Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
The CVE spike across major software companies is a remediation problem
2+ day, 18+ hour ago (854+ words) Advanced AppSec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats VC firm a16z just shared a chart that has exploded on X over the last few days. The chart shows critical and high CVEs jumping…...
The New Economics Of Software Security: Discovery Is Cheap; Response Isn't
1+ week, 4+ day ago (468+ words) Aaron Mitchell is CEO of HeroDevs, a company that provides Never-Ending Support for end-of-life open-source software. The recently released "Open Weights and American AI Leadership" letter has reignited the debate over whether increasingly capable open-weight AI models should remain broadly…...
Linux kernel nears record 2,000 vulnerabilities per release as AI bug hunters scour 40 million lines of code — maintainers say they are 'completely overwhelmed' by CVE finds
1+ week, 4+ day ago (150+ words) Tom's Hardware Maintenance teams are now fighting AI with AI This problem already constitutes a nuisance for kernel teams that have to fix these issues. In the Linux 7.3 networking pull request, maintainer Jakub Kicinski estimated that between one-third and one-half…...
Cosmos EVM Bug Cleared Before $5.7M Six-Chain Hack
1+ week, 6+ day ago (542+ words) Cosmos Labs says a critical Cosmos EVM vulnerability reported through its bug bounty programme in April was incorrectly judged not to affect production networks. Attackers exploited the vulnerability across six chains between August 20 and August 25, 2026. The activity moved about $2.87 million…...
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
2+ week, 1+ day ago (1013+ words) Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published…...
JetBrains told everyone to patch. It didn't patch itself.
2+ week, 1+ day ago (437+ words) JetBrains failed to patch its own TeamCity server, exposing its Cadence cloud service to attackers who accessed credentials, source code, and AWS accounts....
Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability (CVE-2026-64715)
2+ week, 4+ day ago (118+ words) CVE number – CVE-2026-64715 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file....
91 Vulnerabilities Patched in Spring Application Framework
2+ week, 5+ day ago (464+ words) The developers of Broadcom’s Spring application development framework last week announced the release of updates that patch 91 vulnerabilities. Spring is an open source application framework for the Java platform that simplifies the creation of enterprise applications through features such as…...
Besu Patches 5 Node Vulnerabilities: What Operators Must Know
2+ week, 6+ day ago (325+ words) Ethereum client Besu remediated five security vulnerabilities discovered by Certik in version 26.7.1, released July 27. Certik’s Jialiang Chang highlighted that the “patch-first, details-later” model protects node operators against immediate N-day exploits by allowing staging and rollout before attack details become public....
Besu patches 5 vulnerabilities in urgent 26.7.1 release
2+ week, 5+ day ago (23+ words) Besu issued urgent v26.7.1 to fix five vulnerabilities found by Certik; advisories were published after a patch-first delay. Node operators should upgrade now....