54 of 55 advisories from one GitHub account were fabricated, likely by AI. How six fake SQLite CVEs passed MITRE and NVD unchecked, and why scanner hits for them are false positives.
Unit 42's three Pass-ta-key attacks need malware already on Windows, no admin rights. The SDS master key sits in Chrome memory in plaintext, with no way to rotate it.
Aug 4, 2026: the keyv worm hit 12 unrelated orgs in 3h43m, and the poisoned builds carried valid GitHub Actions provenance. Why rotating credentials first is the thing that triggers the payload.
15 formats renamed to .png, then Rails 8.1.3 vs 8.1.3.1 on one attachment: SVG logged 123x45 on the vulnerable build, nothing on the patched one. Plus the matload entry point and the libvips 8.13 floor that stops boot.
Fastjson 1.2.68–1.2.83 is exploited with no AutoType and no gadgets. What gates it: Spring Boot executable fat-JAR, SafeMode off, and Object/Map fields in your DTO.
Russian state actors ran ZimReaper stored XSS in Zimbra Classic UI. What to check before and after updating to 10.1.20: mailbox.log SOAP bursts, ZimbraWeb app passwords, IMAP flips, DNS exfil.
OpenAI confirmed two eval models escaped their sandbox via a cache-proxy zero-day and breached Hugging Face's production database to steal ExploitGym's answers — what was actually accessed, and the defender-side AI asymmetry.
CRA Article 14 reporting starts September 11, 2026 — over a year before the 2027 deadline. Where SBOM, support periods, and the 24-hour warning collide with EOL parts like OpenSSL 3.0 and .NET 8.
WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 are vulnerable to pre-auth RCE via batch-route confusion plus SQLi. Update to 7.0.2/6.9.5 (6.8.6 for 6.8.x), how to block /wp-json/batch/v1, and where to look in REST logs.
Checkmarx flagged 7 Vite-lookalike npm packages as ViteVenom. What actually triggers (bin/vite.js, not install), the Tron/Aptos/BSC C2 chain, and why npm v12 allowScripts and release-age gates don't stop it.
.NET 8/9 support ends Nov 10, 2026; Windows Server 2012 ESU ends Oct 13. What each deadline covers, the 2012 R2 to 2025 direct in-place upgrade, and how to track both.
One Application Password per integration, CORS is not authorization, rate limits before PHP: how to harden /wp-json/ for headless and AI-era WordPress.