vulnerability management

The Week in Vulnerabilities: GitHub Enterprise, Argo CD, Oracle Identity Manager, and Mozilla Security Flaws

The Week in Vulnerabilities: GitHub Enterprise, Argo CD, Oracle Identity Manager, and Mozilla Security Flaws 2026-04-30 at 16:45 By Ashish Khaitan The latest weekly vulnerability Insights report to clients by Cyble provides a detailed view of vulnerabilities tracked between April 15, 2026, and April 21, 2026. The findings highlight a slight dip in overall disclosures compared to the previous week, but the persistence […]

The Week in Vulnerabilities: GitHub Enterprise, Argo CD, Oracle Identity Manager, and Mozilla Security Flaws Read More »

The Week in Vulnerabilities: SharePoint, Fortinet, OpenClaw, and GPL Odorizers

The Week in Vulnerabilities: SharePoint, Fortinet, OpenClaw, and GPL Odorizers 2026-04-24 at 05:54 By Mihir Bagwe Cyble Research & Intelligence Labs (CRIL) weekly vulnerability report tracked 1,675 vulnerabilities, last week, reflecting continued high disclosure volume across enterprise software, cloud services, and emerging AI ecosystems. Of these, more than 205 vulnerabilities have publicly available Proof-of-Concept (PoC)

The Week in Vulnerabilities: SharePoint, Fortinet, OpenClaw, and GPL Odorizers Read More »

Claude Mythos finds 271 Firefox flaws, Mozilla believes it shifts security toward defenders

Claude Mythos finds 271 Firefox flaws, Mozilla believes it shifts security toward defenders 2026-04-22 at 18:51 By Sinisa Markovic The Mozilla Foundation tested Claude Mythos, an Anthropic AI model that has stirred debate in the cybersecurity community. Before granting access to Mythos, Mozilla scanned Firefox using Opus 4.6, which led to fixes for 22 security-sensitive

Claude Mythos finds 271 Firefox flaws, Mozilla believes it shifts security toward defenders Read More »

NIST admits defeat on NVD backlog, will enrich only highest-risk CVEs going forward

NIST admits defeat on NVD backlog, will enrich only highest-risk CVEs going forward 2026-04-16 at 19:48 By Zeljka Zorz NIST is overhauling how it manages the National Vulnerability Database (NVD) and switching to a risk-based model that prioritizes “enrichment” of only the most critical CVE-numbered security vulnerabilities. “This change is driven by a surge in

NIST admits defeat on NVD backlog, will enrich only highest-risk CVEs going forward Read More »

The Week in Vulnerabilities: Azure AI, Spring AI, Fortinet, and Critical ICS Exposure

The Week in Vulnerabilities: Azure AI, Spring AI, Fortinet, and Critical ICS Exposure 2026-04-16 at 15:04 By Mihir Bagwe Cyble Research & Intelligence Labs (CRIL) in its weekly vulnerability report tracked 1,431 bugs last week. Of these, over 270 vulnerabilities have publicly available Proof-of-Concept (PoC) exploits, significantly accelerating exploitation timelines and increasing real-world attack likelihood.

The Week in Vulnerabilities: Azure AI, Spring AI, Fortinet, and Critical ICS Exposure Read More »

Fixing vulnerability data quality requires fixing the architecture first

Fixing vulnerability data quality requires fixing the architecture first 2026-04-13 at 09:02 By Mirko Zorz In this Help Net Security interview, Art Manion, Deputy Director at Tharros, examines why vulnerability data across repositories stays inconsistent and hard to trust. The problem starts with systems not designed to collect or manage that data well. They introduce

Fixing vulnerability data quality requires fixing the architecture first Read More »

The Week in Vulnerabilities: OpenClaw, FreeBSD, F5 BIG-IP, and Critical ICS Bugs

The Week in Vulnerabilities: OpenClaw, FreeBSD, F5 BIG-IP, and Critical ICS Bugs 2026-04-09 at 14:24 By Mihir Bagwe Cyble Research & Intelligence Labs (CRIL) weekly vulnerability report tracked 1,960 vulnerabilities last week, reflecting a continued surge in vulnerability disclosures across enterprise and cloud ecosystems. Of these, 248 vulnerabilities have publicly available Proof-of-Concept (PoC) exploits, significantly

The Week in Vulnerabilities: OpenClaw, FreeBSD, F5 BIG-IP, and Critical ICS Bugs Read More »

The case for fixing CWE weakness patterns instead of patching one bug at a time

The case for fixing CWE weakness patterns instead of patching one bug at a time 2026-04-07 at 09:24 By Mirko Zorz In this Help Net Security interview, Alec Summers, MITRE CVE/CWE Project Lead, discusses how CWE is moving from a background reference into active use in vulnerability disclosure. More CVE records now include CWE mappings

The case for fixing CWE weakness patterns instead of patching one bug at a time Read More »

The Week in Vulnerabilities: AI Frameworks, VMware, and Critical ICS Exposure

The Week in Vulnerabilities: AI Frameworks, VMware, and Critical ICS Exposure 2026-04-02 at 13:24 By Ashish Khaitan Cyble Research & Intelligence Labs (CRIL) tracked 1,452 vulnerabilities last week, reflecting the continued expansion of the global attack surface.   Of these, 222 vulnerabilities have publicly available Proof-of-Concept (PoC) exploits, significantly accelerating the likelihood of exploitation in real-world environments.   Additionally, multiple vulnerabilities surfaced across underground forums,

The Week in Vulnerabilities: AI Frameworks, VMware, and Critical ICS Exposure Read More »

The Week in Vulnerabilities: Juniper, Cisco SD-WAN, and Critical ICS Exposure

The Week in Vulnerabilities: Juniper, Cisco SD-WAN, and Critical ICS Exposure 2026-03-20 at 11:15 By Ashish Khaitan Cyble Research & Intelligence Labs (CRIL) tracked 1,641 vulnerabilities between March 04 and March 10, 2026. Of these, 175 vulnerabilities already have publicly available Proof-of-Concept (PoC) exploits, significantly increasing the likelihood of real-world attacks.  A total of 200 vulnerabilities were rated critical under CVSS v3.1, while 61

The Week in Vulnerabilities: Juniper, Cisco SD-WAN, and Critical ICS Exposure Read More »

Open-source security debt grows across commercial software

Open-source security debt grows across commercial software 2026-02-26 at 08:36 By Mirko Zorz Open source code sits inside nearly every commercial application, and development teams continue to add new dependencies. Black Duck’s 2026 Open Source Security and Risk Analysis Report data shows that nearly all audited codebases contain open source components, with average component counts

Open-source security debt grows across commercial software Read More »

The Week in Vulnerabilities: WordPress, BeyondTrust, and Critical ICS Bugs

The Week in Vulnerabilities: WordPress, BeyondTrust, and Critical ICS Bugs 2026-02-25 at 15:20 By Ashish Khaitan Cyble Research & Intelligence Labs (CRIL) tracked 1,102 vulnerabilities last week. Of these, 166 vulnerabilities already have publicly available Proof-of-Concept (PoC) exploits, significantly increasing the likelihood of real-world attacks. A total of 49 vulnerabilities were rated critical under CVSS v3.1, while 32 received critical

The Week in Vulnerabilities: WordPress, BeyondTrust, and Critical ICS Bugs Read More »

The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure

The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure 2026-02-19 at 14:07 By Ashish Khaitan Cyble Research & Intelligence Labs (CRIL) tracked 1,158 vulnerabilities last week. Of these, 251 vulnerabilities already have publicly available Proof-of-Concept (PoC) exploits, significantly increasing the likelihood of real-world attacks.  A total of 94 vulnerabilities were rated critical under CVSS v3.1, while 43 were rated

The Week in Vulnerabilities: SolarWinds, Ivanti, and Critical ICS Exposure Read More »

The hidden cost of putting off security decisions

The hidden cost of putting off security decisions 2026-02-06 at 08:01 By Help Net Security In this Help Net Security video, Hanah Darley, Chief AI Officer, Geordie AI, talks about how putting off security risk decisions creates long-term costs that often stay hidden. Drawing on her work with CISOs and security leaders, she shows how

The hidden cost of putting off security decisions Read More »

CISA confirms exploitation of VMware ESXi flaw by ransomware attackers

CISA confirms exploitation of VMware ESXi flaw by ransomware attackers 2026-02-05 at 18:17 By Zeljka Zorz CVE-2025-22225, a VMware ESXi arbitrary write vulnerability, is being used in ransomware campaigns, CISA confirmed on Wednesday by updating the vulnerability’s entry in its Known Exploited Vulnerabilities (KEV) catalog. Researchers linked VMware ESXi zero-day trio to single exploit toolkit

CISA confirms exploitation of VMware ESXi flaw by ransomware attackers Read More »

Nullify Secures $12.5 Million in Seed Funding for Cybersecurity AI Workforce

Nullify Secures $12.5 Million in Seed Funding for Cybersecurity AI Workforce 2026-02-05 at 15:02 By Eduard Kovacs This latest infusion, led by SYN Ventures, brings the company’s total funding to $16.9 million. The post Nullify Secures $12.5 Million in Seed Funding for Cybersecurity AI Workforce appeared first on SecurityWeek. This article is an excerpt from

Nullify Secures $12.5 Million in Seed Funding for Cybersecurity AI Workforce Read More »

RapidFort Raises $42M to Automate Software Supply Chain Security

RapidFort Raises $42M to Automate Software Supply Chain Security 2026-02-03 at 17:01 By Eduard Kovacs The company will use the latest capital to scale its go-to-market efforts and expand its platform’s capabilities. The post RapidFort Raises $42M to Automate Software Supply Chain Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

RapidFort Raises $42M to Automate Software Supply Chain Security Read More »

The Week in Vulnerabilities: Open-Sources Fixes Urged by Cyble

The Week in Vulnerabilities: Open-Sources Fixes Urged by Cyble 2026-02-03 at 15:15 By Ashish Khaitan Cyble Vulnerability Intelligence researchers tracked 1,147 vulnerabilities in the last week, and more than 128 of the disclosed vulnerabilities already have a publicly available Proof-of-Concept (PoC), significantly increasing the likelihood of real-world attacks.  A total of 108 vulnerabilities were rated as critical under the CVSS v3.1 scoring system, while 54 received a critical severity rating

The Week in Vulnerabilities: Open-Sources Fixes Urged by Cyble Read More »

Open-source attacks move through normal development workflows

Open-source attacks move through normal development workflows 2026-02-03 at 08:18 By Anamarija Pogorelec Software development relies on a steady flow of third-party code, automated updates, and fast release cycles. That environment has made the software supply chain a routine point of entry for attackers, with malicious activity blending into normal build and deployment processes. A

Open-source attacks move through normal development workflows Read More »

Aisy Launches Out of Stealth to Transform Vulnerability Management

Aisy Launches Out of Stealth to Transform Vulnerability Management 2026-01-30 at 17:19 By Kevin Townsend Aisy has emerged from stealth mode with $2.3 million in seed funding for its AI-assisted platform. The post Aisy Launches Out of Stealth to Transform Vulnerability Management appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Aisy Launches Out of Stealth to Transform Vulnerability Management Read More »

Scroll to Top