Skip to main content

Tag: cve

32 articles

Cybersecurity team works in a busy operations center with multiple screens and computer equipment.

Vulnerability Management Scrambles to Keep Pace with AI-Driven Discovery

The National Vulnerability Database (NVD) is undergoing a major overhaul as it struggles to keep up with a staggering 30,000 reclassified vulnerabilities, now marked as "Not Scheduled" for further analysis, amid a surge in AI-driven discoveries. This change aims to help manage the overwhelming backlog through selective processing and automation.

Analyst 207
Cybersecurity team workspace with computers and equipment, featuring a large blank screen.

AI-Driven Vulnerability Discovery Surges, Threatens Software Security

The AI-driven vulnerability discovery surge is alarming, with OpenClaw, a popular AI project, ranking 12th in Q2 for most vulnerabilities discovered and published, with over 200 CVEs registered. This sharp increase in registered vulnerabilities is largely driven by AI adoption in both application development and vulnerability discovery.

Analyst 207
Cluttered developer workstation with laptop, monitor, and notes in a modern office with natural daylight.

AI Coding Tools Expose Open Source to Supply Chain Attacks

New research reveals a shocking vulnerability in AI coding tools: many suggested package names don't exist or point to outdated or compromised packages, leaving open-source projects open to supply chain attacks. This alarming gap in code-generation models highlights a pressing need for better safeguards.

Analyst 207
Diverse team in conference room with whiteboard and modern technology.

NATO, AI Startup Gain Power to Track Software Vulnerabilities

The cybersecurity landscape just got a major boost: NATO's Cyber Security Centre and AI startup AISLE have joined forces with ENISA to supercharge vulnerability management, bringing the total number of CVE numbering authorities to 20. This powerful collaboration aims to revolutionize the way we track software vulnerabilities and stay one step ahead of cyber threats.

Analyst 207
Security researcher working at desk with laptop and notes in a well-lit office.

AI-Generated Patches Found Flawed in Testing

Researchers put AI-generated patches to the test and found that ChatGPT and Claude only succeeded in fixing high-impact vulnerabilities about 47% of the time, leaving a significant gap in remediation. This surprisingly low success rate raises important questions about the reliability of AI-generated solutions for critical security flaws.

Analyst 207
Cluttered desk with scattered code printouts, vulnerability reports, and empty coffee cups.

Fake Vulnerabilities Flood CVE Pipeline via AI-Generated Reports

The CVE pipeline is being flooded with fake vulnerability reports generated by AI, which are then assigned scores as high as 9.8, only to be later debunked as non-existent flaws. Security vendor JFrog recently uncovered six bogus SQLite vulnerabilities, highlighting the alarming ease with which unverified reports can enter the system.

Analyst 207
Modern industrial facility with networking equipment and computer terminal.

Chinese Hacker Exploits DeepSeek AI to Automate Vulnerability Attacks

A Chinese hacker leveraged the DeepSeek AI model to supercharge their vulnerability attacks, using an open-source AI framework to rapidly scan, research, and exploit targets with alarming speed and scale. This alarming automation was achieved through a clever combination of tools, including the Hermes Agent and Telegram.

Analyst 207
Security architect analyzes network data on tablet and laptop in network operations center.

AI Compresses Exploit Timelines, Exposes Prioritization Flaws

The arrival of AI models like Anthropic's Mythos is compressing exploit timelines, shrinking the window to patch vulnerabilities from weeks to just days or even hours. This acceleration exposes flaws in traditional prioritization methods, where only a handful of findings truly matter - out of 50,000, only a dozen make the cut.

Analyst 207
Security analysts work together in a brightly-lit operations center surrounded by computer screens, with a cityscape…

Exposure Window Leaves Security Teams Vulnerable

The exposure window - the time between a vulnerability appearing and your team fixing it - is the critical gap that attackers exploit to cause real damage. With 48,185 CVEs disclosed in 2025 alone, and an average eCrime breakout time of just 29 minutes, the urgency to shrink this window has never been greater.

Analyst 207
Well-lit laptop on a lab bench displays a multitude of alerts and updates on its screen.

Microsoft Patch Deluge Exposes New Normal in Cybersecurity Updates

Microsoft just dropped a record 570 security updates on Patch Tuesday, revealing a new normal in cybersecurity: AI has drastically reduced the cost of finding vulnerabilities, leading to a surge in fixes that shows no signs of slowing down. This massive update batch included critical patches for elevation of privilege, remote code execution, and information disclosure flaws.

Analyst 207
Laptop screen displays Windows update progress bar with blurred coding environment background.

Microsoft Unveils Record-Breaking 622 Vulnerabilities in Massive Patch Update

Get ready for the bug apocalypse - Microsoft just dropped a massive Patch Tuesday update, fixing a record-breaking 622 vulnerabilities in one fell swoop! This behemoth of a patch tackles 416 Windows defects, 82 in Office, and 46 in Microsoft Edge, with 63 critical issues that demand immediate attention.

Analyst 207
Security analysts work amidst a chaotic atmosphere in a brightly-lit operations center.

Vulnerability Management Lagging Behind AI-Driven Exploit Boom

The threat landscape is evolving at breakneck speed, with a new vulnerability emerging every 7.4 minutes and AI-driven tools slashing the time it takes to turn these vulnerabilities into active threats. As a result, traditional vulnerability management strategies are struggling to keep pace with the sheer volume and velocity of attacks.

Analyst 207
Cybersecurity team discusses around a conference table in a modern operations room.

Vulnerability Management Faces Patch Apocalypse Amid AI-Driven Discovery Surge

The AI-driven discovery surge is creating a perfect storm in vulnerability management, with nearly 48,000 CVEs published in 2025 alone, and a growing mismatch between rapid vulnerability discovery and slower human-led remediation. This has given rise to the "Patch Apocalypse," where the scale, speed, and exploitability of vulnerabilities are outpacing traditional patching approaches.

Analyst 207
University campus scene with a building and clock tower, hint of computer equipment in foreground.

China-Aligned Hackers Exploit Roundcube Servers at US, Canada Universities

China-aligned hackers are targeting universities in the US and Canada, exploiting vulnerable Roundcube webmail servers to gain access to sensitive physics and engineering departments with potential national security links. This latest campaign highlights the ongoing threat of email-based attacks and the need for robust server security.

Analyst 207
Dimly lit computer laboratory with scattered technology equipment.

Anonymous Researcher Exploits 15 Software Products with Zero-Day Code Dump

A security bombshell has been dropped: an anonymous researcher has publicly shared exploit code for zero-day vulnerabilities in 15 software products, and hackers are already taking advantage of at least two of them. The alarming revelation has sent shockwaves through the cybersecurity community.

Analyst 207
Well-organized tech workspace with personnel working at computer workstations.

Microsoft Patch Tuesday Release Sets Record with 206 CVEs Addressed

Microsoft just dropped a record-breaking Patch Tuesday update, fixing a whopping 206 vulnerabilities across its products - including 38 critical ones. This massive release surpasses previous months and confirms a trend towards larger updates, raising both relief and concern among security experts.

Analyst 207
Technology company's workspace with multiple workstations and screens, laptop screen blurred in foreground.

Microsoft Patch Tuesday Update Sets Record with 206 Vulnerabilities Fixed

Microsoft just dropped a record-breaking Patch Tuesday update, fixing a staggering 206 vulnerabilities in a single swoop - a move that's both impressive and concerning. This massive update is part of a larger trend, with nearly half of this year's patches containing triple-digit numbers of fixes.

Analyst 207
Risk analyst examines supply chain data on tablet in industrial setting.

Vulnerabilities Dwindle to Manageable Number in Supply Chain Risk Landscape

The good news on supply chain risk: out of 1,200 high-priority vulnerabilities in 2025, only 58 proved both highly exposed and easily exploitable, making them a manageable threat. By focusing on these urgent few, organizations can tackle their most immediate and impactful risks.

Analyst 207
Busy office scene with wireless devices and equipment on a table, surrounded by people working.

Wireless Vulnerabilities Skyrocket, Outpacing Traditional Threats

The number of wireless vulnerabilities has skyrocketed, with a staggering 937 new threats discovered in 2025 alone - that's 2.5 new vulnerabilities every day. This represents a 60% increase since the start of 2024, and a growth rate that's 20 times faster than traditional threats over the last 15 years.

Analyst 207
Security operations center with analysts at workstations and multiple screens displaying data, set against an urban backdrop.

Autonomous Teaming Closes Defenders' Speed Gap

The alarmingly rapid pace of cyber threats has left defenders scrambling to keep up, with the time from vulnerability disclosure to working exploit dwindling from 56 days in 2024 to a staggering 10 hours in 2026. Meanwhile, defenders are still stuck on human time, struggling to match the lightning-fast speed of attackers who now operate in seconds.

Analyst 207
Dimly lit storage room with scattered old computer equipment and faded labels, daylight peeking through grimy windows.

CVE Feeds Overlook End-of-Life Software Vulnerabilities

The blind spot in CVE feeds is leaving end-of-life software vulnerabilities flying under the radar, with a staggering 167,286 false negatives identified in 2025 alone. This oversight can have serious consequences, as outdated software can still be exploited, even if it's no longer receiving patches.

Analyst 207
Overflowing papers and a looming database with a hint of digital warning.

NIST Curtails CVE Enrichment Amid Vulnerability Surge

The National Institute of Standards and Technology (NIST) is overhauling its approach to enriching entries in the National Vulnerability Database (NVD) due to a staggering 263% surge in vulnerability submissions. To keep pace, NIST will now prioritize enrichment for only the most critical entries that meet specific conditions.

Analyst 207
Magnifying glass hovers over shattered computer screen with code-like patterns in dark background.

NIST Shifts Focus to Enriching Exploited Vulnerabilities

The National Vulnerability Database is shifting gears: going forward, it'll prioritize enriching newly reported and actively exploited vulnerabilities, temporarily deprioritizing older entries. This change comes as the database faces an unprecedented surge in reported software flaws, with a record number of Common Vulnerabilities and Exposures (CVEs) submitted.

Analyst 207
Person studies laptop with scattered papers, hands gripped in stress, cityscape at dusk in background.

NIST Refocuses CVE Analysis Amid Vulnerability Surge

The National Institute of Standards and Technology (NIST) has adjusted its approach to vulnerability analysis, now prioritizing critical software, government systems, and actively exploited vulnerabilities amid a surge in reported threats. This strategic refocus aims to optimize its National Vulnerability Database's impact in a threat landscape that's outpacing its capacity.

Analyst 207