NVIDIA fixed 114 CVEs across GPU display drivers and vGPU. GeForce users need 616.56 (R615), 610.88 (R610), or 582.78 (R580). Here is how to verify versions.
Hacktron AI disclosed a 72-hour exploit chain reaching OpenAI's internal monorepo openai/openai: a silent upstream fix in libheif, ASLR bypass via Claude Opus 5, and an OpenAI SSO identity flaw allowing ChatGPT/Codex account takeovers.
CVE-2026-82079 affects Nintendo Switch systems before 23.0.0. Exploitation requires a malicious third party to directly scan a QR code shown by Album or Mario Kart Live: Home Circuit; update to 23.0.0.
MITRE added CWE-1427 for improper neutralization in LLM prompting. Why SQLi-style escaping fails on natural language, and how Dual-LLM and guardrails stop attacks.
NVIDIA fixed a CVSS 9.0 container escape (CVE-2024-0132) in Container Toolkit 1.16.2. How TOCTOU symlinks expose the host root filesystem, and how CDI eliminates it.
862-bit RSA-260 fell on September 3, 2026 after 35 years. I verified the posted factor in Python on an M4 Mac mini, traced the viral 'seven months by hand' story to a joke, and sized the compute from RSA-250's 2,700 core-years with the GNFS formula.
Probes for percent-encoded traversal hit the cohttp maintainer's logs 10 minutes after the fix PR opened. Mandiant now puts mean time-to-exploit at -7 days, VulnCheck's data disagrees.
Checked August 17, 2026 via the GitHub Advisory Database API: all six fake SQLite CVEs rejected by MITRE still show CVSS up to 9.8 as type unreviewed, withdrawn_at null.
WordPress 7.0.3 (Aug 6, 2026) closes CVE-2026-64638 / XSS2Shell (CVSS 8.9): a whitespace tag like `< area` slips past strip_tags but KSES restores it, giving pre-auth login XSS that chains to PHP RCE. All versions affected; fix backported to 4.7.
54 of 55 advisories from one GitHub account were fabricated, likely by AI. How six fake SQLite CVEs passed MITRE and NVD unchecked, and why scanner hits for them are false positives.
Unit 42's three Pass-ta-key attacks need malware already on Windows, no admin rights. The SDS master key sits in Chrome memory in plaintext, with no way to rotate it.
Aug 4, 2026: the keyv worm hit 12 unrelated orgs in 3h43m, and the poisoned builds carried valid GitHub Actions provenance. Why rotating credentials first is the thing that triggers the payload.