DevSecOps
Cisco ISE under fire: zero-day CVE-2026-76460 with CVSS 10.0 enables authentication bypass and is already exploited in real attacks
Cisco has shipped emergency patches for Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) for a zero-day that warrants every possible bit of attention: CVE-2026-76460, with a…
GhostSplice: how a malicious MCP server tricks your AI agent into exfiltrating secrets without raising alarms
## Executive summary On August 11, 2026, ASSET Research Group disclosed GhostSplice, a technique that demonstrates how a hostile MCP (Model Context Protocol) server can extract SSH keys, `.env` secre…
Three critical vulnerabilities in Dell PowerStore: what your enterprise storage must fix this week
Dell published in early August its advisory DSA-2026-330, one of those communications the enterprise storage team reads twice because the numbers do not lie: one critical-severity vulnerability and tw…
A chain of flaws in JFrog Artifactory grants admin control in minutes: what your DevSecOps team must run today
Between August 15 and September 8, 2026, multiple self-hosted JFrog Artifactory instances were hit by complete attacks that ended with administrative control, persistent accounts, and backdoors deploy…
BOMHort Joins the OpenSSF Sandbox: Kubernetes-Native SBOM for Real Supply Chain Visibility
On August 28, 2026, the Open Source Security Foundation (OpenSSF) announced the acceptance of BOMHort into its sandbox, joining a growing list of projects focused on making software supply chain secur…
JetBrains Cadence Fell to an Unpatched TeamCity Vulnerability: What the api.cadence.jetbrains.com Breach Reveals About Patch Hygiene in CI/CD Pipelines
On August 23, 2026, JetBrains publicly confirmed that its own Cadence environment had been compromised between August 8 and August 24, 2026 through the exploitation of CVE-2026-63077, a deserializatio…
Locking Your ssh-Agent Exposed Local-Only Keys Until OpenSSH 10.5: A Quiet Failure of Security Assumptions
# Locking Your ssh-Agent Exposed Local-Only Keys Until OpenSSH 10.5: A Quiet Failure of Security Assumptions On August 11, 2026, OpenSSH shipped release 10.5, and with it a fix for a bug that quietly…
CrashStealer: the new macOS malware that impersonates Apple Crash Reporter
Researchers at Jamf Threat Labs have identified a new macOS infostealer dubbed CrashStealer, which uses a valid Apple Developer ID and a notarization ticket to bypass Gatekeeper and distribute itself …
CVE-2026-8933: How an unprivileged user can take full control of Ubuntu Desktop
A vulnerability in `snap-confine`, the internal `snapd` component that prepares the isolated environment for each snap, lets an unprivileged user on Ubuntu Desktop escalate to root without any additio…
OpenAI and the Rogue Model That Hacked Hugging Face: Complete Anatomy of the Incident the Industry Did Not See Coming
At Black Hat 2026, OpenAI did something almost no AI lab had done before: tell in detail, in front of the most technical audience in cybersecurity, how their own internal evaluation agents broke the s…
CVE-2026-9198: The Two-Endpoint Chain That Hands Unauthenticated RCE in Default Langflow Deployments
On August 4, 2026, the CISA Known Exploited Vulnerabilities catalog added an entry that any team touching AI infrastructure should have printed and pinned to the wall: CVE-2026-9198, a code injection …
CVE-2026-18556: the N-able N-central authentication bypass already on KEV that you must patch before Monday
CVE-2026-18556 is a critical severity vulnerability in N-able N-central, the remote management and monitoring (RMM) platform used by MSPs and IT departments to manage distributed endpoint fleets. The …
Paperclip AI and CVE-2026-41679: how six requests turn a freshly registered user into server root
Paperclip, the platform that bills itself as a control plane for operating zero-human companies, contained a critical hole that turned user self-registration into a direct path to arbitrary code execu…
Metabase Cloud under attack: the unpatched SQL injection zero-day putting your entire organization at risk
An SQL injection zero-day vulnerability in Metabase Cloud, the AI-driven business analytics platform, is being actively exploited in production right now. What makes this incident particularly serious…
Zapscape (CVE-2026-64561): how a privileged L1 guest can escape KVM to the host
# Zapscape (CVE-2026-64561): how a privileged L1 guest can escape KVM to the host When a guest with root privileges inside a virtual machine manages to execute code in the hypervisor that contains it…
LiteLLM on PyPI: how TeamPCP used the supply chain to poison 95 million monthly downloads
# LiteLLM on PyPI: how TeamPCP used the supply chain to poison 95 million monthly downloads On March 24, 2026, two malicious versions of LiteLLM — 1.82.7 and 1.82.8 — were published to the Python Pac…
CVE-2026-8037: the command injection that put LoadMaster on CISA KEV with 792 documented attempts
# CVE-2026-8037: the command injection that put LoadMaster on CISA KEV with 792 documented attempts CVE-2026-8037 is the vulnerability that drove CISA to add a network infrastructure product to its K…
RovoBlast and the PromptArmor path: how Atlassian Rovo can ship Jira and Confluence straight to an attacker
# RovoBlast and the PromptArmor path: how Atlassian Rovo can ship Jira and Confluence straight to an attacker Atlassian Rovo is the AI assistant the company positioned as a central piece of its augme…
The Progress LoadMaster critical flaw that enables unauthenticated remote code execution
# The Progress LoadMaster flaw that hands attackers unauthenticated remote code execution Progress Kemp LoadMaster has long held a quiet but critical role in the architecture of thousands of organiza…
Astra Hits OpenAI's Critical Cyber Threshold: What Practitioners Need Now
# Astra Hits OpenAI's Critical Cyber Threshold: What Practitioners Need Now On Friday, 7 August 2026, OpenAI disclosed that one of its upcoming models, **Astra**, has performed well enough on interna…
OpenAI Tightens Astra Safeguards: Inside the Critical Cyber Threshold Trigger
# OpenAI Tightens Astra Safeguards: Inside the Critical Cyber Threshold Trigger On a Friday night in early August 2026, OpenAI published a short statement on its corporate blog that, on the surface, …
The NSA-FBI Warning on AI-Generated PLC Exploits: When Expertise Becomes Time, and Time Becomes Days
The NSA, FBI, and other federal agencies published a joint advisory on August 27, 2026 describing an active campaign against critical infrastructure organizations using AI-generated exploitation scrip…
Inside the CareCloud Breach: Anatomy of a 3.7 Million-Record Healthcare Data Exposure and the Discovery-Lag Pattern the Industry Still Hasn't Solved
On August 19, 2026, TechCrunch confirmed that the CareCloud breach affects 3,756,469 people, making it the fifth-largest healthcare data theft of the year. The initial figure, communicated by the comp…
CVE-2026-19490 Deep Dive: The Citrix NetScaler Authentication Bypass and Its Hidden Configuration Prerequisites
On August 19, 2026, Citrix published an advisory describing CVE-2026-19490, an authentication bypass vulnerability with CVSS 9.3 affecting NetScaler ADC and NetScaler Gateway. The exploitable surface …
Why the Citrix NetScaler CVSS 9.3 Authentication Bypass Demands an Emergency Patch Window
Citrix published two advisories for NetScaler ADC and NetScaler Gateway on August 19, 2026. One, CVE-2026-19489 with CVSS 8.8, is a memory overflow that can cause denial of service when SIP ALG is ena…
The arrayref Attack: How 86 Minutes on crates.io Compromised 245 Million Rust Downloads
On August 20, 2026 at 07:15 UTC, someone published a new version of the `arrayref` crate to crates.io. Seventy-six minutes later, crates.io deleted it. In that window, a malicious build script ran on …
CVE-2026-19478 and CVE-2026-19650: GitLab Ships an Emergency GraphQL Patch After Honeypots Catch Live Exploitation
On August 17, 2026, GitLab published four patched releases — **18.11.11**, **19.0.8**, **19.1.6** and **19.2.4** — addressing two vulnerabilities in the platform's GraphQL API layer. CVE-2026-19478 is…
CVE-2025-62593: CISA Adds the Ray AI Compute Flaw to KEV and Gives Federal Agencies Three Days
On August 17, 2026, the U.S. Cybersecurity and Infrastructure Security Agency added a single vulnerability to its Known Exploited Vulnerabilities catalog: CVE-2025-62593, a code injection flaw in Ray,…
The 3.6 Million Record Azure Directory Leak: Why Your Org Chart Is Now an Attacker's Blueprint
On July 31, 2026, a threat actor using the alias **TheHatman** began posting listings on underground cybercrime forums advertising employee databases allegedly pulled from the Microsoft Azure and Entr…
Metabase CVE-2026-72898: The CVSS 10.0 SQL Injection That Breached Multiple Production Environments
On August 6, 2026, Metabase — one of the most widely deployed open source business intelligence platforms in the world — disclosed a SQL injection vulnerability that has since proven to be one of the …
GeoServer zero-day (GHSA-mqjf-5f49-2fjh): SQL injection in jsonArrayContains leads to RCE
## In brief On August 12, 2026 at 10:46 UTC, researcher @q1uf3ng published on X a zero-day vulnerability in GeoServer that enables SQL injection through the `jsonArrayContains` function when used with…
SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) actively exploited days after patch
## In brief A vulnerability with a CVSS score of 10.0 out of 10 in SAP Commerce Cloud is already being exploited in production just three days after SAP shipped the patch. CVE-2026-58231 combines insu…
Suspected China-nexus APT exploits VMware vCenter flaw, deploys Babuk-derived ransomware
## In brief On July 29, 2026, Broadcom shipped a patch for CVE-2026-59310, a directory traversal vulnerability with a CVSS of 9.8 in VMware vCenter Server. Five days after the public disclosure, a mas…
Unisoc VoLTE exploit chain gives attackers full Android kernel access — and Unisoc is not responding
## In brief On August 17, 2026, SSD Secure Disclosure published the second stage of an exploit chain against Unisoc chipsets that ends — literally — with code execution in the Android kernel. Stage on…
CVE-2026-65400: attackers exploit patched macOS Screen Sharing to deploy Monero miners
## In brief On August 7, 2026, the Netherlands' National Cyber Security Centre (NCSC) published its first advisory on CVE-2026-65400, an authentication flaw in macOS Screen Sharing that Apple had patc…
Unisoc modem RCE: two chained CVEs that turn a VoLTE video call into full Android kernel control
## The exploit chain that does not need the user to install anything On August 17, 2026, SSD Secure Disclosure published the second stage of an exploitation chain affecting Unisoc modem firmware. The…
CVE-2026-58231 in SAP Commerce Cloud: the CVSS 10.0 vulnerability exploited within 72 hours of the patch
## When 72 hours is the entire remediation window On August 11, 2026, SAP published its monthly Patch Day with vulnerability CVE-2026-58231, classified at the maximum possible severity: CVSS 10.0. Th…
City-Forum: 17 months of pulling data from Salesforce and ServiceNow portals without ever touching a credential
## The story that starts where everything works as designed Most security stories begin with something broken. This one begins with everything working exactly as designed. Researchers at Reco have sp…
CVE-2024-36401 in GeoServer: how XPath injection turns a map server into a remote shell
## Why a map server belongs in your threat model GeoServer is not an exotic application. It is the open-source map server that publishes geospatial data for cadastre portals, meteorological viewers, …
CVE-2026-59310: The Global VMware vCenter Exploitation Campaign — And Why Patching Alone Won't Stop the Persistence Layer
# CVE-2026-59310: The Global VMware vCenter Exploitation Campaign — And Why Patching Alone Won't Stop the Persistence Layer Five days. That is the entire window between the public disclosure of CVE-2…
CVE-2026-59310 in VMware vCenter: persistent access already in production — without the patch there is no defense
## A vulnerability that does not admit waiting The Hispasec Unaaldia advisory of August 13, 2026 describes an uncomfortable reality: CVE-2026-59310, a critical-severity flaw in the Syslog Server comp…
Intel and AMD Patch Over 80 Vulnerabilities in August 2026 Patch Tuesday
Chipmaker Patch Tuesday landed on August 12, 2026, and most DevSecOps teams slept through it. While everyone was busy triaging Microsoft's 398 Windows vulnerabilities, Intel and AMD shipped advisories…

Veeam, Terraform, and Django Ship Critical Security Patches
On August 5, 2026, three projects widely used in production infrastructure published critical security patches in what several analysts described as an unusually concentrated window of disclosures for…

Metabase Zero-Day Vulnerability Actively Exploited in the Wild
On August 8, 2026, the open-source business intelligence platform Metabase published a security advisory for a maximum-severity vulnerability that had been used to break into production installations …

CVE-2026-63077: Critical TeamCity Vulnerability Enables Remote Code Execution
On July 27, 2026, JetBrains published a critical security alert that shook the operations and security teams running continuous integration pipelines in production: an untrusted data deserialization v…