Alice Raises $140M for AI Trust, Safety, and Security
Trusted by Anthropic, Google, and Cohere, Alice brings nearly a decade of real-world adversarial intelligence to frontier AI — and is approaching $100M in ARR.
Releases, funding, leadership changes and incidents across the vendors in this catalog — collected automatically from vendors' own public feeds.Where this comes fromEvery item links to the vendor's own published source: a GitHub release feed, a changelog, a status page, an SEC filing or a company blog. Nothing here is written or editorially reviewed by 0-Doubt, and nothing is a recommendation — it is machine-collected public record, labelled the same way as all other baseline content on the platform. Coverage is uneven by design: a vendor that publishes no public feed will not appear, and that absence is not a judgement about the vendor.
994 matching stories — showing up to 3 per vendorPer-vendor capWhile browsing, no single vendor may fill more than three slots on any one page, so a vendor with a chatty release cadence cannot buy the page you are looking at. That means a page can render fewer stories than the count above. Searching a headline or naming a vendor turns the cap off, because then you have asked to see everything that matches.
Trusted by Anthropic, Google, and Cohere, Alice brings nearly a decade of real-world adversarial intelligence to frontier AI — and is approaching $100M in ARR.
Ubiquiti's latest security bulletin patches 22 UniFi vulnerabilities, three of them maximum severity. For MSPs managing UniFi fleets across dozens of client sites, the patch cycle takes days. Here's what to do while it runs.
TLDR: “Preview” isn’t a lightweight version of GA, and it isn’t a beta with a new name on it. It just changes the timing and access. You’ll see new JFrog capabilities the day they’re ready for real use, not the day they’re ready for a press release. We’re starting at swampUP 2026. As we know, …
Based on the principles of transparency, accessibility, usability, verifiability and perceptibility of security capabilities, Antiy releases weekly updates of the AVL SDK anti-virus engine and the full set of capabilities to the public every week. 1.Weekly Update                            Statistical period: August 22, 2026 ~ August 28, 2026 Antiy AVL SDK anti-v
This release makes working with data in the Explorer easier: browse stored schemas, use field actions in more places, preview value frequencies, plus new view options in the Stream view and custom time field selection. It also ships various fixes and security updates under the hood.
CVE-2026-81934 betrifft Redis-Instanzen mit TLS-Konfiguration. Bereinigte Releases stehen für mehrere Redis-Branches bereit. The post CVE-2026-81934: Redis-Schwachstelle in der TLS-Datenverarbeitung appeared first on LocateRisk.
Certain versions of PaperCut NG and PaperCut MF are affected by two vulnerabilities. Here's how to find impacted assets with runZero.
New initiative enables security providers to extend their trusted customer relationships while creating new recurring revenue opportunities. JENSEN BEACH, Fla. — August […] The post uRISQ® Expands into Commercial Security Channel to Help Dealers and Integrators Deliver Privacy Regulatory Compliance Solutions appeared first on CSR Privacy Solutions.
eXate and IBM Sovereign Core have announced a validated golden pattern for Sovereign Boundary Control, pairing IBM's sovereign infrastructure with eXate's geo-aware data tagging and context-aware entitlements. Together they govern how data crosses sovereign boundaries — closing the gap between data residency and real data-level control, a discipline that matters even more as sovereign AI scales.
SonarQube Hunter Agent uses AI to detect broken access control, business logic flaws, and authentication vulnerabilities traditional SAST can miss.
Token Security launches the first NHI MCP Server — an AI-powered interface giving security teams intelligent visibility & fast automated remediation across all machine identities.
Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE A critical vulnerability chain tracked as CVE-2026-18431 affects the Avada WordPress theme and its required Fusion Builder plugin, now branded as Avada Builder .
A single pricing mistake, like charging per-device in a remote-first environment where every user carries three endpoints, can cut your margin fast. The way a managed service provider (MSP) charges for managed services shapes everything downstream: margins, scalability, how many clients you can take on without burning out your team, and whether monthly revenue holds up when the next vendor price increase lands. Get it wrong and every contract drains resources; get it right and recurring revenue
This week's Corgea changelog post focuses on broader webhook coverage, richer SARIF exports for SCA findings, and private package registry support from the latest public releases in Corgea Docs.
CVE-2026-73570 is an unauthenticated Zimbra RCE under active exploitation and now on CISA's KEV list. Patching closes the door, but it doesn't tell you who already walked through it.
A critical remote code execution vulnerability in Gitea has moved from disclosure to active exploitation less than a month after a patch became available. Tracked as CVE-2026-60004 and rated 9.8 on the CVSS scale, the flaw allows an attacker with ordinary repository write access to plant an executable Git hook and run arbitrary shell commands […] The post CVE-2026-60004: Critical Gitea RCE Exploited to Deploy Miner-Like Payloads appeared first on SOC Prime.
Santa Barbara, CA – August 26, 2026 (Business Wire) – Theta Lake today announced a new integration that enables AI interaction governance telemetry from Theta Lake to flow into CrowdStrike Falcon® Next-Gen SIEM. As organizations increasingly adopt AI assistants and agentic...
Global initiative fights AI with AI and application security community expertise, validating and implementing AI-generated fixes to remediate open source vulnerabilities at scale SAN FRANCISCO, CA — August 26, 2026
CVE-2026-64849 (CVSS 9,3, EPSS ≥ 95. Perzentil) ist eine als kritisch eingestufte, nicht authentifizierte, serverseitige Request-Forgery-Schwachstelle (SSRF) [CWE-918] bei der MLflow-Webhook-Übermittlung. Die CVE betrifft alle Versionen vor 3.15.0. Die Hauptursache ist eine fehlerhafte Umleitungsverarbeitung und DNS-Rebinding. Die Schwachstelle wird durch Umgehung der Schutzmaßnahmen _validate_webhook_url in der Standardkonfiguration des MLflow-Tracking-Servers ausgenutzt. Die CISA hat CVE-2026-
Aikido's agents pentest your Android app and its backend in a single whitebox assessment. You get reproducible findings, AutoFix, and retests for every issue. Category: Product & Company Updates
Aikido's agents pentest your Android app and its backend in a single whitebox assessment. You get reproducible findings, AutoFix, and retests for every issue. Category: Product & Company Updates
Your FinOps lead needs to easily drill-down into Databricks spend and identify what’s driving costs, ...
Fresh 25 August 2026 NVD publication for `CVE-2026-55663` shows the npm package `mediasoup` and Rust crate `mediasoup` trusted fixed SCTP State Cookie markers (`msworker`, `0xAD81`) instead of a secret-keyed MAC. On `PlainTransport` or `PipeTransport` with SCTP enabled, an on-path attacker could forge `COOKIE-ECHO`, establish an unauthorized association, and inject DataChannel messages as a trusted peer.
Manage user groups in the dashboard: create groups, add and remove members, and assign roles to all users of a group at once.
As a company grows, more employees join, but the size of the IT team overseeing critical systems often doesn’t grow at the same pace. Admins have to be intentional about prioritizing their efforts to meet the needs of a growing organization. That’s why we’re excited to announce several releases aimed at helping admins optimize their organization’s use of 1Password in two important areas: reducing lockouts and automating provisioning at scale. Preventing avoidable lockouts Entra ID Secret Expirat
Tenzir now lets you build, store, merge, and compare statistical models in TQL to detect distribution drift across pipelines and time windows. The release also adds session windows, bounded event-time reordering, preceding-event access, native Splunk HEC ingestion, and more self-contained container and Python deployments.
ThreatMon ThreatMon, the AI-powered end-to-end risk intelligence platform, today announced the launch of National Cyber Defence, a new country-wide cyber intelligence solution designed to help governments, national CERTs, CSIRTs, and cybersecurity agencies gain continuous visibility into their nation’s digital attack surface, critical infrastructure, cyber exposure, and evolving threat landscape. As cyber threats increasingly target not […] The post ThreatMon Launches National Cyber Defenc
Note: Now available to organizations in the Indian data center. Support for other Zoho data centers will be available soon.AI assistants have gotten remarkably good at writing, summarizing, and reasoning, but ask one which deals are stalling in your pipeline—or to draft a reply to an urgent support ticket—and it can hit a wall.It's not because...
Horizon3 appoints federal go-to-market veteran Chad Keefer as Vice President of Federal Sales to lead growth across civilian, defense, and intelligence agencies.
The critical mcp-remote RCE (CVE-2025-6514, CVSS 9.6) exposes how AI clients over-trust MCP servers — see what identity-first Zero Trust reachability would have stopped. The post Patching mcp-remote Is the Easy Part: The Harder Lesson of CVE-2025-6514 appeared first on NetFoundry.
Now in open beta, Vault Enforcement drives password manager adoption by requiring vault login on your organization’s riskiest accounts. The post Introducing Vault Enforcement: Close the Adoption Gap on Your Terms appeared first on Dashlane Blog
Full-fidelity context at line rate gives autonomous agents the rapid evidence needed to match machine-speed attacks with machine-speed defense
New conversational, agentic AI platform unifies data security, attack surface management, and attack-path mapping into a single system that reasons, decides, and acts at machine speed — before a breach can occur. MIAMI, FL — August 25, 2026 — CYBRAL today announced the launch of CYBRAL ONE, an agentic AI platform built to help enterprises and small organizations move from reactive defense to pre-emptive cybersecurity. Simple to operate and requiring no technical expertise, CYBRAL ONE gives...
Magecart Turns Trusted GTM Into a Launchpad for Smarter Skimmers Payment-skimming attacks are continuing to abuse Google Tag Manager (GTM) as a trusted path into checkout pages, while changing what happens after the malicious code reaches the browser. Recent findings included chained GTM containers, payload delivery through Google Firestore, long-running campaigns rotating through new containers, The post MAGECART TURNS TRUSTED GTM INTO A LAUNCHPAD FOR SMARTER SKIMMERS appeared first on Source D