Releases, funding, leadership changes and incidents across the vendors in this catalog — collected automatically from vendors' own public feeds.Where this comes fromEvery item links to the vendor's own published source: a GitHub release feed, a changelog, a status page, an SEC filing or a company blog. Nothing here is written or editorially reviewed by 0-Doubt, and nothing is a recommendation — it is machine-collected public record, labelled the same way as all other baseline content on the platform. Coverage is uneven by design: a vendor that publishes no public feed will not appear, and that absence is not a judgement about the vendor.
995 matching stories — showing up to 3 per vendorPer-vendor capWhile browsing, no single vendor may fill more than three slots on any one page, so a vendor with a chatty release cadence cannot buy the page you are looking at. That means a page can render fewer stories than the count above. Searching a headline or naming a vendor turns the cap off, because then you have asked to see everything that matches.
OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are , >= 8.0, , and >= 8.1, . Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our Emergent Threat Response blog cov
CVE-2026-42533 is a critical heap buffer overflow in the NGINX script engine reached through the map directive, with weaponized public exploit code that defeats ASLR. A plain-English advisory, a tested non-destructive Nuclei detection template, and the two-window version trap that makes naive scanners clear every mainline 1.31.x host as patched. The post CVE-2026-42533: NGINX map Directive Heap Buffer Overflow – Advisory + Nuclei Detection first appeared on Sn1perSecurity.
CVE-2026-42945, known as NGINX Rift, is a critical heap buffer overflow in ngx_http_rewrite_module reachable from a single unauthenticated request, with exploitation reported in the wild. A plain-English advisory, a tested non-destructive Nuclei detection template, a configuration audit template for the pattern nginx -t will not warn you about, and why upgrading to 1.30.1 leaves you exposed. The post CVE-2026-42945 (NGINX Rift): Heap Buffer Overflow in the Rewrite Module – Advisory + Nuclei Dete
Kura equips coding agents with precise security context at scale, continuously adapting to each task so they can securely plan, implement, and test every change based on your organization's architecture, controls, and business logic. The post Introducing Kura: Adaptive Security Context built for secure agentic coding appeared first on Clover Security.
Reading Time: 4 minsLearn how real-time threat tracking helps protect your organization from the latest cyberattacks in your sector and in your location. The post Introducing the Lumu Threat Observatory™ appeared first on Lumu Technologies.
Security teams do not need another threat feed. Instead, they need to know which threats matter to their organization, what’s coming, and what they should do next. That distinction has never been … The post Introducing Unit 42 Threat Intelligence: Know What Matters, Understand the Adversary, and Act Faster appeared first on Palo Alto Networks Blog.
Today marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network Topology view, and continuing our commitment to a modern, consistent UI. This release is powered by Metasploit Framework 6.5.Malleable C2 ProfilesOne of the most requested capabilities in modern red-team engagements is the ability to blend Meterpreter's network traffic
As AI expands who builds software, the developer workstation is becoming a new security perimeter. AI and third-party software increasingly operate with access to your most sensitive credentials and cloud environments.
In January 2023, this column's first life at Kenna featured CVE-2022-44698 , a Windows SmartScreen Mark-of-the-Web bypass that attackers were happily using while the scoring systems shrugged. Three and a half years later, here we are again. This month's pick scores 3.3 under CVSS v3.1, the kind of number that never makes a patch queue, and our sensors have recorded it being exploited in the wild multiple times in the past month.
Smart and effective server security that combines real-time threat detection with health monitoring to identify real risks and changes in system reliability. Messageware Incorporated today announced the release of Server Threat Guard (STG) Version 2.9. This release builds on the health monitoring capabilities giving IT and SecOps teams clearer separation between security and health reporting, [...] The post Messageware Launches Server Threat Guard v2.9: Security, IIS Detection & Server Health Mo
Horizon3, the AI-Native Proactive Security Company behind NodeZero®, the World’s Best AI Hacker™, today announced a $250 million Series E at a valuation of more than $2 billion.
The addition of Agent Intent-Based Access Control (IBAC) brings a new capability to Varonis Atlas that lets businesses connect AI agents to their enterprise data with safeguards that stop dangerous or out-of-policy behavior.
Thales Launches Imperva for AWS to Help Organizations Protect Applications and APIs prezly Mon, 08/03/2026 - 13:00 Cybersecurity Application security Share options Facebook X Whatsapp Linkedin Email URL copied to clipboard 03 Aug 2026 Imperva for AWS delivers enterprise-grade web application, API, and bot protection for AWS environmentsUsing Amazon CloudFront, AWS's fully managed content delivery network, to simplify deployment while strengthening application securityReduces operational complexi
We’re excited to introduce ZeroFox HNTR Executive Protection, and we can’t wait to put it in front of the teams who protect leaders. Executives get targeted everywhere at once. Consider how a fake profile spreads on social media, a home address can go up for sale on a data broker site, or a hostile crowd […]
Ross Baker is Senior Director, Northern Europe at Rapid7.As organizations across the United Kingdom and Ireland embrace AI, cloud technologies, and digital transformation in the name of enhancing customer experiences and accelerating business growth, the cybersecurity landscape must continue to evolve just as quickly.In this environment, business leaders still expect security to enable innovation, not slow it down. They're pushed to reduce risk, improve visibility across expanding attack surface
Discover what's new in Obot Platform v0.25.0, including AI governance enhancements, MCP tunnels, Agent Auth Scopes, and broader platform availability. The post Announcing Obot Platform v0.25.0: Tool Call Enforcement, MCP Tunnels, and Agent Auth Scopes appeared first on Obot AI.
A single pricing mistake, like charging per-device in a remote-first environment where every user carries three endpoints, can cut your margin fast. The way a managed service provider (MSP) charges for managed services shapes everything downstream: margins, scalability, how many clients you can take on without burning out your team, and whether monthly revenue holds up when the next vendor price increase lands. Get it wrong and every contract drains resources; get it right and recurring revenue
A newly published August 2026 PyPI vulnerability shows GitPython 3.1.50 can still pass attacker-controlled helper commands to `git clone` through joined short options such as `-u`, turning clone wrappers that trust `allow_unsafe_options=False` into command-execution surfaces.
A newly published August 2026 npm vulnerability shows axios can lose its null-prototype hardening after request interceptors clone config objects, letting a polluted `Object.prototype.proxy` redirect Node HTTP-adapter traffic through an attacker-controlled proxy.
CVE-2026-20316 is a high-severity static credential vulnerability affecting Cisco Secure Firewall Management Center that allows unauthenticated access through a built-in account. NodeZero® Rapid Response safely validates exposure and verifies remediation.
CVE-2026-61511 is a critical unauthenticated RCE in vBulletin 5.x and 6.x, caused by eval injection in the runMaths() template handler. A plain-English advisory, a tested non-destructive Nuclei detection template, the 6.x patch-level trap that hides unpatched hosts, and how to find vulnerable vBulletin at scale with Sn1per. The post CVE-2026-61511: Pre-Auth Remote Code Execution in vBulletin (runMaths) – Advisory + Nuclei Detection first appeared on Sn1perSecurity.
Today we’re announcing Censys Investigator in closed beta: an AI-powered threat investigation feature that automates pivoting, infrastructure mapping, and host profiling. Give it a network observable (single, bulk list, or intel report), and it runs the investigation in parallel across Censys’ internet-wide intelligence, then returns ranked, evidence-backed findings. The key here: it operates on top […] The post Introducing Censys Investigator: Run Every Lead Like You’ve Got Hours ap
Keycloak filters its main users list so a restricted admin sees nothing. The endpoint that lists a role's members skips that filter and hands the same account everyone's email and name. Escape research found it, reported it, and it's now tracked as CVE-2026-17059.
Based on the principles of transparency, accessibility, usability, verifiability and perceptibility of security capabilities, Antiy releases weekly updates of the AVL SDK anti-virus engine and the full set of capabilities to the public every week. 1.Weekly Update Statistical period: July 25, 2026 ~ July 31, 2026 Antiy AVL SDK anti-virus engine released a total of […]
v0.76 closes a high-severity local privilege escalation in the NetBird daemon's IPC interface. The daemon now verifies who is calling it using kernel-level identity checks, and privileged operations require actual privileges.
The late-July 2026 public exploit write-up for `CVE-2026-53264` matters to AppSec teams because concurrent `RTM_NEWTFILTER` and `RTM_DELTFILTER` operations can reclaim a freed `tc_action` in `net/sched`, pivot `tcf_action_fill_size()` through a forged vtable, and turn ordinary local code execution on user-namespace-enabled Linux hosts into init-namespace root until fixed kernels such as `5.10.259`, `5.15.210`, `6.1.176`, `6.6.143`, `6.12.94`, `6.18.36`, or `7.0.13` are deployed.
GreyNoise Tactics gives anyone running a Deception Sensor visibility into what adversaries do after initial compromise, automatically mapping qualifying sessions to the MITRE ATT&CK framework.
The Runtime Remediation Skill turns a runtime alert into a safe, auditable response: real blast radius, ordered actions, confirmation on every destructive step, and a respawn watch, all with the analyst in control.
Malicious beta versions of the Joyfill npm packages @joyfill/components and @joyfill/layouts hide an obfuscated remote access trojan and credential stealer. Full analysis, IOCs, and remediation from StepSecurity.
Cisco has released emergency hot fixes for an actively exploited vulnerability impacting Cisco Secure Firewall Management Center (FMC) Software. The issue is caused by static credentials for a low-privileged account and allows an unauthenticated remote attacker to sign in to an affected appliance and access sensitive information. Although the flaw has a CVSS score of […] The post CVE-2026-20316: Actively Exploited Cisco FMC Flaw Exposes Sensitive Data appeared first on SOC Prime.
Ruby on Rails has released security updates for a critical Active Storage vulnerability that can allow an unauthenticated attacker to read arbitrary files from an application server through crafted image uploads. Tracked as CVE-2026-66066 and rated 9.5 on the CVSS scale, the flaw can expose secrets accessible to the Rails process and potentially enable remote […] The post CVE-2026-66066: Critical Rails Flaw Exposes Server Files via Image Uploads appeared first on SOC Prime.
Broadcom has released emergency security updates for a critical VMware ESXi vulnerability that can allow an attacker to escape from a virtual machine and execute code on the underlying hypervisor host. Tracked as CVE-2026-47876 and rated 9.3 on the CVSS scale, the issue resides in the VMXNET3 network adapter. Successful exploitation requires the attacker to […] The post CVE-2026-47876: Critical VMware ESXi VM Escape Flaw Enables Host Code Execution appeared first on SOC Prime.
AMP 2.3 integrates the IAB Diligence Platform and SafeGuard Privacy directly into the Buyer Agent, helping organizations embed privacy diligence into agent workflows.