Common Vulnerabilities and Exposures (CVE) stories
FIRST conference highlights AI & CVE disclosure push
Today
#
iot security
#
application security
#
supply chain
FIRST conference in Scottsdale draws 500-plus as security leaders and AI firms debate vulnerability disclosure, CWE's role and CVE's future.
Splashtop launches unified IT platform for endpoints
3 days ago
#
endpoint protection
#
digital transformation
#
it automation
Splashtop bets on AI-assisted patching and security alerts in a single console as it targets lean IT teams and MSPs with a new endpoint platform.
Forrester says Anthropic AI could break patch playbook
4 days ago
#
hybrid cloud
#
digital transformation
#
application security
Forrester warns Anthropic's Project Glasswing could overwhelm vulnerability management, as AI uncovers flaws faster than patching teams can respond.
Intruder adds container image scanning to cloud platform
Last week
#
virtualisation
#
devops
#
hybrid cloud
Intruder expands cloud security platform with registry-level container image scanning for AWS, Google Cloud and Azure users.
2N urges tougher cyber rules for access control devices
Last week
#
edutech
#
data protection
#
hyperscale
2N calls for tougher cyber rules on access control, urging stronger vulnerability reporting, tighter component sourcing and longer support lifecycles.
Qualys warns attackers exploit flaws before disclosure
Last week
#
firewalls
#
vpns
#
network security
Qualys says attackers are exploiting flaws before disclosure as remediation backlogs swell, with edge devices facing the highest risk.
Percona & Chainguard launch supported database images
Last month
#
virtualisation
#
devops
#
digital transformation
Percona teams up with Chainguard to offer supported, hardened container images for MySQL, PostgreSQL and MongoDB databases.
Open source use rises as firms shun vendor lock-in
Last month
#
devops
#
hybrid cloud
#
digital transformation
Concern over vendor lock-in is driving a global surge in open source adoption, with European organisations leading the shift to digital autonomy.
Rapid7 warns exploited software flaws more than double
Last month
#
firewalls
#
ransomware
#
network security
Rapid7 warns exploited high and critical software flaws more than doubled in 2025, as attackers compress disclosure-to-attack windows.
FIRST announces 2026 cyber security conference trio
Last month
#
application security
#
advanced persistent threat protection
#
socs
FIRST to host three cybersecurity conferences in 2026 as it predicts annual CVE disclosures will surpass 50,000 for the first time.
GitHub backs Alpha-Omega with fresh open source funds
Last month
#
siem
#
hyperscale
#
application security
GitHub joins tech giants in a USD $12.5 million Alpha-Omega push, boosting AI-powered defences for critical open source software.
Microsoft patches major SQL Server flaw in March update
Last month
#
firewalls
#
network security
#
mfa
Microsoft's March Patch Tuesday fixes 77 flaws, including a severe SQL Server bug that could grant attackers sysadmin rights remotely.
Wireless CVEs surge, exposing hidden risks for AI centres
Last month
#
uc
#
firewalls
#
surveillance
Wireless flaws have surged 230-fold since 2010, as Bastille warns AI data centres and critical infrastructure face escalating unseen risks.
AI-driven phishing surge as Acronis warns MSPs at risk
Fri, 20th Feb 2026
#
malware
#
ransomware
#
cloud security
Acronis warns AI is turbocharging phishing, email attacks and ransomware in 2025, with MSPs and collaboration tools under rising fire.
Simbian unveils AI agent for continuous pentesting
Fri, 20th Feb 2026
#
data protection
#
devops
#
application security
Simbian launches an AI Pentest Agent that runs continuous, adaptive penetration tests, promising faster, context-aware vulnerability detection.
Data-only extortion surges as remote access abused
Wed, 18th Feb 2026
#
data protection
#
dr
#
vpns
Data-only extortion soars 11-fold as attackers 'log in instead of break in', abusing remote access tools for faster, stealthier raids.
Cybersecurity teams brace for surge in global CVEs in 2026
Thu, 12th Feb 2026
#
siem
#
cloud security
#
socs
Cyber group FIRST warns CVE disclosures could smash records in 2026, topping 50,000 and potentially surging towards six figures.
New ENCS-DIVD pact targets energy cyber weaknesses
Thu, 5th Feb 2026
#
devops
#
iot security
#
iot
ENCS and DIVD have agreed a new cyber pact to uncover and disclose vulnerabilities in Europe's high-impact energy and critical systems.
Black Kite unveils tool to analyse third-party software risk
Thu, 8th Jan 2026
#
saas
#
supply chain
#
risk & compliance
Black Kite launches Product Analysis tool to expose hidden risks in third-party software, from SaaS subdomains to SBOM dependencies.
Codific predicts nine key cybersecurity shifts for 2026
Wed, 24th Dec 2025
#
data protection
#
digital transformation
#
encryption
Codific sees 2026 cybersecurity shaped by shadow AI, passwordless logins, tighter regulation and a sharper focus on software supply chains.