Tools & Apps 7/15/2026 5 min@ZachasADMINPatch SharePoint CVE-2026-56164 Before a Low CVSS Score Hides the KEV RiskMicrosoft's July 2026 Patch Tuesday includes an actively exploited SharePoint Server privilege escalation flaw that NVD lists in CISA KEV, despite Microsoft's medium CVSS score.Read more
Tools & Apps 7/15/2026 5 min@ZachasADMINMap AWS AI assets before GuardDuty AI findings hit your queueAWS added AI Inventory to Security Hub and made GuardDuty AI Protection generally available, giving cloud security teams a native way to discover AI assets and detect Bedrock or SageMaker abuse.Read more
Tools & Apps 7/15/2026 4 min@ZachasADMINUpdate GitHub Actions OIDC Trust Policies Before New Repos Break Cloud DeploysGitHub now enforces immutable OIDC subject claims for new repositories and post-July 15 renames or transfers. Teams using GitHub Actions to deploy to AWS, Azure, Google Cloud, or Vault should check trust policies before new CI/CD pipelines fail.Read more
Tools & Apps 7/15/2026 5 min@ZachasADMINPatch SonicWall SMA 1000 Now, Then Check for CompromiseSonicWall says two SMA 1000 vulnerabilities are actively exploited, and CISA has added the issues to KEV. Patch affected appliances, then review SonicWall's indicators before trusting the device state.Read more
Tools & Apps 7/15/2026 4 min@ZachasADMINDelay Dependabot Version PRs Before Fresh Packages Hit Your BuildGitHub now delays Dependabot version update pull requests for three days by default, giving maintainers and scanners time to catch compromised or broken releases before they enter automated update queues.Read more
Tools & Apps 7/15/2026 4 min@ZachasADMINUpgrade Vercel Projects Before Node.js 20 Blocks New DeploymentsVercel will disable Node.js 20 for Builds and Functions on October 1, 2026, after the Node.js 20 release line reached end of life. Existing serverless deployments keep running, but new deployments can fail.Read more