Vulnerabilities and CVEs VMware patches a VM escape and two critical vCenter flaws
VMSA-2026-0006 fixes VM escape CVE-2026-47876 and two critical vCenter flaws. Review versions, priorities, detection and rollout.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs VMSA-2026-0006 fixes VM escape CVE-2026-47876 and two critical vCenter flaws. Review versions, priorities, detection and rollout.
Vulnerabilities and CVEs A critical Fastjson 1.x flaw enables remote code execution even with AutoType disabled. Learn the attack conditions, SafeMode mitigation and response plan.
AI Security Grafana has made gcx and its MCP server generally available, giving coding agents structured access to metrics, logs, alerts and dashboards.
Threats and Incidents A coordinated cyberattack reached technology at more than 30 Minnesota water systems. We separate confirmed impact from speculation and outline OT/SCADA priorities.
Threats and Incidents Kaspersky uncovered new Mirage Kitten tools: the NightLedger backdoor and ArcBridge and BridgeHead tunnelers. We analyse the techniques and detection.
AI Security Alibaba Cloud unveiled Agent Native Cloud — sandboxes, workload isolation and identity for agents. What it means for securing agentic deployments.
AI Security The EU AI Omnibus took effect on 27 July 2026. We explain new high-risk deadlines, deepfake rules, sandboxes, business duties and a compliance plan.
Vulnerabilities and CVEs A public exploit runs commands as git on unpatched GitLab 18.11.3 servers. The fix shipped as a bugfix, with no CVE. Analysis and lessons.
Threats and Incidents Sysdig documented JadePuffer — the first ransomware attack carried out end to end by an LLM agent. We analyse the chain and what defenders should do.
AI Security Microsoft unveiled Project Perception, joining red, blue and green-team agents. We examine its design, reported results, risks and safe SOC adoption.
Vulnerabilities and CVEs Node.js announced HIGH-severity fixes for the 26, 24 and 22 release lines. Here is what is confirmed, what remains undisclosed and how to patch safely.
AI Security OpenAI analysed 800,000 messages to measure task crossover. We examine the results, limitations and implications for skills, security and AI governance.
Threats and Incidents Spirals ransomware encrypted an IT firm's network in under 24 hours. We break down the attack timeline and show where it could have been stopped.
AI Security Anthropic released the Claude Security Plugin in beta — a multi-agent vulnerability scanner for Claude Code. How it works, where it helps, what it won't replace.
Vulnerabilities and CVEs Two CVSS 9.1 flaws in FortiSandbox let an unauthenticated attacker run OS commands. Both are in CISA KEV. Analysis, detection and remediation.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.