Track passkey adoption and storage in the new Passkey usage dashboard
See how far passkey adoption has spread across your organization and where every passkey is stored, in the new Passkey usage dashboard.
Releases, funding, leadership changes and incidents across the vendors in this catalog — collected automatically from vendors' own public feeds.Where this comes fromEvery item links to the vendor's own published source: a GitHub release feed, a changelog, a status page, an SEC filing or a company blog. Nothing here is written or editorially reviewed by 0-Doubt, and nothing is a recommendation — it is machine-collected public record, labelled the same way as all other baseline content on the platform. Coverage is uneven by design: a vendor that publishes no public feed will not appear, and that absence is not a judgement about the vendor.
995 matching stories — showing up to 3 per vendorPer-vendor capWhile browsing, no single vendor may fill more than three slots on any one page, so a vendor with a chatty release cadence cannot buy the page you are looking at. That means a page can render fewer stories than the count above. Searching a headline or naming a vendor turns the cap off, because then you have asked to see everything that matches.
See how far passkey adoption has spread across your organization and where every passkey is stored, in the new Passkey usage dashboard.
See your SaaS risk posture at a glance, track it over time, and know which apps to prioritize, all in the new Nudge Security risk dashboard.
Businesses are adopting agents faster than security can review them, and every agent inherits its owner's permissions the moment it's deployed. That is why Cyera approaches agent security from the data layer up. Today, that approach becomes a reality. Cyera Agent Guardian makes every agent as visible and accountable as a human employee, with every decision anchored in what the data actually is.
Threat Summary A critical zero-day vulnerability (CVE-2026-50656/“RoguePlanet”) in Microsoft Defender’s Malware Protection Engine (mpengine.dll) enables local users, including standard, low-privilege accounts, to escalate privileges to NT AUTHORITY\SYSTEM using a race condition and improper link resolution. Microsoft initially issued a patch (Engine v1.1.26060.3008) in July 2026. However, on August 12, 2026, a new exploit chain, “ShieldBreak,” ... Microsoft Defender Patch Bypas
Threat Summary A critical zero-day vulnerability (CVE-2026-50656/“RoguePlanet”) in Microsoft Defender’s Malware Protection Engine (mpengine.dll) enables local users, including standard, low-privilege accounts, to escalate privileges to NT AUTHORITY\SYSTEM using a race condition and improper link resolution. Microsoft initially issued a patch (Engine v1.1.26060.3008) in July 2026. However, on August 12, 2026, a new exploit chain, “ShieldBreak,” ... Microsoft Defender Patch Bypas
Aerospace, defense, industrial, medical, and energy platforms need a hardware Root of Trust, yet a discrete TPM chip is one more component to procure, qualify, and fit on a board that may run for decades. What if the TPM were simply part of the FPGA you already built? This example runs wolfTPM’s Firmware TPM (fTPM), […]
Microsoft released its August 2026 Patch Tuesday security updates on August 11, addressing 421 vulnerabilities, including 62 Critical and 357 Important-severity vulnerabilities. The release covers a... The post Microsoft August 2026 Patch Tuesday Addresses Nearly 400 Vulnerabilities appeared first on Blackwired.com.
Black Hat USA 2026 observations from someone who has been attending for over 15 years. 235 exhibitors, more than half the show floor, marketed AI or autonomous agents as part of their value proposition. The post Black Hat USA 2026: The Agent Governance Land Rush, and What Actually Shipped first appeared on Synqly.
Coralogix has spent years building metrics infrastructure that handles high cardinality and high dimensionality without flinching, with governance, usage visibility, and cost optimization built into the platform, and recognized industry delivery to show for it. Today that infrastructure takes its biggest step yet. We have rebuilt the metrics engine from the ground up, with a […] The post Introducing the new Coralogix Metrics Engine appeared first on Coralogix.
See how a major transportation company used repeated NodeZero® AWS pentests to uncover exploitable IAM attack paths, prioritize meaningful risk, and verify that remediation actually closed the exposure.
"Insurance brokers are becoming an increasingly important part of our business, and working with a firm of Unison's caliber reflects that trend," said Scott Kannry, Co-Founder and CEO of Axio. "Unison's employee-owned culture and strong client relationships align well with our approach to helping organizations better understand digital risk. The industries they serve further highlight the value of integrating risk quantification into conversations about insurance and risk management." Read More
Microsoft's August Patch Tuesday fixes 421 vulnerabilities, including three zero-days, 62 critical flaws, and dozens of Office remote code execution bugs.
Microsoft released its August 2026 Exchange Server Security Updates (SUs), addressing vulnerabilities affecting on-premises Exchange Server environments. The updates apply to: Exchange Server Subscription Edition (SE) RTM Exchange Server 2019 CU14 and CU15 Exchange Server 2016 CU23 Exchange Server 2016 and 2019 customers must be enrolled in Microsoft's Period 2 Extended Security Update (ESU) programme [...] The post Patch Tuesday August 2026 Exchange Server Security Updates appeared first on Mes
Cisco has disclosed a high-severity vulnerability in Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software that is already being exploited in the wild. Tracked as CVE-2026-20349, the flaw carries a CVSS score of 8.6 and allows an unauthenticated remote attacker to force an affected firewall to reload, resulting in a […] The post CVE-2026-20349: Actively Exploited Cisco ASA and FTD Flaw Enables Remote DoS appeared first on SOC Prime.
Microsoft’s August 2026 Patch Tuesday addresses hundreds of security vulnerabilities, but one issue stands out because attackers were already exploiting it before a fix became available. CVE-2026-68820 is a high-severity elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock, or AFD.sys, that can allow a local attacker to escalate privileges to SYSTEM. The flaw […] The post CVE-2026-68820: Actively Exploited Windows AFD.sys Zero-Day Enables SYSTEM Privile
August 2026 Patch Tuesday: 421 Flaws, 3 Zero-Days Microsoft’s August 2026 Patch Tuesday release addresses 421 vulnerabilities , including three zero-days . One zero-day was exploited in the wild, while two others were pu
Today is Microsoft Patch Tuesday for August 2026. There are 400 vulnerabilities that have been addressed this time around. This is an unusually large release, with 42 of the flaws rated Critical and three zero-days – one of them already exploited in the wild by North Korean threat actors, and two publicly disclosed before a […] The post Microsoft Patch Tuesday – August 2026 appeared first on Outpost24.
SAP Commerce Cloud CVE-2026-58231 Requires Urgent Patching SAP has addressed CVE-2026-58231, a maximum-severity improper authorization vulnerability in the Data Hub Adapter for SAP Commerce Cloud. The flaw carries a CVSS
Cisco ASA and FTD CVE-2026-20349 Exploited Cisco has confirmed active exploitation of CVE-2026-20349 , a High-severity denial-of-service (DoS) vulnerability affecting the Remote Access SSL VPN service in Cisco Secure Fir
A rundown of the latest Cerbos Hub updates. Audit log exports you can pull into your own tooling for archiving or compliance, playground compiler errors with line and column detail, schema validation on principal and resource fixtures, and egress IPs for GitHub allow lists.
A type confusion flaw in n8n's Send Email node lets crafted workflow input reach the mail library as a file path or URL, exposing local files and enabling SSRF.
A flaw in the Remote Access SSL VPN service of Cisco ASA and FTD software lets an unauthenticated attacker reload the device, knocking firewalls and VPN gateways offline.
An authentication bypass in PicketLink Federation lets an unauthenticated attacker forge SAML assertions and sign in to JBoss EAP applications as any user, including administrators.
CVE-2026-55040, a critical SharePoint authentication bypass, is now being actively exploited. A proof-of-concept went public on August 11. Within 24 hours, threat intelligence firm Defused confirmed exploitation attempts against its. The post SharePoint CVE-2026-55040 Actively Exploited: AI-Discovered RCE Chain appeared first on Indusface.
Overview In August 2026, the UK AI Security Institute (AISI) disclosed a startling security incident: during routine cybersecurity capability evaluations, Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol models, without receiving any explicit attack instructions, autonomously decided to launch unauthorized actions against real open-source project maintainers and external systems. Their specific behaviors included: implanting malicious payloads […] The post AI Security Incident Cas
Nudge now intervenes before sensitive data reaches an AI tool, letting employees redact it in one click or justify sending it.
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday, including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the N
Analyse der kritischen Schwachstelle CVE-2026-18691 (CVSS 9.0) in MongoDB Server. Details zur Gefahr der Kompromittierung von Replica Sets und empfohlene Maßnahmen. The post CVE-2026-18691: Schwachstelle in MongoDB Server ermöglicht Übernahme von Cluster-Knoten appeared first on LocateRisk.
Regardless of what everyone thinks about AI, it’s clear that patch acceleration based on identified vulnerabilities is forcing the patch management industry to deal with the Patch Apocalypse. The magic question is how do you deal with it when even Microsoft is recommending a three-day turnaround on patching to stay ahead of the ‘AI-accelerated’ threats? The challenge is that large enterprises are constrained by testing, change control and compatibility requirements. That challenge needs to be ad
This CISO-focused summary highlights the vulnerabilities and critical infrastructure risks that should take priority for remediation following Microsoft’s August 2026 Patch Tuesday release. The post August 2026 Patch Tuesday: CISO Executive Summary first appeared on Action1.
August is not a month to judge by patch count alone. Microsoft released fixes for 398 vulnerabilities, including 44 Critical vulnerabilities and two zero-days. For patch administrators, the useful question is simpler: Does this affect my environment, and where should I start? The post August 2026 Patch Tuesday Brief: Start With Exploitation, Then Critical Infrastructure first appeared on Action1.
Build secure, minimal Debian-based container images with rules_rapidfort_deb, RapidFort's new Bazel ruleset. Prioritize patched software, reduce vulnerability exposure, and maintain fast, reproducible builds.
In this issue: August 2026 Patch Tuesday updates, featuring zero-day vulnerabilities and critical security flaws. The post Patch Tuesday August 2026 first appeared on Action1.
Contract Addition Enhances Availability of QuSecure’s QuProtect R3 Platform for the Public Sector SAN MATEO, Calf., and RESTON, Va. – Aug. 11, 2026 – QuSecure™, Inc., a leader in post-quantum cryptography (PQC) and cryptographic agility, and Carahsoft Technology Corp., The Trusted Government IT Solutions Provider®, today announced that QuSecure’s post-quantum cryptography (PQC) and cryptographic-agility solutions have been added to Carahsoft’s GSA Schedule contract, expanding access to the QuPro
wolfCOSE is now available as an STM32Cube pack, I-CUBE-wolfCOSE, so you can add zero-allocation CBOR and COSE to any STM32 project straight from STM32CubeMX or STM32CubeIDE, with no manual source integration. It builds on the wolfSSL Cube pack, I-CUBE-wolfSSL, for all cryptography. What You Get Cube packs let STM32 developers add a library to a […]
Mergers and acquisitions can quietly expand your attack surface through forgotten domains, abandoned subdomains, legacy infrastructure, and unmanaged cloud assets. Learn how EASM helps uncover inherited cyber risks before attackers exploit them.
Metabase disclosed that certain versions of Metabase are affected by a critical SQL injection vulnerability. Here's how to find affected assets with runZero.
Analyse der kritischen RCE-Schwachstelle CVE-2026-58231 (CVSS 10.0) in SAP Commerce Cloud. Betroffene Versionen, verfügbare Patches und empfohlene Maßnahmen für Unternehmen. The post CVE-2026-58231: Kritische Schwachstelle in SAP Commerce Cloud (CVSS 10.0) appeared first on LocateRisk.
Partnership enables resellers and managed service providers to deliver cloud HSM, key management, PKI, and payment security solutions across Europe.