Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksNothing here is ranked by paymentHelp & FAQAPI

Vendor news

Releases, funding, leadership changes and incidents across the vendors in this catalog — collected automatically from vendors' own public feeds.Where this comes fromEvery item links to the vendor's own published source: a GitHub release feed, a changelog, a status page, an SEC filing or a company blog. Nothing here is written or editorially reviewed by 0-Doubt, and nothing is a recommendation — it is machine-collected public record, labelled the same way as all other baseline content on the platform. Coverage is uneven by design: a vendor that publishes no public feed will not appear, and that absence is not a judgement about the vendor.

AllNew capability 352Release 343Incident 226Leadership 43Funding 30Announcement 10849AnnouncementsEverything the classifier could not read as a release, funding round, leadership change, incident or new capability lands in Announcement — in practice mostly vendor blog and marketing posts, and about nine in ten of everything collected. It is filterable here, but deliberately kept out of the default view rather than mixed in, so the feed you land on is not ninety percent marketing.

994 matching stories — showing up to 3 per vendorPer-vendor capWhile browsing, no single vendor may fill more than three slots on any one page, so a vendor with a chatty release cadence cannot buy the page you are looking at. That means a page can render fewer stories than the count above. Searching a headline or naming a vendor turns the cap off, because then you have asked to see everything that matches.

Funding

Alice Raises $140M for AI Trust, Safety, and Security

Trusted by Anthropic, Google, and Cohere, Alice brings nearly a decade of real-world adversarial intelligence to frontier AI — and is approaching $100M in ARR.

Alice·Vendor blog·Aug 25, 2026
Release

Ubiquiti's SAB-067: 22 UniFi Vulnerabilities, Three Rated CVSS 10.0, and a Patch Cycle MSPs Can't Outrun Alone

Ubiquiti's latest security bulletin patches 22 UniFi vulnerabilities, three of them maximum severity. For MSPs managing UniFi fleets across dozens of client sites, the patch cycle takes days. Here's what to do while it runs.

Vijilan·Vendor blog·Aug 28, 2026
New capability

Introducing JFrog Preview: Getting New Capabilities Into Your Hands, Faster

TLDR: “Preview” isn’t a lightweight version of GA, and it isn’t a beta with a new name on it. It just changes the timing and access. You’ll see new JFrog capabilities the day they’re ready for real use, not the day they’re ready for a press release. We’re starting at swampUP 2026. As we know, …

JFrog·Vendor blog·Aug 28, 2026
New capability

Antiy AVL SDK Anti-Virus Engine Upgrade Announcement (20260829)

Based on the principles of transparency, accessibility, usability, verifiability and perceptibility of security capabilities, Antiy releases weekly updates of the AVL SDK anti-virus engine and the full set of capabilities to the public every week. 1.Weekly Update                            Statistical period: August 22, 2026 ~ August 28, 2026 Antiy AVL SDK anti-v

← Newer
  1. 1
  2. 2
  3. 3
  4. …
  5. 7
Older →
Antiy Labs·Vendor blog·Aug 28, 2026
Release

Customize the reverification window

Clerk·Changelog·Aug 28, 2026
Release

Tenzir Platform v1.39.0: Explorer Usability Improvements

This release makes working with data in the Explorer easier: browse stored schemas, use field actions in more places, preview value frequencies, plus new view options in the Stream view and custom time field selection. It also ships various fixes and security updates under the hood.

Tenzir·Changelog·Aug 28, 2026
Incident

CVE-2026-81934: Redis-Schwachstelle in der TLS-Datenverarbeitung

CVE-2026-81934 betrifft Redis-Instanzen mit TLS-Konfiguration. Bereinigte Releases stehen für mehrere Redis-Branches bereit. The post CVE-2026-81934: Redis-Schwachstelle in der TLS-Datenverarbeitung appeared first on LocateRisk.

LocateRisk·Vendor blog·Aug 27, 2026
Incident

PaperCut Software vulns: CVE-2026-81578, CVE-2026-82078

Certain versions of PaperCut NG and PaperCut MF are affected by two vulnerabilities. Here's how to find impacted assets with runZero.

runZero·Vendor blog·Aug 27, 2026
New capability

uRISQ® Expands into Commercial Security Channel to Help Dealers and Integrators Deliver Privacy Regulatory Compliance Solutions

New initiative enables security providers to extend their trusted customer relationships while creating new recurring revenue opportunities. JENSEN BEACH, Fla. — August […] The post uRISQ® Expands into Commercial Security Channel to Help Dealers and Integrators Deliver Privacy Regulatory Compliance Solutions appeared first on CSR Privacy Solutions.

CSR Privacy Solutions·Vendor blog·Aug 27, 2026
New capability

eXate and IBM Sovereign Core Announce a Validated Golden Pattern for Boundary-Controlled Data Flow

eXate and IBM Sovereign Core have announced a validated golden pattern for Sovereign Boundary Control, pairing IBM's sovereign infrastructure with eXate's geo-aware data tagging and context-aware entitlements. Together they govern how data crosses sovereign boundaries — closing the gap between data residency and real data-level control, a discipline that matters even more as sovereign AI scales.

eXate·Vendor blog·Aug 27, 2026
Release

SonarQube Hunter Agent is now GA: Catch broken access control and business logic flaws

SonarQube Hunter Agent uses AI to detect broken access control, business logic flaws, and authentication vulnerabilities traditional SAST can miss.

Sonar·Vendor blog·Aug 27, 2026
New capability

Introducing The First NHI MCP Server: AI Powered, Smarter, Driving Fast Remediation | Token Security

Token Security launches the first NHI MCP Server — an AI-powered interface giving security teams intelligent visibility & fast automated remediation across all machine identities.

Token Security·Vendor blog·Aug 27, 2026
Incident

Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE

Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE A critical vulnerability chain tracked as CVE-2026-18431 affects the Avada WordPress theme and its required Fusion Builder plugin, now branded as Avada Builder .

SOCRadar Cyber Intelligence Inc.·Vendor blog·Aug 27, 2026
Release

New Mail Assure Releases: Turning Email Security Signals into Faster Business Decisions

A single pricing mistake, like charging per-device in a remote-first environment where every user carries three endpoints, can cut your margin fast. The way a managed service provider (MSP) charges for managed services shapes everything downstream: margins, scalability, how many clients you can take on without burning out your team, and whether monthly revenue holds up when the next vendor price increase lands. Get it wrong and every contract drains resources; get it right and recurring revenue

N-able·Vendor blog·Aug 27, 2026
Release

Changelog - August 27, 2026

This week's Corgea changelog post focuses on broader webhook coverage, richer SARIF exports for SCA findings, and private package registry support from the latest public releases in Corgea Docs.

Corgea·Vendor blog·Aug 27, 2026
New capability

Introducing OttoFlow: AI Workflows for Kubernetes

Nirmata·Vendor blog·Aug 26, 2026
New capability

Introducing Enzo by Token Security: The AI-Native Identity Security Application Builder for Creating Live Security Applications | Token Security

Token Security·Vendor blog·Aug 26, 2026
Incident

Zimbra CVE-2026-73570 Exploited: Why Patching Isn't the Finish Line

CVE-2026-73570 is an unauthenticated Zimbra RCE under active exploitation and now on CISA's KEV list. Patching closes the door, but it doesn't tell you who already walked through it.

Vijilan·Vendor blog·Aug 26, 2026
Release

CISA Releases Guidance to Help Organizations Secure Agentic AI. The Need to Rethink Your Defenses Is Urgent | Token Security

Token Security·Vendor blog·Aug 26, 2026
Incident

CVE-2026-60004: Critical Gitea RCE Exploited to Deploy Miner-Like Payloads

A critical remote code execution vulnerability in Gitea has moved from disclosure to active exploitation less than a month after a patch became available. Tracked as CVE-2026-60004 and rated 9.8 on the CVSS scale, the flaw allows an attacker with ordinary repository write access to plant an executable Git hook and run arbitrary shell commands […] The post CVE-2026-60004: Critical Gitea RCE Exploited to Deploy Miner-Like Payloads appeared first on SOC Prime.

SOC Prime·Vendor blog·Aug 26, 2026
New capability

Theta Lake Announces AI Interaction Governance Integration with CrowdStrike Falcon® Next-Gen SIEM

Santa Barbara, CA – August 26, 2026 (Business Wire) – Theta Lake today announced a new integration that enables AI interaction governance telemetry from Theta Lake to flow into CrowdStrike Falcon® Next-Gen SIEM. As organizations increasingly adopt AI assistants and agentic...

Theta Lake·Vendor blog·Aug 26, 2026
New capability

Introducing OWASP OASIS: AI Fixes, Community Validated

Global initiative fights AI with AI and application security community expertise, validating and implementing AI-generated fixes to remediate open source vulnerabilities at scale SAN FRANCISCO, CA — August 26, 2026

AppSecAI·Vendor blog·Aug 26, 2026
Incident

CVE-2026-64849: SSRF-Sicherheitslücke in MLflow wird aktiv ausgenutzt

CVE-2026-64849 (CVSS 9,3, EPSS ≥ 95. Perzentil) ist eine als kritisch eingestufte, nicht authentifizierte, serverseitige Request-Forgery-Schwachstelle (SSRF) [CWE-918] bei der MLflow-Webhook-Übermittlung. Die CVE betrifft alle Versionen vor 3.15.0. Die Hauptursache ist eine fehlerhafte Umleitungsverarbeitung und DNS-Rebinding. Die Schwachstelle wird durch Umgehung der Schutzmaßnahmen _validate_webhook_url in der Standardkonfiguration des MLflow-Tracking-Servers ausgenutzt. Die CISA hat CVE-2026-

Greenbone AG·Vendor blog·Aug 26, 2026
Funding

The Future of Security is “Identity” Integrity360 acquires IAM specialist CyberIAM

…

CyberIAM·Vendor blog·Aug 26, 2026
New capability

Introducing SecureTransit: Endpoint Privacy, Enforced as Policy

 

DNSFilter·Vendor blog·Aug 26, 2026
New capability

Aikido launches agentic pentesting for Android apps

Aikido's agents pentest your Android app and its backend in a single whitebox assessment. You get reproducible findings, AutoFix, and retests for every issue. Category: Product & Company Updates

Aikido Security·Vendor blog·Aug 26, 2026
New capability

Aikido launches agentic pentesting for Android apps

Aikido's agents pentest your Android app and its backend in a single whitebox assessment. You get reproducible findings, AutoFix, and retests for every issue. Category: Product & Company Updates

Root.io·Vendor blog·Aug 26, 2026
New capability

Introducing Governance Hub: Intelligent, account-level governance over your Databricks estate

Your FinOps lead needs to easily drill-down into Databricks spend and identify what’s driving costs, ...

Databricks·Vendor blog·Aug 26, 2026
Incident

CVE-2026-55663: mediasoup SCTP state-cookie forgery

Fresh 25 August 2026 NVD publication for `CVE-2026-55663` shows the npm package `mediasoup` and Rust crate `mediasoup` trusted fixed SCTP State Cookie markers (`msworker`, `0xAD81`) instead of a secret-keyed MAC. On `PlainTransport` or `PipeTransport` with SCTP enabled, an on-path attacker could forge `COOKIE-ECHO`, establish an unauthorized association, and inject DataChannel messages as a trusted peer.

Corgea·Vendor blog·Aug 26, 2026
Release

User Groups

Manage user groups in the dashboard: create groups, add and remove members, and assign roles to all users of a group at once.

WorkOS·Changelog·Aug 26, 2026
Release

Fewer lockouts, less manual work: What's new for 1Password EPM admins

As a company grows, more employees join, but the size of the IT team overseeing critical systems often doesn’t grow at the same pace. Admins have to be intentional about prioritizing their efforts to meet the needs of a growing organization. That’s why we’re excited to announce several releases aimed at helping admins optimize their organization’s use of 1Password in two important areas: reducing lockouts and automating provisioning at scale. Preventing avoidable lockouts Entra ID Secret Expirat

1Password·Vendor blog·Aug 26, 2026
Release

Tenzir Node v6.14.0: Statistical models for distribution drift

Tenzir now lets you build, store, merge, and compare statistical models in TQL to detect distribution drift across pipelines and time windows. The release also adds session windows, bounded event-time reordering, preceding-event access, native Splunk HEC ingestion, and more self-contained container and Python deployments.

Tenzir·Changelog·Aug 26, 2026
New capability

ThreatMon Launches National Cyber Defence: Country-Wide Cyber Intelligence for Governments and National CERTs

ThreatMon ThreatMon, the AI-powered end-to-end risk intelligence platform, today announced the launch of National Cyber Defence, a new country-wide cyber intelligence solution designed to help governments, national CERTs, CSIRTs, and cybersecurity agencies gain continuous visibility into their nation’s digital attack surface, critical infrastructure, cyber exposure, and evolving threat landscape. As cyber threats increasingly target not […] The post ThreatMon Launches National Cyber Defenc

ThreatMon·Vendor blog·Aug 25, 2026
New capability

Introducing Zoho connected apps for Google Gemini

Note: Now available to organizations in the Indian data center. Support for other Zoho data centers will be available soon.AI assistants have gotten remarkably good at writing, summarizing, and reasoning, but ask one which deals are stalling in your pipeline—or to draft a reply to an urgent support ticket—and it can hit a wall.It's not because...

Zoho Corporation·Vendor blog·Aug 25, 2026
Leadership

Horizon3 Names Chad Keefer Vice President of Federal Sales

Horizon3 appoints federal go-to-market veteran Chad Keefer as Vice President of Federal Sales to lead growth across civilian, defense, and intelligence agencies.

Horizon3.ai·Vendor blog·Aug 25, 2026
Incident

Patching mcp-remote Is the Easy Part: The Harder Lesson of CVE-2025-6514

The critical mcp-remote RCE (CVE-2025-6514, CVSS 9.6) exposes how AI clients over-trust MCP servers — see what identity-first Zero Trust reachability would have stopped. The post Patching mcp-remote Is the Easy Part: The Harder Lesson of CVE-2025-6514 appeared first on NetFoundry.

NetFoundry·Vendor blog·Aug 25, 2026
New capability

Introducing Vault Enforcement: Close the Adoption Gap on Your Terms

Now in open beta, Vault Enforcement drives password manager adoption by requiring vault login on your organization’s riskiest accounts. The post Introducing Vault Enforcement: Close the Adoption Gap on Your Terms appeared first on Dashlane Blog

Dashlane·Vendor blog·Aug 25, 2026
Release

ExtraHop® Closes Enterprise Data Center Blind Spots with the First NDR Platform to Run at 400 Gbps

Full-fidelity context at line rate gives autonomous agents the rapid evidence needed to match machine-speed attacks with machine-speed defense

ExtraHop·Changelog·Aug 25, 2026
New capability

CYBRAL Launches CYBRAL ONE: The Agentic AI Platform That Protects Data and Stops Cyberattacks Before They Happen, Continuously and at AI Speed

New conversational, agentic AI platform unifies data security, attack surface management, and attack-path mapping into a single system that reasons, decides, and acts at machine speed — before a breach can occur. MIAMI, FL — August 25, 2026 — CYBRAL today announced the launch of CYBRAL ONE, an agentic AI platform built to help enterprises and small organizations move from reactive defense to pre-emptive cybersecurity. Simple to operate and requiring no technical expertise, CYBRAL ONE gives...

Cybral·Vendor blog·Aug 25, 2026
New capability

MAGECART TURNS TRUSTED GTM INTO A LAUNCHPAD FOR SMARTER SKIMMERS

Magecart Turns Trusted GTM Into a Launchpad for Smarter Skimmers Payment-skimming attacks are continuing to abuse Google Tag Manager (GTM) as a trusted path into checkout pages, while changing what happens after the malicious code reaches the browser. Recent findings included chained GTM containers, payload delivery through Google Firestore, long-running campaigns rotating through new containers, The post MAGECART TURNS TRUSTED GTM INTO A LAUNCHPAD FOR SMARTER SKIMMERS appeared first on Source D

Source Defense·Vendor blog·Aug 25, 2026