Releases, funding, leadership changes and incidents across the vendors in this catalog — collected automatically from vendors' own public feeds.Where this comes fromEvery item links to the vendor's own published source: a GitHub release feed, a changelog, a status page, an SEC filing or a company blog. Nothing here is written or editorially reviewed by 0-Doubt, and nothing is a recommendation — it is machine-collected public record, labelled the same way as all other baseline content on the platform. Coverage is uneven by design: a vendor that publishes no public feed will not appear, and that absence is not a judgement about the vendor.
343 matching stories — release — showing up to 3 per vendorPer-vendor capWhile browsing, no single vendor may fill more than three slots on any one page, so a vendor with a chatty release cadence cannot buy the page you are looking at. That means a page can render fewer stories than the count above. Searching a headline or naming a vendor turns the cap off, because then you have asked to see everything that matches.
Ubiquiti's latest security bulletin patches 22 UniFi vulnerabilities, three of them maximum severity. For MSPs managing UniFi fleets across dozens of client sites, the patch cycle takes days. Here's what to do while it runs.
This release makes working with data in the Explorer easier: browse stored schemas, use field actions in more places, preview value frequencies, plus new view options in the Stream view and custom time field selection. It also ships various fixes and security updates under the hood.
A single pricing mistake, like charging per-device in a remote-first environment where every user carries three endpoints, can cut your margin fast. The way a managed service provider (MSP) charges for managed services shapes everything downstream: margins, scalability, how many clients you can take on without burning out your team, and whether monthly revenue holds up when the next vendor price increase lands. Get it wrong and every contract drains resources; get it right and recurring revenue
This week's Corgea changelog post focuses on broader webhook coverage, richer SARIF exports for SCA findings, and private package registry support from the latest public releases in Corgea Docs.
As a company grows, more employees join, but the size of the IT team overseeing critical systems often doesn’t grow at the same pace. Admins have to be intentional about prioritizing their efforts to meet the needs of a growing organization. That’s why we’re excited to announce several releases aimed at helping admins optimize their organization’s use of 1Password in two important areas: reducing lockouts and automating provisioning at scale. Preventing avoidable lockouts Entra ID Secret Expirat
Tenzir now lets you build, store, merge, and compare statistical models in TQL to detect distribution drift across pipelines and time windows. The release also adds session windows, bounded event-time reordering, preceding-event access, native Splunk HEC ingestion, and more self-contained container and Python deployments.
See what’s new in Equixly’s August 2026 release: Attack Trace, AI Red Teaming controls, faster pentest scans, workspace upgrades, and simpler MCP setup.
Every browser tab runs code the vendor chose to send to it, and everything in that code is visible to whoever opens developer tools, reads a source map, or decompiles the bundle. A recurring and often underestimated class of exposure is what happens when that shipped code, or a config response it calls, carries something… Read More »Shipped to the Browser: How FireCompass’s Agentic AI Penetration Testing Found API Keys and Signing Secrets Hardcoded Into Client-Side Code Acr
tenzir-ship now lets changelog projects require authors and reject pull request metadata in unreleased entries without invalidating published releases. Validation applies these policies to unreleased entries by default, while an explicit full-history check remains available for audits.
OIDC SSO connections now support PKCE, the userinfo endpoint, pinned token-endpoint auth methods and ID token signing algorithms, all configurable (and rotatable) without resetting the connection.
We benchmarked 11 frontier LLMs on real-world web app pentesting. See which AI models lead in recall, precision, and cost efficiency in PWNBench-v0.1. The post PWNBench-v0.1: Evaluating Frontier Models for Web Application Pentesting appeared first on Novee.
At a glance: Open-source reporting indicates CVE-2026-8452 is being exploited in the wild following the release of public proof-of-concept exploit code. The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway deployments configured as a Gateway or Authentication, Authorization, and Accounting (AAA) virtual server and was patched on June 30, 2026. Citrix describes the issue as a memory overflow vulnerability, while watchTowr researchers demonstrated a path to pre-authentication remot
The post Operationalizing SBOMs to Boost Incident Response Velocity with Anchore Enterprise v6.1 appeared first on Anchore.We are excited to announce the release of Anchore Enterprise v6.1, built specifically to operationalize your SBOM data for instant blast radius analysis when a zero-day hits. We also added scan coverage for virtual machines and expanded the unified asset model to address global compliance regulations such as EU CRA. A critical zero-day drops. The […]
Version 9.5.2 of the Elastic Stack was released today. We recommend you upgrade to this latest version. We recommend 9.5.2 over the previous versions 9.5.1 For details of the issues that have been fixed and a full list of changes for each product in this version, please refer to the release notes.
ECK 3.5 brings dynamic namespace management via label selectors, pause orchestration for safe maintenance windows, mutual TLS across all stack components, simplified resource specs, and a reduced operator memory footprint.
This June release of Omada Identity Cloud includes new AI capabilities to facilitate easier onboarding, compliance and access decisions, tightens control over precise time-based access controls, completed the move to a modern self-service interface and simplifies platform configuration and administration. The post Omada Identity Cloud June 2026 Release appeared first on Omada.
Most AppSec friction is administrative. A vulnerability gets fixed, but the ticket stays open. A triage decision made in Jira never reaches Polaris. Code on an internal server can’t be scanned without a firewall exception. Three repositories scan against a config file nobody has updated in a year. The latest Black Duck Polaris™ Platform release […] The post Polaris release update: Two-way bug tracker sync, AI-assisted fixes, scanning you can govern appeared first on Black Duck.
To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies #50616 [CVE-2026-14613] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role Groups Endpoint admin/fine-grained-permissions #50955 [CVE-2026-59888 and CVE-2026-59889] Upgrade jackson-databind to 2.21.
TL;DR: OWASP released MASWE v1.0.0 on Aug. 17, 2026, the first stable version of the Mobile Application Security Weakness Enumeration and the missing middle layer between the OWASP Mobile Application Security Verification Standard (MASVS) and the OWASP Mobile Application Security Testing Guide (MASTG). Two years of beta feedback produced 78 clearly defined organized as a […] The post OWASP MASWE Hits v1.0: NowSecure Platform Already Maps to It appeared first on NowSecure.
A roundup of the latest features and updates shipped to the Intruder platform, from new integrations and expanded cloud coverage to GregAI improvements and a fresh look.
For most software teams, security is a race against a clock. The median time from vulnerability disclosure to weaponization has collapsed from 840 days to 1.6 days, and 80% of exploitations now occur on or before the day of disclosure. That’s bad. But if you write Solidity, you already know your situation is categorically worse.  […]
Few teams within a company touch as many parts of the business daily as product marketing. Sitting at the intersection of marketing, product, and sales, product marketing managers (or PMMs, for short) need to stay steeped in the product while translating nuanced technical information into stories that resonate with the broader market. At NinjaOne, that’s […]
Cerbos PDP v0.55.0 adds strict evaluation mode, which turns runtime errors in policy conditions into explicit denials instead of silent skips. This release also lets auxData carry multiple named JWTs, folds constant expressions at compile time, and upgrades CEL with 21 new expression functions for networking, regex, and sets.
Reearcher NightmareEclipse has released another proof of concept for a Microsoft vulnerability. ShieldBreak exploits the same weakness as the previously patched RoguePlanet.
This week's Corgea changelog highlights the new Vulnerability Workbench, bulk triage ingestion with approval workflows, and stronger sign-in resilience with email one-time passwords.