Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Critical Security Risks in vSphere Active Directory Integration

Microsoft Active Directory is widely used for authentication, and many software solutions can integrate with it to rely on a single authentication system. VMware vSphere components, including vCenter Server and ESXi hosts, also support Active Directory integration, which simplifies account and access management. However, this convenience introduces specific security risks that administrators need to understand and mitigate.

Autonomous Attacks Are Already Here. The Defense Has to Match Their Speed.

Last week, Snyk CTO Manoj Nair sat down with Alon Krifcher, Head of Applied AI from Anthropic, for a live discussion on the coming wave of autonomous attacks. Manoj kept landing on one thing: the AI Hurricane has already arrived, and what's left is deciding whether your defense runs at the same speed as the threat.

Frontier models found the vulnerabilities. Only the attacker found the chains.

Attackers don't read your repository; they hit your URL, and chain together whatever they find. In an era where offensive AI runs against live applications at machine speed, your security tooling needs to go beyond finding vulnerabilities to prove exploitability, including whether they can be combined into a breach.

Emerging Threat: (CVE-2026-21589) Atlassian Data Center Arbitrary File Access via Path Traversal

CVE-2026-21589 is an arbitrary file access flaw affecting most of Atlassian’s self-hosted Data Center product line. CISA classifies it as CWE-552, files or directories accessible to external parties. An unauthenticated remote attacker can read specific files inside the web application root directory. The vulnerability carries a CVSS v4.0 base score of 9.3 (Critical). Attack vector is network, attack complexity is low, and neither privileges nor user interaction are required.

How we replaced our host vulnerability scanner with the Datadog Agent

A year ago, Datadog’s cloud environment had grown to support tens of thousands of users across the globe. As our host fleet expanded alongside that user growth, we saw that our original system for vulnerability scanning was becoming less effective at reaching and assessing every host.

Lost in Translation: A Native Heap Overflow in Unmaintained Jansi (CVE-2026-8484)

Jansi is the small Java package that makes colored console output work everywhere, including the Windows terminals that never understood ANSI escape codes. You may not have heard of it, but if you build Java, you almost certainly have it on disk: the Apache Maven 3.9.16 distribution puts jansi-2.4.3.jar in its lib/ directory, and Maven's pom.xml declares it as a dependency.

Emerging Threat: (CVE-2026-94483) Next.js Server-Side Request Forgery via Image Optimization

CVE-2026-94483 is a server-side request forgery flaw in the Image Optimization feature of Next.js, the React framework maintained by Vercel. It is classified as CWE-918. Image Optimization fetches a remote image on the server and re-encodes it. Before fetching, it checks the requested URL against the images.remotePatterns allow-list. The flaw is that the allow-list check and the fetch resolve DNS separately, so a host that passes the check can resolve to a different address by the time the fetch happens.

How to Choose an Application Security Solution

Most teams need a combination of application security tools rather than a single one. Common categories are SAST, DAST, IAST/RASP, SCA, API and container security, and ASPM, and each covers a different stage of development. When you evaluate options, look for coverage that matches your stack, integration with developer workflows, accurate findings, risk-based prioritization, and actionable remediation guidance.

Emerging Threat: (CVE-2026-84411) MikroTik RouterOS Unauthenticated Root RCE via Web Management

CVE-2026-84411 is an integer underflow in the web management service of MikroTik RouterOS, classified as CWE-191. The flaw sits in the service’s HTTP request body handling and is reachable before authentication. A single crafted request lets an unauthenticated network attacker execute arbitrary code as root, or crash the device. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical).

The Year the Vulnerability Backlog Changed Shape

As we enter the AI era, few among us have found themselves so entrenched in the throes of the shifting landscape as CISOs. With the threat landscape shifting, they are up against increasing rates of vulnerabilities and exploits alongside rapidly scaling demands for ever more secure environments. As CISOs, with our role as the protectors of an organization, we are expected to deliver guidance and security visibility. This is not a vision of the future, it’s today’s reality.