Common Vulnerabilities and Exposures (CVE) stories
Microsoft patches major SQL Server flaw in March update
Today
#
firewalls
#
network security
#
mfa
Microsoft's March Patch Tuesday fixes 77 flaws, including a severe SQL Server bug that could grant attackers sysadmin rights remotely.
ControlPlane unveils enterprise support for OpenBao
Yesterday
#
encryption
#
pam
#
cloud security
ControlPlane launches enterprise support for OpenBao as IBM's USD $6.4 billion HashiCorp deal drives demand for open source Vault alternatives.
Wireless CVEs surge, exposing hidden risks for AI centres
Yesterday
#
uc
#
firewalls
#
surveillance
Wireless flaws have surged 230-fold since 2010, as Bastille warns AI data centres and critical infrastructure face escalating unseen risks.
AI-driven phishing surge as Acronis warns MSPs at risk
Last month
#
malware
#
ransomware
#
cloud security
Acronis warns AI is turbocharging phishing, email attacks and ransomware in 2025, with MSPs and collaboration tools under rising fire.
Simbian unveils AI agent for continuous pentesting
Last month
#
data protection
#
devops
#
application security
Simbian launches an AI Pentest Agent that runs continuous, adaptive penetration tests, promising faster, context-aware vulnerability detection.
Data-only extortion surges as remote access abused
Last month
#
data protection
#
dr
#
vpns
Data-only extortion soars 11-fold as attackers 'log in instead of break in', abusing remote access tools for faster, stealthier raids.
Cybersecurity teams brace for surge in global CVEs in 2026
Last month
#
siem
#
cloud security
#
supply chain
Cyber group FIRST warns CVE disclosures could smash records in 2026, topping 50,000 and potentially surging towards six figures.
Black Kite unveils tool to analyse third-party software risk
Thu, 8th Jan 2026
#
saas
#
supply chain
#
risk & compliance
Black Kite launches Product Analysis tool to expose hidden risks in third-party software, from SaaS subdomains to SBOM dependencies.
Codific predicts nine key cybersecurity shifts for 2026
Wed, 24th Dec 2025
#
data protection
#
digital transformation
#
encryption
Codific sees 2026 cybersecurity shaped by shadow AI, passwordless logins, tighter regulation and a sharper focus on software supply chains.
Minimus launches Image Creator for custom container images
Thu, 20th Nov 2025
#
hyperscale
#
cloud security
#
application security
Minimus unveils Image Creator, enabling enterprises to build secure, custom container images with enhanced compliance and reduced vulnerabilities.
Cloud breaches driven by identity failures & process flaws
Thu, 6th Nov 2025
#
malware
#
cloud security
#
phishing
ReliaQuest reveals identity compromises and process flaws, not zero-day exploits, drive most cloud breaches, with 99% of cloud identities still over-privileged.
Rapid7 adds AI risk summaries to Command Platform for faster response
Thu, 30th Oct 2025
#
risk & compliance
#
ai
#
cybersecurity
Rapid7 has added AI-generated risk summaries to its Command Platform, helping security teams speed up prioritisation and remediation of vulnerabilities.
Study finds CVE security scores flawed, with third unsubstantiated
Fri, 17th Oct 2025
#
application security
#
cybersecurity
#
security industry
Nearly one-third of CVE entries are unverified, revealing flaws in how organisations assess software security risks and reliance on CVSS scores.
Azul launches TAP Program to boost global Java innovation & security
Wed, 24th Sep 2025
#
virtualisation
#
public cloud
#
cloud security
Azul launches its Technology Alliance Partner Program to enhance global Java innovation, boosting performance, security, and cost-efficiency for enterprises.
Preemptive cybersecurity to reach 50% of IT security spend by 2030
Fri, 19th Sep 2025
#
data protection
#
advanced persistent threat protection
#
supply chain
Preemptive cybersecurity is set to command 50% of IT security spend by 2030, driven by AI and machine learning to counter rising cyber threats, says Gartner.
Global ransomware attacks rise as healthcare faces surge in cyber threats
Fri, 22nd Aug 2025
#
firewalls
#
ransomware
#
encryption
Ransomware attacks surge to 20 daily incidents in 2025H1, with healthcare facing increased cyber threats and hackers targeting overlooked IoT devices worldwide.
Black Kite unveils ASI for targeted third-party cyber risk
Sat, 9th Aug 2025
#
ransomware
#
advanced persistent threat protection
#
supply chain
Black Kite has launched its Adversary Susceptibility Index to help firms spot which suppliers are most exposed to specific cyber threat actors, enhancing risk management.
BackBox 8.0 automates hybrid network security & compliance
Thu, 26th Jun 2025
#
firewalls
#
network infrastructure
#
network security
BackBox 8.0 unifies and automates security and compliance across hybrid networks, helping firms manage on-premise and cloud assets with a single dashboard.
Azul enhances Java security detection, cutting false positives by 99%
Fri, 13th Jun 2025
#
saas
#
devops
#
application security
Azul's new Java security tool cuts false positives by 99%, boosting detection accuracy and helping DevOps teams focus on real risks in production code.
Azul boosts Java security with improved runtime vulnerability detection
Fri, 13th Jun 2025
#
devops
#
application security
#
apm
Azul's Intelligence Cloud now cuts Java security false positives by up to 99%, using runtime data to boost vulnerability detection accuracy for DevOps teams.