Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Model Risk Intelligence Know Which Models You Can Trust Before You Deploy

When we started thinking about how to surface AI model risk inside Evo, the obvious answer was to borrow from how we score everything else: find the issue, assign a severity, surface it. Done. The core of the new approach is a real risk score, built the way security teams already reason about risk: Likelihood × Impact. Likelihood comes from Attack Success Rate (ASR), the share of real adversarial attacks that succeed against a model. Impact is how much damage the attacker's goal does when it lands.

A First Look at Evo Agentic AppSec: Agentic Remediation and Malicious Code Defense

The Remediation Agent and Malicious Code Defense are the first two pieces of Evo Agentic AppSec: security that not only surfaces risk, but resolves it and prevents the next ones. This morning, we announced the broadest expansion of the Snyk AI Security Platform to date: discover, remediate, validate, and prevent. A loop with a missing segment is not a loop; it is a gap that an autonomous attacker will occupy. Evo Continuous Offensive Security closes validation and shipped today.

CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching

Threat actors are actively exploiting two high-severity authentication bypass vulnerabilities, CVE-2026-18556 and CVE-2026-18577, in N-able N-Central, a widely deployed remote monitoring and management (RMM) platform used by MSPs and enterprise IT teams. N-able began investigating anomalous activity on July 31 and released an emergency hotfix (2026.3.1.7) on August 2, 2026, to remediate both vulnerabilities.

Copilot RCE, Entra SSRF, and SharePoint Zero-Day: Critical Vulnerabilities in Microsoft's July 2026 Advisory

AI assistants are quietly becoming one of Microsoft’s largest attack surfaces. In its July 2026 advisory, Microsoft patched a command injection vulnerability in Copilot. Crafted prompts can trigger unintended actions through this flaw. The advisory also included a critical SSRF vulnerability in Entra’s identity provisioning service. It carries the among the highest severity score in the entire release. Both point to the same shift.

Oracle's July 2026 CPU: Critical Unauth Vulnerabilities in PeopleSoft, WebLogic, and E-Business Suite

Oracle released its July 2026 Critical Patch Update (CPU) on July 21, delivering 1,449 security fixes across 1,235 unique CVEs, the largest CPU in the company’s history. The release spans 32 product families, with the heaviest concentration in Oracle E-Business Suite, Oracle Fusion Middleware, Oracle Communications, and PeopleSoft. Nine of these CVEs received a perfect CVSS 10.0 score.

The 2026 Buyer's Guide to Open Source Vulnerability Remediation

How to evaluate your options, price the status quo, and make a decision your executive team will actually approve. A note on the numbers. The salaries, headcounts, and costs in this guide are illustrative. They're drawn to be realistic so the math works the way it does in a real budget meeting - but they're examples, not benchmarks. Replace them with your own.

What Claude Mythos Means for Vulnerability Management Programs

If you've been following the cybersecurity conversation over the last several weeks, you've heard some version of the phrase “Claude Mythos changes everything.” It’s dominated the industry news cycles since early April. While the capabilities these stories tout are very much real, I have an issue with the framing being wrong when it comes to vulnerability management. There’s a narrative that Mythos and other frontier models will find too many vulnerabilities to deal with.

Secure at Inception: Announcing the Snyk Studio Integration for Snowflake Cortex Code

Building on our initial partnership that brought Snyk’s security intelligence into the Snowflake AI Data Cloud, we are taking the next step in securing the future of data-driven development. This new collaboration integrates Snyk Studio directly with Snowflake Cortex Code, ensuring that as organizations move their application logic to where their data lives, security remains an inherent part of the process rather than a secondary hurdle. Play Video: YouTube video 1.

Find and stop vulnerable code at runtime - Secure App in Splunk Observability Cloud

Secure App brings runtime application security into Splunk Observability Cloud using the same OpenTelemetry instrumentation as your APM traces to surface the vulnerabilities actually running in production, prioritize them by real-world exploit risk, and catch live attacks. TOC.

From External Exposure to Closed Risk: Seemplicity + IONIX

Modern exposure management has evolved beyond vulnerability scanning and alert volume into a discipline focused on measurable risk reduction. As the exposure management market matures, security leaders are adopting cyber exposure management platforms that unify signals across vulnerability, cloud, application, and attack surface tools to prioritize what truly matters.