Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksNothing here is ranked by paymentHelp & FAQAPI

Vendor news

Releases, funding, leadership changes and incidents across the vendors in this catalog — collected automatically from vendors' own public feeds.Where this comes fromEvery item links to the vendor's own published source: a GitHub release feed, a changelog, a status page, an SEC filing or a company blog. Nothing here is written or editorially reviewed by 0-Doubt, and nothing is a recommendation — it is machine-collected public record, labelled the same way as all other baseline content on the platform. Coverage is uneven by design: a vendor that publishes no public feed will not appear, and that absence is not a judgement about the vendor.

AllNew capability 352Release 343Incident 227Leadership 43Funding 30Announcement 10860AnnouncementsEverything the classifier could not read as a release, funding round, leadership change, incident or new capability lands in Announcement — in practice mostly vendor blog and marketing posts, and about nine in ten of everything collected. It is filterable here, but deliberately kept out of the default view rather than mixed in, so the feed you land on is not ninety percent marketing.

995 matching stories — showing up to 3 per vendorPer-vendor capWhile browsing, no single vendor may fill more than three slots on any one page, so a vendor with a chatty release cadence cannot buy the page you are looking at. That means a page can render fewer stories than the count above. Searching a headline or naming a vendor turns the cap off, because then you have asked to see everything that matches.

New capability

Unison Risk Advisors Partners With Axio to Expand Access to Digital Risk Insights

"Insurance brokers are becoming an increasingly important part of our business, and working with a firm of Unison's caliber reflects that trend," said Scott Kannry, Co-Founder and CEO of Axio. "Unison's employee-owned culture and strong client relationships align well with our approach to helping organizations better understand digital risk. The industries they serve further highlight the value of integrating risk quantification into conversations about insurance and risk management." Read More

Axio·Vendor blog·Jul 22, 2026
Incident

July 2026 CVE of the Month: The Apache Solr Backdoor You Installed on Purpose (CVE-2026-44825)

Four years ago I wrote a monthly column at Kenna Security about the vulnerabilities the headlines were missing. It's back: same idea, better models. A year ago this week, every security team in the world was sprinting to patch SharePoint's ToolShell. This series is about the other kind of vulnerability, the kind that is covered in the feeds and present in the scanners but sitting nowhere near the top of anyone's queue, even while our exploitation telemetry says it should be. This month's pick co

Empirical Security·Vendor blog·Jul 22, 2026
New capability

Announcing InfraTrust, the source of intelligence on security risks across hardware infrastructure

Today we’re excited to announce InfraTrust, a global hardware infrastructure security knowledgebase making mission critical infrastructure security data available faster, so you have it when you need it to defend your enterprise. InfraTrust is a searchable, continuously updated source of security advisories and risk data from major enterprise hardware infrastructure vendors.  In addition to the […] The post Announcing InfraTrust, the source of intelligence on security risks across har

← Newer
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
Older →
Eclypsium·Vendor blog·Jul 22, 2026
New capability

Eclypsium Launches InfraTrust to Centralize Enterprise Hardware Security Risks

New global infrastructure security intelligence database debuts alongside monthly advisory delivering actionable risk data to protect critical enterprise hardware infrastructure. Portland, OR – July 22, 2026 – Eclypsium, the infrastructure assurance company, today announced the launch of InfraTrust, a global hardware infrastructure risk knowledge base, and InfraTrust Pulse, a monthly digest, similar to Patch Tuesday, […] The post Eclypsium Launches InfraTrust to Centralize Enterprise Hardw

Eclypsium·Vendor blog·Jul 22, 2026
Incident

The Great (Sandbox) Escape – Analyzing the OpenAI and Hugging Face Security Incident

What began as an internal benchmark evaluation has quickly become another watershed moment in cybersecurity history. An autonomous AI agentic framework initiated a full-scale attack against Hugging Face, executing a multi-stage intrusion end-to-end at machine speed and all without human direction or manual oversight. Beyond displaying the raw power of next-generation models, this incident revealed […] The post The Great (Sandbox) Escape – Analyzing the OpenAI and Hugging Face Securit

Noma Security·Vendor blog·Jul 22, 2026
New capability

Introducing SonarQube Server 2026.4

Discover SonarQube Server 2026.4 with architecture management, faster scans and stronger verification for agent generated code.

Sonar·Vendor blog·Jul 22, 2026
New capability

Introducing Lunar Domain Exposure: A Free OSINT View of Corporate Credential Risk

A company domain can reveal far more than its website, email addresses, or public infrastructure. It can also provide a starting point for understanding how widely an organization’s credentials have appeared across infostealer logs, database breaches, combo lists, and other leaked data. Webz.io has launched Lunar Domain Exposure, a free OSINT tool that turns this […] The post Introducing Lunar Domain Exposure: A Free OSINT View of Corporate Credential Risk appeared first on Lunar Cyber.

Webz.io·Vendor blog·Jul 22, 2026
New capability

ExtraHop® Launches the Agentic SOC Alliance to Validate a Shared Operating Model for Machine-Speed Defense

Alliance members will validate architectural requirements for the AI SOC across Context, Harness, and Model, anchored by discoverable, semantically rich context every agent can query and reason on, so enterprises can adopt autonomous, machine-speed defense

ExtraHop·Changelog·Jul 22, 2026
Incident

wp2shell: Inside the WordPress Unauthenticated RCE Chain (CVE-2026-63030/CVE-2026-60137)

A new WordPress core exploit chain, now widely tracked as wp2shell, is being actively used against internet-facing WordPress sites. It […] The post wp2shell: Inside the WordPress Unauthenticated RCE Chain (CVE-2026-63030/CVE-2026-60137) appeared first on .

Prophaze Technologies Pvt.Ltd.·Vendor blog·Jul 22, 2026
Release

Radar for User Management API Integrations

Radar can now be used with the User Management APIs

WorkOS·Changelog·Jul 22, 2026
Release

Configurable default OAuth scopes

Clerk·Changelog·Jul 22, 2026
Release

Connect your AI tools to Clerk MCP with one command

Clerk·Changelog·Jul 22, 2026
Release

Export a complete log of admin activity

Track every administrative action in Nudge Security and export it as a CSV.

Nudge Security·Changelog·Jul 22, 2026
New capability

Introducing Internal Network Scanning: see your network the way an attacker inside it would

Most breaches don't begin with a zero-day but with something ordinary like a forgotten server, an unmanaged network device, a service reachable across a segment that was supposed to be isolated. Internal scanning was supposed to catch exactly that but most scanners match a host's banner and version against a CVE list and flag everything potentially affected, so the few reachable exposures sit lost among thousands that were never exploitable. That noise is expensive now that the window to respon

ProjectDiscovery·Vendor blog·Jul 21, 2026
New capability

Indicio Launches Digital Workforce Credentials: One Verified Identity for Your Workforce

Indicio·Vendor blog·Jul 21, 2026
Incident

WP2Shell Technical Analysis: CVE-2026-63030 & CVE-2026-60137 WordPress Core RCE Chain

WP2Shell combines two WordPress Core vulnerabilities into a critical unauthenticated Remote Code Execution chain. This technical analysis explains the exploit path, affected versions, detection techniques, indicators of compromise, and practical remediation guidance for security teams.

Brandefense·Vendor blog·Jul 21, 2026
Incident

A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit

ManageEngine's SSO ticket was just the millisecond wall-clock time at login, making unauthenticated account takeover theoretically possible. Bishop Fox confirmed the exploit end to end and breaks down why blind exploitation is still impractical and what defenders should do about it.

Bishop Fox·Vendor blog·Jul 21, 2026
Leadership

Oomnitza Welcomes Victor Hwei as Chief Financial Officer

Oomnitza expands executive team to capitalize on the demand for its Enterprise Technology Management (ETM) solution. The post Oomnitza Welcomes Victor Hwei as Chief Financial Officer appeared first on Oomnitza.

Oomnitza·Vendor blog·Jul 21, 2026
New capability

Microsoft Announces Retirement of OWA Light for Exchange Server

Microsoft is officially retiring Outlook on the Web (OWA) Light. First introduced nearly 20 years ago to support legacy browsers and slow network connections, the lightweight email interface has reached the end of its journey. In an upcoming Exchange Server SE update, estimated for August 2026, Microsoft will permanently disable and remove OWA Light. Exchange [...] The post Microsoft Announces Retirement of OWA Light for Exchange Server appeared first on Messageware.

Messageware·Vendor blog·Jul 21, 2026
Incident

wp2shell (CVE-2026-63030 + CVE-2026-60137): WordPress pre-auth RCE, now detected by Escape

wp2shell is an unauthenticated RCE chain in WordPress core. It combines two separate vulnerabilities: CVE-2026-63030 and CVE-2026-60137. Escape detects it across DAST and AI Pentesting, confirms exploitability, and shows affected assets within its Attack Surface Management.

Escape·Vendor blog·Jul 21, 2026
New capability

Introducing Hyper-Supervised Assurance Intelligence (H_SAI)

H_SAI is SecurityPal's operating system for cybersecurity assurance — combining foundational AI, organizational security knowledge, and continuous certified human supervision for accuracy, consistency, and confidence.

securitypal·Vendor blog·Jul 21, 2026
Incident

CVE-2026-45659: Authenticated SharePoint Remote Code Execution Vulnerability Moves from Patch Tuesday to Active Exploitation

Executive Summary Microsoft addressed CVE-2026-45659, an authenticated remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server, as part of its May 2026 security updates. The vulnerability stems from improper validation of untrusted data during deserialization, enabling an authenticated user with Site Member permissions to execute arbitrary code without requiring administrative privileges. Microsoft assigned the vulnerability […]

Gurucul·Vendor blog·Jul 21, 2026
Release

Tenzir Ship v1.11.1: Release-scoped changelog entry IDs

This release fixes changelog entry identity handling by scoping entry IDs to individual releases. Reused slugs now participate correctly in version bumps, validation, and changelog output.

Tenzir·Changelog·Jul 21, 2026
Release

Tenzir Platform v1.37.2: Container security hardening and KeyCloak session fix

This release rebuilds the platform's AWS Lambda and SeaweedFS container images to clear a broad set of known CVEs, and fixes unexpected logouts when KeyCloak is the identity provider on the Sovereign Edition. The Library also refreshes its package view immediately after source changes and surfaces install errors inline.

Tenzir·Changelog·Jul 21, 2026
Release

Tenzir Node v6.8.0: Splunk search input

The new `from_splunk` operator lets nodes run bounded searches against a Splunk Search Head and emit results as events. `to_clickhouse` now re-batches events before insert for higher throughput and supports writing directly into JSON columns. This release also makes nodes resilient to corrupt or truncated partitions, quarantining them instead of crashing repeatedly.

Tenzir·Changelog·Jul 21, 2026
Release

Now Available: Intelligence Dashboard in the GreyNoise Platform

With the new Intelligence Dashboard, pin any combination of CVEs, tags, countries, IPs, and GNQL queries into one persistent, always-current view.

GreyNoise·Vendor blog·Jul 21, 2026
Release

Prioritize your SaaS and AI inventory automatically with data types and business criticality tiers | Nudge Security

See what data every app can access across 27 distinct data types, automatically classified by data sensitivity and business criticality.

Nudge Security·Changelog·Jul 21, 2026
Release

Nudge Security releases inherent and residual risk scores for every SaaS and AI vendor in open beta

Nudge Security continuously monitors and scores every vendor's inherent and residual risk, factoring in vendor posture, your environment, and your controls.

Nudge Security·Changelog·Jul 21, 2026
Release

Binalyze AIR v5.22

Administrators can now define named, policy-style rules that automatically exclude matching assets from automatic Responder updates. The post Binalyze AIR v5.22 appeared first on Binalyze.

Binalyze·Vendor blog·Jul 20, 2026
Funding

Unfinished Mission: Empirical’s New Funding

Today, Empirical Security announced our $25 million Series A led by Brightmind Partners. We started Empirical because prediction has become a requirement for modern defense, and because the technology finally exists to build this the right way.

Empirical Security·Vendor blog·Jul 20, 2026
Incident

CVE-2026-42533 – NGINX Heap Overflow

TL;DR Die Schwachstelle CVE-2026-42533 entsteht durch eine inkonsistente Verarbeitung von Regex-Captures in der zweistufigen Script Engine von NGINX. Dadurch kann ein Heap Buffer Overflow ausgelöst werden, der einen Denial of Service oder unter bestimmten Voraussetzungen sogar die Ausführung von beliebigem Code ermöglicht. F5 hat am 15. Juli 2026 in NGINX 1.30.4 (Stable), 1.31.3 (Mainline) sowie […] Der Beitrag CVE-2026-42533 – NGINX Heap Overflow erschien zuerst auf

Enginsight·Vendor blog·Jul 20, 2026
New capability

Trilio and OSIE Announce Strategic Partnership to Deliver Integrated Data Protection and Billing for OpenStack MSP Environments

Trilio and OSIE announce a strategic partnership to deliver seamlessly integrated data protection and robust billing solutions engineered for OpenStack MSP environments. The post Trilio and OSIE Announce Strategic Partnership to Deliver Integrated Data Protection and Billing for OpenStack MSP Environments appeared first on Trilio.

Trilio·Vendor blog·Jul 20, 2026
Incident

AD FS CVE-2026-56155 Forges Federation Tokens. Identity Is Not the Data Boundary.

CISA added AD FS CVE-2026-56155 to KEV on July 14, 2026 with a July 28 federal deadline. The flaw hands an attacker the token-signing keys, and a forged federation token replays against every connected application. Object-level enforcement is what still refuses it.

Lattix·Vendor blog·Jul 20, 2026
Release

Product release: July 2026

Here’s what’s new on the Push platform for July 2026.

Push Security·Vendor blog·Jul 20, 2026
Incident

WordPress wp2shell RCE: CVE-2026-63030 and CVE-2026-60137

On July 17, 2026, WordPress pushed an emergency security update. WordPress 7.0.2, 6.9.5, and 6.8.6 fixed two core vulnerabilities: CVE-2026-63030 and CVE-2026-60137. Our team at Element Security analyzed the patched code to understand the vulnerabilities, protect our customers, and develop an exploit module for our External Security platform. We identified both root causes and investigated […] The post WordPress wp2shell RCE: CVE-2026-63030 and CVE-2026-60137 appeared first on Element Secu

Element Security·Vendor blog·Jul 19, 2026
Incident

wp2shell (CVE-2026-63030): Unauthenticated Pre-Auth RCE in WordPress Core – Advisory + Nuclei Detection

wp2shell (CVE-2026-63030) is an unauthenticated pre-auth RCE in WordPress Core 6.9.0-6.9.4 and 7.0.0-7.0.1. A plain-English advisory, a ready-to-run Nuclei detection template, remediation, and how to detect affected WordPress at scale with Sn1per. The post wp2shell (CVE-2026-63030): Unauthenticated Pre-Auth RCE in WordPress Core – Advisory + Nuclei Detection first appeared on Sn1perSecurity.

Sn1perSecurity LLC·Press release·Jul 18, 2026
Release

Even Google Can’t Ship Its Best AI

TSMC bet another $100 billion this week. Google can’t ship its best model. And the evaluations that actually decide enterprise AI purchases just went private. […] The post Even Google Can’t Ship Its Best AI appeared first on Olakai.

Olakai·Vendor blog·Jul 17, 2026
Release

Echoworx Release Turns Encryption Into Audit Evidence

DORA enforcement is live. NIS2 obligations are tightening. GDPR penalties keep climbing. For security managers at regulated institutions, the mandate is blunt: “encrypted” is no longer a checkbox — it… The post Echoworx Release Turns Encryption Into Audit Evidence appeared first on Echoworx Email Encryption.

Echoworx·Vendor blog·Jul 16, 2026
New capability

Introducing Time-Based Metadata: Unlocking a new layer of data in media forensics

Time-based metadata reveals frame-specific data such as GPS coordinates, speed, and event timelines, helping investigators analyze evidence with greater accuracy. Discover how Magnet Verify unlocks this hidden layer of forensic data. The post Introducing Time-Based Metadata: Unlocking a new layer of data in media forensics appeared first on Magnet Forensics.

Magnet Forensics·Vendor blog·Jul 16, 2026
Funding

NINJIO Acquires SafeStack to Expand Human Risk Management with Secure Code Training

Cybersecurity risk doesn’t begin and end with employee awareness.  It also lives in the software applications organizations build, maintain, and rely on every day.  That’s why we’re excited to announce that NINJIO has acquired SafeStack, a leading developer security and application security training platform. This acquisition expands NINJIO’s Human Risk Management platform beyond cybersecurity awareness training and phishi

NINJIO·Vendor blog·Jul 16, 2026