Supply Chain Security Rust: arrayref, internment and append-only-vec Ran Malware at Build Time
Three compromised crates.io releases executed a malicious build script. Understand the 86–107 minute window, Cargo cache, lockfiles, CI and response.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Supply Chain Security Three compromised crates.io releases executed a malicious build script. Understand the 86–107 minute window, Cargo cache, lockfiles, CI and response.
AI Security Spring AI 2.0.0 retains unlimited Streamable HTTP MCP sessions without authentication by default. Analyse DoS exposure, upgrades and resource budgets.
Vulnerabilities and CVEs SQL injection in Fleet's Okta integration and predictable iOS package URLs expose two endpoint-management trust boundary failures.
Vulnerabilities and CVEs Six codec-ohttp and Binary HTTP flaws cover parser loops, OOM, off-heap leaks, integer overflow and private HPKE key disclosure through logs.
Cloud, Infrastructure and DevSecOps CVE-2026-66785, 66787, 66788, 67567 and 73137 let a tenant or spoke redirect traffic, inject resources or exfiltrate Kubernetes secrets.
Threats and Incidents CISA and partners warn that AI-generated scripts are targeting Siemens S7 PLCs. A technical guide to S7comm exposure, detection, integrity and hardening.
AI Security CVE-2026-76832 escapes Agno's base_dir while CVE-2026-76850 abuses pickle in LMDeploy. We examine fixes, exposure and runtime isolation.
Vulnerabilities and CVEs Citrix fixed an authentication bypass and memory overflow in NetScaler ADC and Gateway. We explain SAML, SIP ALG, affected builds and HA rollout.
AI Security OpenAI is pairing frontier-model ZDR with private abuse-pattern detection. We analyse scope, the CSAM exception, customer keys and due-diligence questions.
Vulnerabilities and CVEs Three Splunk advisories dated 19 August cover 92 CVEs. We analyse RCE, unsafe deserialisation, SPL and SQL injection, roles and rollout priorities.
AI Security SkyWalking MCP 0.1.0 allowed a tool to change its backend URL and manipulate GraphQL. We analyse MCP boundaries, exposure and the 0.2.0 upgrade.
Vulnerabilities and CVEs Mozilla released Firefox 154 and new ESR builds with a substantial security package. We explain the major CVEs, enterprise exposure and rollout priorities.
AI Security OpenAI slowed frontier development after the Hugging Face incident and its Astra assessment. We examine sandboxes, CoT monitoring, cost and lab controls.
Vulnerabilities and CVEs Oracle's final bulletin contains 943 new fixes across databases, EBS, Middleware, Java and other products. Here is how to turn the matrix into a rollout plan.
Vulnerabilities and CVEs Apple released three major security updates on 17 August. We examine ImageIO, WebKit, Kernel and Telephony fixes and a practical MDM rollout plan.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.