Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksNothing here is ranked by paymentHelp & FAQAPI

Vendor news

Releases, funding, leadership changes and incidents across the vendors in this catalog — collected automatically from vendors' own public feeds.Where this comes fromEvery item links to the vendor's own published source: a GitHub release feed, a changelog, a status page, an SEC filing or a company blog. Nothing here is written or editorially reviewed by 0-Doubt, and nothing is a recommendation — it is machine-collected public record, labelled the same way as all other baseline content on the platform. Coverage is uneven by design: a vendor that publishes no public feed will not appear, and that absence is not a judgement about the vendor.

AllNew capability 352Release 343Incident 227Leadership 43Funding 30Announcement 10851AnnouncementsEverything the classifier could not read as a release, funding round, leadership change, incident or new capability lands in Announcement — in practice mostly vendor blog and marketing posts, and about nine in ten of everything collected. It is filterable here, but deliberately kept out of the default view rather than mixed in, so the feed you land on is not ninety percent marketing.

995 matching stories — showing up to 3 per vendorPer-vendor capWhile browsing, no single vendor may fill more than three slots on any one page, so a vendor with a chatty release cadence cannot buy the page you are looking at. That means a page can render fewer stories than the count above. Searching a headline or naming a vendor turns the cap off, because then you have asked to see everything that matches.

Incident

Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are , >= 8.0, , and >= 8.1, . Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our Emergent Threat Response blog cov

Rapid7·Vendor blog·Aug 3, 2026
Incident

CVE-2026-42533: NGINX map Directive Heap Buffer Overflow – Advisory + Nuclei Detection

CVE-2026-42533 is a critical heap buffer overflow in the NGINX script engine reached through the map directive, with weaponized public exploit code that defeats ASLR. A plain-English advisory, a tested non-destructive Nuclei detection template, and the two-window version trap that makes naive scanners clear every mainline 1.31.x host as patched. The post CVE-2026-42533: NGINX map Directive Heap Buffer Overflow – Advisory + Nuclei Detection first appeared on Sn1perSecurity.

Sn1perSecurity LLC·Press release·Aug 3, 2026
Incident

CVE-2026-42945 (NGINX Rift): Heap Buffer Overflow in the Rewrite Module – Advisory + Nuclei Detection

CVE-2026-42945, known as NGINX Rift, is a critical heap buffer overflow in ngx_http_rewrite_module reachable from a single unauthenticated request, with exploitation reported in the wild. A plain-English advisory, a tested non-destructive Nuclei detection template, a configuration audit template for the pattern nginx -t will not warn you about, and why upgrading to 1.30.1 leaves you exposed. The post CVE-2026-42945 (NGINX Rift): Heap Buffer Overflow in the Rewrite Module – Advisory + Nuclei Dete

← Newer
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
Older →
Sn1perSecurity LLC·Press release·Aug 3, 2026
New capability

Introducing Kura: Adaptive Security Context built for secure agentic coding

Kura equips coding agents with precise security context at scale, continuously adapting to each task so they can securely plan, implement, and test every change based on your organization's architecture, controls, and business logic. The post Introducing Kura: Adaptive Security Context built for secure agentic coding appeared first on Clover Security.

Clover Security·Vendor blog·Aug 3, 2026
New capability

Introducing the Lumu Threat Observatory™

Reading Time: 4 minsLearn how real-time threat tracking helps protect your organization from the latest cyberattacks in your sector and in your location. The post Introducing the Lumu Threat Observatory™ appeared first on Lumu Technologies.

Lumu Technologies·Vendor blog·Aug 3, 2026
New capability

Introducing Unit 42 Threat Intelligence: Know What Matters, Understand the Adversary, and Act Faster

Security teams do not need another threat feed. Instead, they need to know which threats matter to their organization, what’s coming, and what they should do next. That distinction has never been … The post Introducing Unit 42 Threat Intelligence: Know What Matters, Understand the Adversary, and Act Faster appeared first on Palo Alto Networks Blog.

Palo Alto Networks·Vendor blog·Aug 3, 2026
Release

Metasploit Pro 5.1 Released

Today marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network Topology view, and continuing our commitment to a modern, consistent UI. This release is powered by Metasploit Framework 6.5.Malleable C2 ProfilesOne of the most requested capabilities in modern red-team engagements is the ability to blend Meterpreter's network traffic

Rapid7·Vendor blog·Aug 3, 2026
New capability

Introducing the Wiz Sensor for Developer Workstations to Protect Endpoints in the AI Era

As AI expands who builds software, the developer workstation is becoming a new security perimeter. AI and third-party software increasingly operate with access to your most sensitive credentials and cloud environments.

Wiz·Vendor blog·Aug 3, 2026
Incident

August 2026 CVE of the Month: The 7-Zip Bug Every Scorecard Says to Ignore (CVE-2026-58052)

In January 2023, this column's first life at Kenna featured CVE-2022-44698 , a Windows SmartScreen Mark-of-the-Web bypass that attackers were happily using while the scoring systems shrugged. Three and a half years later, here we are again. This month's pick scores 3.3 under CVSS v3.1, the kind of number that never makes a patch queue, and our sensors have recorded it being exploited in the wild multiple times in the past month.

Empirical Security·Vendor blog·Aug 3, 2026
Release

Messageware Launches Server Threat Guard v2.9: Security, IIS Detection & Server Health Monitoring

Smart and effective server security that combines real-time threat detection with health monitoring to identify real risks and changes in system reliability. Messageware Incorporated today announced the release of Server Threat Guard (STG) Version 2.9. This release builds on the health monitoring capabilities giving IT and SecOps teams clearer separation between security and health reporting, [...] The post Messageware Launches Server Threat Guard v2.9: Security, IIS Detection & Server Health Mo

Messageware·Vendor blog·Aug 3, 2026
Funding

Horizon3 Raises $250M Series E at $2B+ Valuation to Lead the “AI vs. AI” Cybersecurity Era

Horizon3, the AI-Native Proactive Security Company behind NodeZero®, the World’s Best AI Hacker™, today announced a $250 million Series E at a valuation of more than $2 billion.

Horizon3.ai·Vendor blog·Aug 3, 2026
New capability

Introducing Agent Intent-Based Access Control

The addition of Agent Intent-Based Access Control (IBAC) brings a new capability to Varonis Atlas that lets businesses connect AI agents to their enterprise data with safeguards that stop dangerous or out-of-policy behavior.

Varonis·Vendor blog·Aug 3, 2026
New capability

Thales Launches Imperva for AWS to Help Organizations Protect Applications and APIs

Thales Launches Imperva for AWS to Help Organizations Protect Applications and APIs prezly Mon, 08/03/2026 - 13:00 Cybersecurity Application security Share options Facebook X Whatsapp Linkedin Email URL copied to clipboard 03 Aug 2026 Imperva for AWS delivers enterprise-grade web application, API, and bot protection for AWS environmentsUsing Amazon CloudFront, AWS's fully managed content delivery network, to simplify deployment while strengthening application securityReduces operational complexi

Thales Group·Vendor blog·Aug 3, 2026
New capability

Introducing ZeroFox HNTR Executive Protection

We’re excited to introduce ZeroFox HNTR Executive Protection, and we can’t wait to put it in front of the teams who protect leaders. Executives get targeted everywhere at once. Consider how a fake profile spreads on social media, a home address can go up for sale on a data broker site, or a hostile crowd […]

ZeroFox·Vendor blog·Aug 3, 2026
New capability

Rapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive Networks

Ross Baker is Senior Director, Northern Europe at Rapid7.As organizations across the United Kingdom and Ireland embrace AI, cloud technologies, and digital transformation in the name of enhancing customer experiences and accelerating business growth, the cybersecurity landscape must continue to evolve just as quickly.In this environment, business leaders still expect security to enable innovation, not slow it down. They're pushed to reduce risk, improve visibility across expanding attack surface

Rapid7·Vendor blog·Aug 3, 2026
Release

Announcing Obot Platform v0.25.0: Tool Call Enforcement, MCP Tunnels, and Agent Auth Scopes

Discover what's new in Obot Platform v0.25.0, including AI governance enhancements, MCP tunnels, Agent Auth Scopes, and broader platform availability. The post Announcing Obot Platform v0.25.0: Tool Call Enforcement, MCP Tunnels, and Agent Auth Scopes appeared first on Obot AI.

Obot·Vendor blog·Aug 2, 2026
Incident

Security Incident Response Metrics: Measure What Matters

A single pricing mistake, like charging per-device in a remote-first environment where every user carries three endpoints, can cut your margin fast. The way a managed service provider (MSP) charges for managed services shapes everything downstream: margins, scalability, how many clients you can take on without burning out your team, and whether monthly revenue holds up when the next vendor price increase lands. Get it wrong and every contract drains resources; get it right and recurring revenue

N-able·Vendor blog·Aug 1, 2026
Incident

CVE-2026-67324: GitPython 3.1.50 lets `-u` clone options escape the unsafe-option gate

A newly published August 2026 PyPI vulnerability shows GitPython 3.1.50 can still pass attacker-controlled helper commands to `git clone` through joined short options such as `-u`, turning clone wrappers that trust `allow_unsafe_options=False` into command-execution surfaces.

Corgea·Vendor blog·Aug 1, 2026
Incident

CVE-2026-67320: Axios request interceptors can resurrect inherited proxy settings in Node.js

A newly published August 2026 npm vulnerability shows axios can lose its null-prototype hardening after request interceptors clone config objects, letting a polluted `Object.prototype.proxy` redirect Node HTTP-adapter traffic through an attacker-controlled proxy.

Corgea·Vendor blog·Aug 1, 2026
Incident

CVE-2026-20316 | Cisco Secure Firewall Management Center Static Credential Vulnerability

CVE-2026-20316 is a high-severity static credential vulnerability affecting Cisco Secure Firewall Management Center that allows unauthenticated access through a built-in account. NodeZero® Rapid Response safely validates exposure and verifies remediation.

Horizon3.ai·Vendor blog·Jul 31, 2026
Incident

CVE-2026-61511: Pre-Auth Remote Code Execution in vBulletin (runMaths) – Advisory + Nuclei Detection

CVE-2026-61511 is a critical unauthenticated RCE in vBulletin 5.x and 6.x, caused by eval injection in the runMaths() template handler. A plain-English advisory, a tested non-destructive Nuclei detection template, the 6.x patch-level trap that hides unpatched hosts, and how to find vulnerable vBulletin at scale with Sn1per. The post CVE-2026-61511: Pre-Auth Remote Code Execution in vBulletin (runMaths) – Advisory + Nuclei Detection first appeared on Sn1perSecurity.

Sn1perSecurity LLC·Press release·Jul 31, 2026
New capability

Introducing Censys Investigator: Run Every Lead Like You’ve Got Hours

Today we’re announcing Censys Investigator in closed beta: an AI-powered threat investigation feature that automates pivoting, infrastructure mapping, and host profiling. Give it a network observable (single, bulk list, or intel report), and it runs the investigation in parallel across Censys’ internet-wide intelligence, then returns ranked, evidence-backed findings. The key here: it operates on top […] The post Introducing Censys Investigator: Run Every Lead Like You’ve Got Hours ap

Censys·Vendor blog·Jul 31, 2026
New capability

Opsin Adds Support for Claude Cowork

News

Opsin·Vendor blog·Jul 31, 2026
Leadership

Alex Hurtado joins Nebulock as Head of Detection Strategy

Alex Hurtado joins Nebulock as Head of Detection Strategy to shape how detection engineering evolves hunt-first security operations.

Nebulock·Vendor blog·Jul 31, 2026
Leadership

Alex Hurtado joins Nebulock as Head of Detection Strategy

Alex Hurtado joins Nebulock as Head of Detection Strategy to shape how detection engineering evolves hunt-first security operations.

Nebulock·Vendor blog·Jul 31, 2026
Release

Whitebox pentesting is now available in Escape's AI Pentesting - Cascade

Run Escape's AI Pentesting with your source code.

Escape·Vendor blog·Jul 31, 2026
New capability

Introducing Tines 3B, the next generation of Tines

Tines·Vendor blog·Jul 31, 2026
Incident

Escape Research team found a PII disclosure in Keycloak. It's now CVE-2026-17059.

Keycloak filters its main users list so a restricted admin sees nothing. The endpoint that lists a role's members skips that filter and hands the same account everyone's email and name. Escape research found it, reported it, and it's now tracked as CVE-2026-17059.

Escape·Vendor blog·Jul 31, 2026
New capability

Antiy AVL SDK Anti-Virus Engine Upgrade Announcement (20260801)

Based on the principles of transparency, accessibility, usability, verifiability and perceptibility of security capabilities, Antiy releases weekly updates of the AVL SDK anti-virus engine and the full set of capabilities to the public every week. 1.Weekly Update Statistical period: July 25, 2026 ~ July 31, 2026 Antiy AVL SDK anti-virus engine released a total of […]

Antiy Labs·Vendor blog·Jul 31, 2026
Release

NetBird v0.76 - Securing the Local Daemon

v0.76 closes a high-severity local privilege escalation in the NetBird daemon's IPC interface. The daemon now verifies who is calling it using kernel-level identity checks, and privileged operations require actual privileges.

NetBird·Vendor blog·Jul 31, 2026
Incident

CVE-2026-53264: Linux net/sched `tc_action` race turns local filter access into root

The late-July 2026 public exploit write-up for `CVE-2026-53264` matters to AppSec teams because concurrent `RTM_NEWTFILTER` and `RTM_DELTFILTER` operations can reclaim a freed `tc_action` in `net/sched`, pivot `tcf_action_fill_size()` through a forged vtable, and turn ordinary local code execution on user-namespace-enabled Linux hosts into init-namespace root until fixed kernels such as `5.10.259`, `5.15.210`, `6.1.176`, `6.6.143`, `6.12.94`, `6.18.36`, or `7.0.13` are deployed.

Corgea·Vendor blog·Jul 31, 2026
Release

Self-serve SSO for OIDC

Clerk·Changelog·Jul 31, 2026
New capability

Introducing Tactics: See What Adversaries Do After They’re Inside

GreyNoise Tactics gives anyone running a Deception Sensor visibility into what adversaries do after initial compromise, automatically mapping qualifying sessions to the MITRE ATT&CK framework.

GreyNoise·Vendor blog·Jul 31, 2026
New capability

Introducing the Runtime Remediation Skill for headless cloud security

The Runtime Remediation Skill turns a runtime alert into a safe, auditable response: real blast radius, ordered actions, confirmation on every destructive step, and a respawn watch, all with the analyst in control.

Sysdig·Vendor blog·Jul 31, 2026
Release

Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan

Malicious beta versions of the Joyfill npm packages @joyfill/components and @joyfill/layouts hide an obfuscated remote access trojan and credential stealer. Full analysis, IOCs, and remediation from StepSecurity.

StepSecurity·Vendor blog·Jul 30, 2026
Incident

Gitea vulnerability CVE-2026-60004: find impacted assets

Gitea disclosed that certain versions of Gitea are affected by a RCE vulnerability within the diffpatch feature. Here's how to find affected assets.

runZero·Vendor blog·Jul 30, 2026
Incident

CVE-2026-20316: Actively Exploited Cisco FMC Flaw Exposes Sensitive Data

Cisco has released emergency hot fixes for an actively exploited vulnerability impacting Cisco Secure Firewall Management Center (FMC) Software. The issue is caused by static credentials for a low-privileged account and allows an unauthenticated remote attacker to sign in to an affected appliance and access sensitive information. Although the flaw has a CVSS score of […] The post CVE-2026-20316: Actively Exploited Cisco FMC Flaw Exposes Sensitive Data appeared first on SOC Prime.

SOC Prime·Vendor blog·Jul 30, 2026
Incident

CVE-2026-66066: Critical Rails Flaw Exposes Server Files via Image Uploads

Ruby on Rails has released security updates for a critical Active Storage vulnerability that can allow an unauthenticated attacker to read arbitrary files from an application server through crafted image uploads. Tracked as CVE-2026-66066 and rated 9.5 on the CVSS scale, the flaw can expose secrets accessible to the Rails process and potentially enable remote […] The post CVE-2026-66066: Critical Rails Flaw Exposes Server Files via Image Uploads appeared first on SOC Prime.

SOC Prime·Vendor blog·Jul 30, 2026
Incident

CVE-2026-47876: Critical VMware ESXi VM Escape Flaw Enables Host Code Execution

Broadcom has released emergency security updates for a critical VMware ESXi vulnerability that can allow an attacker to escape from a virtual machine and execute code on the underlying hypervisor host. Tracked as CVE-2026-47876 and rated 9.3 on the CVSS scale, the issue resides in the VMXNET3 network adapter. Successful exploitation requires the attacker to […] The post CVE-2026-47876: Critical VMware ESXi VM Escape Flaw Enables Host Code Execution appeared first on SOC Prime.

SOC Prime·Vendor blog·Jul 30, 2026
Release

IAB Tech Lab Releases AAMP 2.3, Bringing Privacy Diligence to Agentic Advertising

AMP 2.3 integrates the IAB Diligence Platform and SafeGuard Privacy directly into the Buyer Agent, helping organizations embed privacy diligence into agent workflows.

SafeGuard Privacy·Vendor blog·Jul 30, 2026