Content Paint

vulnerabilities

NIST asks industry what to do about AI and vulnerabilities

National Vulnerability Database is due for further modernisation after cuts to CVE enrichment programme.

MSPs at risk amid ongoing N-Central “active incident”

"Anauthenticated administrative account takeover" ftw, with attackers gaining persistence

OpenAI has tough questions to answer on Hugging Face attack

'We can't build a secure sandbox nor monitor our own model tests properly' is not a flex - and Hugging Face's Thomas Wolf has views

Cursor says seven-month unresolved bug is not its responsibility

"Issues that depend on compromised or malicious inputs already present in that context generally fall outside our bug bounty scope."

Gold Eagle: White House announces new vuln system… a lot like the old one

So far, the Gold Eagle vulnerability clearing house seems to be CISA with some extra bits.

Critical "Gitea" vulnerability exploited

"User access on a Gitea box isn't "a web panel," it's your source code"

Citrix credits JPMorgan, pushes fixes for six ugly NetScaler bugs

watchTowr also credited after letting “our small pets walk across our keyboard, and watching what happens.”

nissan data breach

Bug was exploited as a zero day for two weeks before a patch landed

AWS's latest security tool will prioritise bugs before patching

AWS Continuum promises "machine speed" remediation for the post-Mythos era.

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.