flaws. Security vendor JFrog recently uncovered six bogus SQLite vulnerabilities, highlighting the alarming ease with which unverified reports can enter the system.

Chinese Hacker Exploits DeepSeek AI to Automate Vulnerability Attacks
A Chinese hacker leveraged the DeepSeek AI model to supercharge their vulnerability attacks, using an open-source AI framework to rapidly scan, research, and exploit targets with alarming speed and scale. This alarming automation was achieved through a clever combination of tools, including the Hermes Agent and Telegram.

AI Compresses Exploit Timelines, Exposes Prioritization Flaws
The arrival of AI models like Anthropic's Mythos is compressing exploit timelines, shrinking the window to patch vulnerabilities from weeks to just days or even hours. This acceleration exposes flaws in traditional prioritization methods, where only a handful of findings truly matter - out of 50,000, only a dozen make the cut.

Exposure Window Leaves Security Teams Vulnerable
The exposure window - the time between a vulnerability appearing and your team fixing it - is the critical gap that attackers exploit to cause real damage. With 48,185 CVEs disclosed in 2025 alone, and an average eCrime breakout time of just 29 minutes, the urgency to shrink this window has never been greater.

Microsoft Patch Deluge Exposes New Normal in Cybersecurity Updates
Microsoft just dropped a record 570 security updates on Patch Tuesday, revealing a new normal in cybersecurity: AI has drastically reduced the cost of finding vulnerabilities, leading to a surge in fixes that shows no signs of slowing down. This massive update batch included critical patches for elevation of privilege, remote code execution, and information disclosure flaws.

Microsoft Unveils Record-Breaking 622 Vulnerabilities in Massive Patch Update
Get ready for the bug apocalypse - Microsoft just dropped a massive Patch Tuesday update, fixing a record-breaking 622 vulnerabilities in one fell swoop! This behemoth of a patch tackles 416 Windows defects, 82 in Office, and 46 in Microsoft Edge, with 63 critical issues that demand immediate attention.

Vulnerability Management Lagging Behind AI-Driven Exploit Boom
The threat landscape is evolving at breakneck speed, with a new vulnerability emerging every 7.4 minutes and AI-driven tools slashing the time it takes to turn these vulnerabilities into active threats. As a result, traditional vulnerability management strategies are struggling to keep pace with the sheer volume and velocity of attacks.

Vulnerability Management Faces Patch Apocalypse Amid AI-Driven Discovery Surge
The AI-driven discovery surge is creating a perfect storm in vulnerability management, with nearly 48,000 CVEs published in 2025 alone, and a growing mismatch between rapid vulnerability discovery and slower human-led remediation. This has given rise to the "Patch Apocalypse," where the scale, speed, and exploitability of vulnerabilities are outpacing traditional patching approaches.

China-Aligned Hackers Exploit Roundcube Servers at US, Canada Universities
China-aligned hackers are targeting universities in the US and Canada, exploiting vulnerable Roundcube webmail servers to gain access to sensitive physics and engineering departments with potential national security links. This latest campaign highlights the ongoing threat of email-based attacks and the need for robust server security.

Anonymous Researcher Exploits 15 Software Products with Zero-Day Code Dump
A security bombshell has been dropped: an anonymous researcher has publicly shared exploit code for zero-day vulnerabilities in 15 software products, and hackers are already taking advantage of at least two of them. The alarming revelation has sent shockwaves through the cybersecurity community.

Microsoft Patch Tuesday Release Sets Record with 206 CVEs Addressed
Microsoft just dropped a record-breaking Patch Tuesday update, fixing a whopping 206 vulnerabilities across its products - including 38 critical ones. This massive release surpasses previous months and confirms a trend towards larger updates, raising both relief and concern among security experts.

Microsoft Patch Tuesday Update Sets Record with 206 Vulnerabilities Fixed
Microsoft just dropped a record-breaking Patch Tuesday update, fixing a staggering 206 vulnerabilities in a single swoop - a move that's both impressive and concerning. This massive update is part of a larger trend, with nearly half of this year's patches containing triple-digit numbers of fixes.

Vulnerabilities Dwindle to Manageable Number in Supply Chain Risk Landscape
The good news on supply chain risk: out of 1,200 high-priority vulnerabilities in 2025, only 58 proved both highly exposed and easily exploitable, making them a manageable threat. By focusing on these urgent few, organizations can tackle their most immediate and impactful risks.

Wireless Vulnerabilities Skyrocket, Outpacing Traditional Threats
The number of wireless vulnerabilities has skyrocketed, with a staggering 937 new threats discovered in 2025 alone - that's 2.5 new vulnerabilities every day. This represents a 60% increase since the start of 2024, and a growth rate that's 20 times faster than traditional threats over the last 15 years.

Autonomous Teaming Closes Defenders' Speed Gap
The alarmingly rapid pace of cyber threats has left defenders scrambling to keep up, with the time from vulnerability disclosure to working exploit dwindling from 56 days in 2024 to a staggering 10 hours in 2026. Meanwhile, defenders are still stuck on human time, struggling to match the lightning-fast speed of attackers who now operate in seconds.

CVE Feeds Overlook End-of-Life Software Vulnerabilities
The blind spot in CVE feeds is leaving end-of-life software vulnerabilities flying under the radar, with a staggering 167,286 false negatives identified in 2025 alone. This oversight can have serious consequences, as outdated software can still be exploited, even if it's no longer receiving patches.

NIST Curtails CVE Enrichment Amid Vulnerability Surge
The National Institute of Standards and Technology (NIST) is overhauling its approach to enriching entries in the National Vulnerability Database (NVD) due to a staggering 263% surge in vulnerability submissions. To keep pace, NIST will now prioritize enrichment for only the most critical entries that meet specific conditions.

NIST Shifts Focus to Enriching Exploited Vulnerabilities
The National Vulnerability Database is shifting gears: going forward, it'll prioritize enriching newly reported and actively exploited vulnerabilities, temporarily deprioritizing older entries. This change comes as the database faces an unprecedented surge in reported software flaws, with a record number of Common Vulnerabilities and Exposures (CVEs) submitted.

NIST Refocuses CVE Analysis Amid Vulnerability Surge
The National Institute of Standards and Technology (NIST) has adjusted its approach to vulnerability analysis, now prioritizing critical software, government systems, and actively exploited vulnerabilities amid a surge in reported threats. This strategic refocus aims to optimize its National Vulnerability Database's impact in a threat landscape that's outpacing its capacity.