vulnerability management

Open-source malware zeroes in on developer environments

Open-source malware zeroes in on developer environments 2026-01-29 at 08:36 By Anamarija Pogorelec Open source malware activity during 2025 concentrated on a single objective: executing code inside developer environments, according to Sonatype. The focus reflected a broader shift in supply chain attacks away from end users and toward the tools, machines, and pipelines used to […]

Open-source malware zeroes in on developer environments Read More »

The Week in Vulnerabilities: Cyble Urges Oracle, OpenStack Fixes

The Week in Vulnerabilities: Cyble Urges Oracle, OpenStack Fixes 2026-01-28 at 12:33 By Ashish Khaitan Cyble Vulnerability Intelligence researchers tracked 1,031 vulnerabilities in the last week, and nearly 200 already have a publicly available Proof-of-Concept (PoC), significantly increasing the likelihood of real-world attacks on those vulnerabilities.  A total of 72 vulnerabilities were rated as critical under the CVSS v3.1 scoring system, while 33 received a critical severity rating based on

The Week in Vulnerabilities: Cyble Urges Oracle, OpenStack Fixes Read More »

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever 2026-01-21 at 07:34 By Help Net Security Penetration testing has evolved significantly over the past several years. While uncovering exploitable vulnerabilities remains the core goal, the real differentiator today is how findings are handled after the testing concludes. The method of reporting,

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever Read More »

The Week in Vulnerabilities: 2026 Starts with 100 PoCs and New Exploits 

The Week in Vulnerabilities: 2026 Starts with 100 PoCs and New Exploits  2026-01-09 at 13:39 By Ashish Khaitan Cyble Vulnerability Intelligence researchers tracked 678 vulnerabilities in the last week, a decline from the high volume of new vulnerabilities observed in the last few weeks of 2025.   Nearly 100 of the disclosed vulnerabilities already have a publicly available Proof-of-Concept (PoC), significantly increasing the likelihood of real-world attacks on those vulnerabilities.  A total of 42 vulnerabilities were rated as critical under

The Week in Vulnerabilities: 2026 Starts with 100 PoCs and New Exploits  Read More »

Singapore Cyber Agency Warns of Critical IBM API Connect Vulnerability (CVE-2025-13915) 

Singapore Cyber Agency Warns of Critical IBM API Connect Vulnerability (CVE-2025-13915)  2026-01-06 at 10:01 By Ashish Khaitan Overview  The Cyber Security Agency of Singapore has issued an alert regarding a critical vulnerability affecting IBM API Connect, following the release of official security updates by IBM on 2 January 2026. The flaw, tracked as CVE-2025-13915, carries a CVSS v3.1 base score of 9.8, placing

Singapore Cyber Agency Warns of Critical IBM API Connect Vulnerability (CVE-2025-13915)  Read More »

CISA Known Exploited Vulnerabilities Surged 20% in 2025 

CISA Known Exploited Vulnerabilities Surged 20% in 2025  2026-01-02 at 14:43 By Ashish Khaitan The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added 245 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog in 2025, as the database grew to 1,484 software and hardware flaws at high risk of cyberattacks.  The agency removed at least one vulnerability from the catalog in 2025 – CVE-2025-6264, a Velociraptor Incorrect Default Permissions vulnerability that CISA determined had

CISA Known Exploited Vulnerabilities Surged 20% in 2025  Read More »

The Week in Vulnerabilities: The Year Ends with an Alarming New Trend 

The Week in Vulnerabilities: The Year Ends with an Alarming New Trend  2025-12-31 at 11:30 By Ashish Khaitan Cyble Vulnerability Intelligence researchers tracked 1,782 vulnerabilities in the last week, the third straight week that new vulnerabilities have been growing at twice their long-term rate.  Over 282 of the disclosed vulnerabilities already have a publicly available Proof-of-Concept (PoC), significantly increasing the likelihood of real-world attacks on those vulnerabilities.  A total of 207 vulnerabilities were rated as critical under the CVSS

The Week in Vulnerabilities: The Year Ends with an Alarming New Trend  Read More »

LLMs can assist with vulnerability scoring, but context still matters

LLMs can assist with vulnerability scoring, but context still matters 2025-12-26 at 08:26 By Sinisa Markovic Every new vulnerability disclosure adds another decision point for already stretched security teams. A recent study explores whether LLMs can take on part of that burden by scoring vulnerabilities at scale. While the results show promise in specific areas,

LLMs can assist with vulnerability scoring, but context still matters Read More »

The Week in Vulnerabilities: More Than 2,000 New Flaws Emerge 

The Week in Vulnerabilities: More Than 2,000 New Flaws Emerge  2025-12-23 at 14:47 By Ashish Khaitan Cyble Vulnerability Intelligence researchers tracked 2,415 vulnerabilities in the last week, a significant increase over even last week’s very high number of new vulnerabilities. The increase signals a heightened risk landscape and expanding attack surface in the current threat environment.  Over 300 of the disclosed vulnerabilities already have a publicly available Proof-of-Concept (PoC), significantly increasing the likelihood of real-world attacks. 

The Week in Vulnerabilities: More Than 2,000 New Flaws Emerge  Read More »

Why vulnerability reports stall inside shared hosting companies

Why vulnerability reports stall inside shared hosting companies 2025-12-17 at 09:24 By Mirko Zorz Security teams keep sending vulnerability notifications, and the same pattern keeps repeating. Many alerts land, few lead to fixes. A new qualitative study digs into what happens after those reports arrive and explains why remediation so often stops short. The research

Why vulnerability reports stall inside shared hosting companies Read More »

Dux Emerges From Stealth Mode With $9 Million in Funding

Dux Emerges From Stealth Mode With $9 Million in Funding 2025-12-17 at 09:24 By Ionut Arghire The startup takes an agentic approach to preventing vulnerability exploitation by uncovering exposure across assets. The post Dux Emerges From Stealth Mode With $9 Million in Funding appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Dux Emerges From Stealth Mode With $9 Million in Funding Read More »

The Week in Vulnerabilities: Cyble Tracks New ICS Threats, Zero-Days, and Active Exploitation

The Week in Vulnerabilities: Cyble Tracks New ICS Threats, Zero-Days, and Active Exploitation 2025-12-16 at 11:38 By Ashish Khaitan Last week’s reports from Cyble Research & Intelligence Labs (CRIL) to clients highlighted new flaws from December 03 through December 09, 2025, including newly disclosed IT vulnerabilities, ICS vulnerabilities, active exploitation attempts, and dark-web discussions around weaponized CVEs. Drawing from CISA alerts, CRIL’s global sensor network, and Cyble’s vulnerability intelligence

The Week in Vulnerabilities: Cyble Tracks New ICS Threats, Zero-Days, and Active Exploitation Read More »

LLM vulnerability patching skills remain limited

LLM vulnerability patching skills remain limited 2025-12-11 at 08:47 By Sinisa Markovic Security teams are wondering whether LLMs can help speed up patching. A new study tests that idea and shows where the tools hold up and where they fall short. The researchers tested LLMs from OpenAI, Meta, DeepSeek, and Mistral to see how well

LLM vulnerability patching skills remain limited Read More »

The Week in Vulnerabilities: Cyble Urges D-Link, React Server Fixes

The Week in Vulnerabilities: Cyble Urges D-Link, React Server Fixes 2025-12-10 at 08:53 By Ashish Khaitan Cyble Vulnerability Intelligence researchers tracked 591 vulnerabilities in the last week, and more than 30 already have a publicly available Proof-of-Concept (PoC), significantly increasing the likelihood of real-world attacks on those vulnerabilities.  A total of 69 vulnerabilities were rated as critical under the CVSS v3.1 scoring system, while 26 received a critical severity

The Week in Vulnerabilities: Cyble Urges D-Link, React Server Fixes Read More »

Zero-Day to Zero-Hour: React2Shell (CVE-2025-55182) Becomes One of the Most Rapidly Weaponized RSC Vulnerability 

Zero-Day to Zero-Hour: React2Shell (CVE-2025-55182) Becomes One of the Most Rapidly Weaponized RSC Vulnerability  2025-12-10 at 08:53 By Ashish Khaitan The vulnerability disclosure cycle has entered a new era, one where the gap between publication and weaponization is measured in minutes, not days. It has been confirmed that China-nexus threat actors began actively exploiting a critical React Server Components flaw, React2Shell,

Zero-Day to Zero-Hour: React2Shell (CVE-2025-55182) Becomes One of the Most Rapidly Weaponized RSC Vulnerability  Read More »

Fragmented tooling slows vulnerability management

Fragmented tooling slows vulnerability management 2025-11-28 at 07:32 By Anamarija Pogorelec Security leaders know vulnerability backlogs are rising, but new data shows how quickly the gap between exposures and available resources is widening, according to a new report by Hackuity. Fragmented detection and slow remediation Organizations use a formalized approach to manage vulnerabilities, but their

Fragmented tooling slows vulnerability management Read More »

Enterprises are losing track of the devices inside their networks

Enterprises are losing track of the devices inside their networks 2025-11-06 at 08:37 By Sinisa Markovic Security teams are often surprised when they discover the range and number of devices connected to their networks. The total goes far beyond what appears in agent-based telemetry or old manual asset inventories. Enterprise networks face broader exposure from

Enterprises are losing track of the devices inside their networks Read More »

VulnRisk: Open-source vulnerability risk assessment platform

VulnRisk: Open-source vulnerability risk assessment platform 2025-11-05 at 09:07 By Anamarija Pogorelec VulnRisk is an open-source platform for vulnerability risk assessment. It goes beyond basic CVSS scoring by adding context-aware analysis that reduces noise and highlights what matters. The tool is free to use and designed for local development and testing. The platform’s scoring engine

VulnRisk: Open-source vulnerability risk assessment platform Read More »

Product showcase: Cogent Community democratizes vulnerability intelligence with agentic AI

Product showcase: Cogent Community democratizes vulnerability intelligence with agentic AI 2025-11-03 at 18:13 By Help Net Security The volume of threat intelligence data has grown exponentially, but the ability to interpret and act on it has not. Every day brings new CVE disclosures, exploit releases, and vendor advisories. Teams are buried under overlapping feeds, inconsistent

Product showcase: Cogent Community democratizes vulnerability intelligence with agentic AI Read More »

SAP zero-day wake-up call: Why ERP systems need a unified defense

SAP zero-day wake-up call: Why ERP systems need a unified defense 2025-10-17 at 08:52 By Help Net Security In this Help Net Security video, Paul Laudanski, Director of Research at Onapsis, discusses key lessons from the SAP zero-day vulnerability. He explains why business-critical systems like ERP and CRM remain top targets for attackers, since they

SAP zero-day wake-up call: Why ERP systems need a unified defense Read More »

Scroll to Top