#Security
Loot, blog posts and adjacent themes connected to this topic. Follow the tag to keep it in your orbit.
More from this topic

















Related reads
Oracle ships record July CPU with 1,449 security patches
Oracle's July 2026 Critical Patch Update is its largest security release to date, covering 1,449 patches across 334 products and giving Orac…
Suno breach exposes 55M accounts as HIBP confirms dataset
Have I Been Pwned has added Suno's November 2025 breach, listing more than 55 million unique email addresses plus phone numbers and a smalle…
Vercel WAF now protects Blob stores in beta
Vercel has extended its Web Application Firewall to Vercel Blob stores in beta, letting teams apply deny, challenge, and rate-limit rules to…
PAN-OS GlobalProtect flaw now leads to Qilin ransomware intrusions
Arctic Wolf says CVE-2026-0257 has moved from observed GlobalProtect exploitation to Qilin ransomware intrusions, giving PAN-OS administrato…
Anthropic brings Claude Security scans to Claude Code beta
Anthropic's Claude Security plugin is now documented for Claude Code, adding multi-agent repository scans, diff scans, and reviewed patch fi…
Next.js patches July security flaws across App Router and Server Actions
Next.js released v16.2.11 and v15.5.21 to fix July 2026 security issues across App Router, Server Actions, middleware/proxy behavior, SSRF p…
Node.js schedules HIGH-severity security releases for July 27
The Node.js project says security releases for the 26.x, 24.x, and 22.x lines are due on or shortly after July 27, 2026, with the highest se…
CISA puts WordPress wp2shell RCE in KEV with July 24 deadline
CISA now lists two WordPress Core wp2shell vulnerabilities as actively exploited, with a July 24 deadline for CVE-2026-63030 and an August 4…
GitHub puts Copilot code review behind a default firewall
GitHub now gives Copilot code review its own firewall, setup workflow, and runner configuration, separating review-agent controls from the b…
Fortinet FortiSandbox CVEs enter CISA KEV with July 19 deadline
CISA added two Fortinet FortiSandbox command-injection flaws to KEV on July 16, with a July 19 remediation deadline for covered agencies and…
Claude Code 2.1.214 fixes permission bypasses in agent shell checks
Anthropic's July 18 Claude Code update closes several permission-check gaps around Windows PowerShell 5.1, Bash parsing, long shell commands…
Cloudflare ships emergency WAF rules for active RCE and SQLi attacks
Cloudflare's July 17 emergency WAF release adds block-mode detections for active unauthenticated RCE and SQL injection exploitation in popul…
WordPress 7.0.2 forces security updates for wp2shell RCE
WordPress 7.0.2 fixes one critical and one high-severity core issue, with forced automatic updates enabled for affected branches and Cloudfl…
SharePoint CVE-2026-58644 is exploited; admins face a July 19 deadline
CISA and NVD now mark CVE-2026-58644 as actively exploited against Microsoft SharePoint Server, with emergency remediation pressure on expos…
GitHub expands secret scanning with Resend tokens and monitoring insights
GitHub is rolling out secret scanning updates that add Resend and APIclub detectors, block VolcEngine Ark API keys by default, expose secret…
Patch Oracle E-Business Suite Payments Before the New KEV Deadline
CISA added CVE-2026-46817 to the KEV catalog with a July 18 deadline after evidence of active exploitation. Oracle E-Business Suite teams sh…
Patch AD FS CVE-2026-56155 Before a Foothold Becomes Admin Access
Microsoft and CISA list CVE-2026-56155 as an actively exploited AD FS elevation-of-privilege flaw. Patch exposed Windows Server estates firs…
Patch SharePoint CVE-2026-56164 Before a Low CVSS Score Hides the KEV Risk
Microsoft's July 2026 Patch Tuesday includes an actively exploited SharePoint Server privilege escalation flaw that NVD lists in CISA KEV, d…
Patch SonicWall SMA 1000 Now, Then Check for Compromise
SonicWall says two SMA 1000 vulnerabilities are actively exploited, and CISA has added the issues to KEV. Patch affected appliances, then re…
Patch SharePoint CVE-2026-56164 before the new CISA deadline
CISA says CVE-2026-56164 is being actively exploited against on-premises SharePoint Server. Treat the July 2026 Patch Tuesday fix as an emer…
Cloudflare Precursor Makes Bot Detection a Full-Session Problem
Cloudflare has launched Precursor, a session-based bot detection system that watches browser behavior across a full visit instead of relying…
Find Old Cisco IOS Routers Before CVE-2008-4128 Becomes a Pivot
CISA added CVE-2008-4128 to KEV on July 13, 2026. The flaw affects obsolete Cisco IOS 12.4 systems, so the practical task is inventory, isol…
Patch Joomla Form Extensions Now: CISA Adds Balbooa Forms and iCagenda RCEs to KEV
CISA added two actively exploited Joomla extension upload flaws to KEV on July 10, 2026, with a July 13 remediation deadline for covered age…
Mark Vercel secrets as Sensitive before build logs expose them
Vercel now redacts Sensitive Environment Variable values from build logs, but only when the variable is marked Sensitive and the value is 32…
CISA KEV puts Adobe, Joomla and Langflow flaws on an urgent patch list
CISA's KEV catalog lists exploited Adobe ColdFusion, Joomla page-builder and Langflow vulnerabilities with near-term remediation deadlines, …
Harden Cloudflare IPsec Tunnels Before Quantum Downgrade Risk Reaches Production
Cloudflare added beta IKEv2 full-transcript authentication for WAN and Magic Transit IPsec tunnels, closing a downgrade gap that can survive…
Verify Shopify Partner IDs Before Collaborator Requests Start Failing
Shopify has started identity verification for Partners who send new collaborator requests, with mandatory enforcement coming in the next few…
Patch Langflow now: CISA flags CVE-2026-55255 as actively exploited
CISA added Langflow CVE-2026-55255 to the Known Exploited Vulnerabilities catalog, giving federal agencies until July 10, 2026 to mitigate a…
CISA adds Adobe ColdFusion CVE-2026-48282 to KEV with a July 10 patch deadline
CISA has marked Adobe ColdFusion CVE-2026-48282 as actively exploited, giving U.S. federal civilian agencies until July 10, 2026, to apply v…
Patch these three CISA KEV entries before public exposure turns expensive
CISA added three actively exploited vulnerabilities to the KEV catalog on July 7, covering Joomlack Page Builder, Langflow, and Adobe ColdFu…
Check Cloudflare WAF Logs Before Citrix and Kemp Exploit Traffic Turns Noisy
Cloudflare has scheduled new WAF detections for Citrix NetScaler CVE-2026-8451 and Progress Kemp LoadMaster CVE-2026-8037, giving defenders …
Patch UniFi OS before the RCE chain becomes your network foothold
Ubiquiti's UniFi OS command-injection flaw is now listed as actively exploited, and Bishop Fox shows how it can sit inside an unauthenticate…
Patch Cisco SD-WAN Manager before CVE-2026-20262 turns into root access
Cisco says CVE-2026-20262 lets an authenticated attacker create or overwrite files on Catalyst SD-WAN Manager systems and may later be used …