Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Reporting a Vulnerability in Somebody Else's Code

A vulnerability in an open-source library inside your product is your vulnerability to report. The duty follows the product to market rather than the code to its author, so integrating somebody else's component transfers the obligation to whoever ships it. ‍ The reporting is the visible half. The harder consequence is that the same regulation requires remediation across the product in its entirety, and the party who wrote the component may have no obligation to help you. ‍

CVE-2026-84869: ConnectWise ScreenConnect Client Vulnerability Critical Remote Session File Transfer Exploitation Risk

A critical security weakness (CVE-2026-84869) has been identified in the ConnectWise ScreenConnect client (prior to version 26.6.5), where missing authorization controls and improper privilege management allow file transfers and execution through active remote sessions without host confirmation.

Is prevention essentially a solved problem?

Stopping new security issues in agent-generated code from being deployed is, architecturally, a solved problem. Prevention is the act of keeping a new vulnerability in code from reaching production at any point in the development and release process, including but not limited to preventing its introduction in a feature branch.

Emerging Threat: (CVE-2026-44756) SAP Remote Code Execution via Extended Passport Processing

CVE-2026-44756, tracked by SAP under the name OVERPASS, is a memory corruption vulnerability in the SAP kernel code that processes the Extended Passport (EPP), a standard SAP tracing structure used to follow call sequences across distributed system landscapes. The flaw stems from missing boundary validation during deserialization of EPP data, which causes unsafe memory behavior when the kernel processes externally supplied length fields. The vulnerability carries a CVSS v3.1 base score of 10.0 (Critical).

The Post-Mythos Era Is Here. Is Your Exposure Management Program Ready?

As AI accelerates vulnerability discovery and exploitation, exposure management can’t stop at visibility and prioritization. Gartner’s post-Mythos outlook points toward more preemptive, autonomous security, and Seemplicity’s Response Options puts that into practice by giving teams multiple context-aware ways to reduce risk quickly, safely, and without waiting for the full fix.

OWASP Top 10 for Large Language Model Applications: Complete Guide to LLM Security Risks

Companies rush to utilise the potential of large language models; however, every new use case of generative AI introduces attack vectors previously unknown in traditional web security. The present guide provides an overview of the official OWASP GenAI LLM Top 10 2026 list and explains the appearance of each vulnerability in practice along with mitigation recommendations.

CISO Risk Intel Brief: Exploited Control Planes, Not Patch Volume, Define Residual Risk

This executive intelligence briefing covers from the past week (2–9 September 2026) and the past month (approximately 10 August – 9 September 2026). CISOs, start here: do not open a 974-row spreadsheet. That queue is the failure mode. This week’s material risk sits in four places you can name before noon.

Compromised Flutter package on pub.dev contains XCSSET malware

Today, pub.dev joins the list of package registries we have found malware on. We detected a variant of XCSSET hiding inside universal_file_viewer (version 0.1.5), a Flutter file preview package on pub.dev with around 500 downloads. This is the first compromised package we have detected on pub.dev, the official package repository for Dart and Flutter. Unlike the recent npm supply chain attacks you might be familiar with, this was not a case of someone deliberately targeting this package.