vulnerability management

AI takes on a bigger role in finding Chrome vulnerabilities

AI takes on a bigger role in finding Chrome vulnerabilities 2026-07-30 at 20:01 By Sinisa Markovic Google has expanded the use of AI in Chrome’s security workflow, using it to find vulnerabilities, triage bug reports, generate patches, and review code to shorten the time between discovering software flaws and delivering security updates. “Historically, triaging a […]

AI takes on a bigger role in finding Chrome vulnerabilities Read More »

Cantina Emerges From Stealth With $8 Million in Funding

Cantina Emerges From Stealth With $8 Million in Funding 2026-07-30 at 16:00 By Ionut Arghire The startup’s community-powered agentic security platform helps proactively identify, prioritize, and remediate vulnerabilities. The post Cantina Emerges From Stealth With $8 Million in Funding appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cantina Emerges From Stealth With $8 Million in Funding Read More »

200 new CVEs a day and no realistic way to patch them all

200 new CVEs a day and no realistic way to patch them all 2026-07-30 at 09:00 By Mirko Zorz Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability

200 new CVEs a day and no realistic way to patch them all Read More »

Google gives developers an AI bug hunter that also writes patches

Google gives developers an AI bug hunter that also writes patches 2026-07-24 at 11:53 By Sinisa Markovic Google has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm they are exploitable, and generate fixes for developers to review. (Source: Google) The company describes it as a response to

Google gives developers an AI bug hunter that also writes patches Read More »

Multi-patch vulnerability fixes can leave open source exposed

Multi-patch vulnerability fixes can leave open source exposed 2026-07-23 at 08:00 By Mirko Zorz Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two

Multi-patch vulnerability fixes can leave open source exposed Read More »

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) 2026-07-22 at 14:47 By Zeljka Zorz Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code,

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) Read More »

Companies keep getting breached by vulnerabilities they already knew about

Companies keep getting breached by vulnerabilities they already knew about 2026-07-16 at 07:30 By Mirko Zorz Scanning tools have gotten good at their work. Organizations now find more weaknesses across more of their systems than at any earlier point in the industry’s history. A survey from the security firm Vicarius points to a gap that

Companies keep getting breached by vulnerabilities they already knew about Read More »

White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative

White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative 2026-07-15 at 13:18 By Eduard Kovacs The new program stems from an AI-focused Executive Order signed by President Trump on June 2. The post White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative Read More »

Vulnerability reports are arriving faster than GitHub can review them

Vulnerability reports are arriving faster than GitHub can review them 2026-06-30 at 08:25 By Anamarija Pogorelec Across the open source world, people are reporting software flaws in record numbers, and the systems built to verify those reports are straining under the weight. The GitHub Advisory Database, which feeds automated security alerts to millions of projects,

Vulnerability reports are arriving faster than GitHub can review them Read More »

AWS Continuum brings AI models to code vulnerability management

AWS Continuum brings AI models to code vulnerability management 2026-06-18 at 07:33 By Sinisa Markovic AWS Continuum for code vulnerabilities, a system built to handle a vulnerability across its lifecycle, from discovery through to a fix, is now available in gated preview. It reasons over a customer’s environment, confirms which findings are real, and works

AWS Continuum brings AI models to code vulnerability management Read More »

The Chainguard Athena coalition already shipped 2,000 patches across 500 open source projects

The Chainguard Athena coalition already shipped 2,000 patches across 500 open source projects 2026-06-17 at 12:42 By Mirko Zorz Chainguard launched Athena, an industry coalition that pools open source vulnerability findings and remediates them under embargo before public disclosure. The group went live with more than two dozen member organizations. Founding members include BNY, Chainguard,

The Chainguard Athena coalition already shipped 2,000 patches across 500 open source projects Read More »

CISA orders federal agencies to “patch smarter”

CISA orders federal agencies to “patch smarter” 2026-06-11 at 20:18 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive that will change how the US federal government approaches vulnerability management. The directive arrives as the patching problem has become nearly unmanageable, driven by a surge in newly

CISA orders federal agencies to “patch smarter” Read More »

CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk

CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk 2026-06-11 at 16:01 By Ionut Arghire The new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries. The post CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk appeared first on SecurityWeek. This

CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk Read More »

From critical to controlled: Cutting vulnerabilities in a live manufacturing environment

From critical to controlled: Cutting vulnerabilities in a live manufacturing environment 2026-06-04 at 09:26 By Help Net Security A vulnerability scanner flags a critical CVSS 10 vulnerability on an industrial asset. The report lands in the boss’ inbox and now he wants to know why we’re sitting on a critical vulnerability. In a normal IT

From critical to controlled: Cutting vulnerabilities in a live manufacturing environment Read More »

Known vulnerabilities behind most application security incidents

Known vulnerabilities behind most application security incidents 2026-06-03 at 07:40 By Anamarija Pogorelec Eight in ten organizations took an application security hit during the past year tied to a vulnerability their team had already cataloged, according to a survey of 902 IT and security professionals conducted by the Cloud Security Alliance. The pattern points to

Known vulnerabilities behind most application security incidents Read More »

Building a risk-based vulnerability management program that scales

Building a risk-based vulnerability management program that scales 2026-05-29 at 08:01 By Help Net Security In this Help Net Security video, Shankar Somasundaram, CEO at Asimily, explains how to build a risk-based vulnerability program. He notes that vulnerabilities are exploding by an order of magnitude in the age of AI-driven attacks, with one customer finding

Building a risk-based vulnerability management program that scales Read More »

Claude now reviews and fixes vulnerabilities as you write code

Claude now reviews and fixes vulnerabilities as you write code 2026-05-27 at 16:37 By Sinisa Markovic Anthropic introduced a security-guidance plugin for Claude Code that reviews code changes for common vulnerabilities and helps Claude identify and fix issues during the same development session. The company says the plugin is designed to catch issues such as

Claude now reviews and fixes vulnerabilities as you write code Read More »

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector 2026-05-20 at 17:16 By Zeljka Zorz Vulnerability exploitation has overtaken stolen credentials as the most common way attackers gain initial access to target networks, according to the 2026 Verizon Data Breach Investigations Report. This is the first time credential theft has been knocked off the

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector Read More »

AI shrinks vulnerability exploitation window to hours

AI shrinks vulnerability exploitation window to hours 2026-05-18 at 09:42 By Anamarija Pogorelec Time has become organizations’ biggest vulnerability because the gap between vulnerability discovery and exploitation has narrowed to hours, according to Synack’s 2026 State of Vulnerabilities Report. Total vulnerabilities by severity (2022-2025) (Source: Synack) AI expands the attack surface Agentic AI systems that

AI shrinks vulnerability exploitation window to hours Read More »

Linux developers weigh emergency “killswitch” for vulnerable kernel functions

Linux developers weigh emergency “killswitch” for vulnerable kernel functions 2026-05-11 at 16:48 By Zeljka Zorz Linux kernel developers are reviewing a proposal for an emergency risk mitigation mechanism (“Killswitch”) that would allow administrators to disable vulnerable kernel functions at runtime. The proposal, submitted by Linux kernel developer/maintainer Sasha Levin, arrives in the wake of the

Linux developers weigh emergency “killswitch” for vulnerable kernel functions Read More »

Scroll to Top