Supply Chain Attack
New GitHub, PyPI Policies Boost Supply Chain Security
Three days for GitHub, fourteen for PyPI — the poisoned-package window narrows this week.
Stay ahead of security risks with effective patch management. Explore strategies, tools, and processes for applying updates, fixing vulnerabilities, and protecting systems from exploits and cyberattacks.
Supply Chain Attack
Three days for GitHub, fourteen for PyPI — the poisoned-package window narrows this week.
Vulnerabilities
An unpatched Fastjson 1.x RCE under active attack — a defender review for Spring Boot deployments this weekend.
Vulnerabilities
A Check Point SmartConsole authentication bypass under active attack — defender teams accelerate patch verification this week.
Artificial Intelligence (AI)
OpenAI patches an AI-insider-forgery vulnerability in ChatGPT Agent — defender review this week.
Vulnerabilities
Oracle's July CPU pushes past 1,400 CVEs — the AI-discovery patch-volume trend continues across major enterprise vendors this week.
Vulnerabilities
SharePoint's fourth actively-exploited flaw in a month lands with a machine-key-theft twist — defender teams patch AND rotate this week.
Vulnerabilities
A crafted XZ archive can run code in 7-Zip — defender teams verify the 26.02 update this week.
Vulnerabilities
wp2shell moves from active exploitation to mass takeover — hosting providers and defender teams accelerate remediation this week.
Vulnerabilities
A ServiceNow AI Platform sandbox escape under active attack — defender teams accelerate patch verification this week.
Vulnerabilities
A critical NGINX flaw with remote-unauthenticated attack surface — defender verification across NGINX and NGINX Plus deployments this week.
Vulnerabilities
wp2shell moves from disclosure to active exploitation — defender teams and hosting providers accelerate verification this week.
Vulnerabilities
WordPress ships the 7.0.2 patch pairing wp2shell with a fresh SQL-injection CVE — defender teams and hosting providers apply immediately this weekend.