AI & software security
-
Cybersecurity and AI: What Mythos means for organisations now
Todd Moore, Vice President of Encryption Products at Thales, examines how AI security models such as Claude Mythos are compressing cyber timelines and reshaping software protection, identity governance, and operational defence.
-
Urgent GeoServer fixes follow exploitation attempts
GeoServer has released urgent security updates for an unauthenticated SQL injection flaw after premature disclosure was followed rapidly by exploitation attempts.
-
Trivy emerges as source of 2,500-org exposure
New analysis indicates that most organisations in a 2,500-plus exposure dataset were caught through the earlier Trivy compromise rather than the short-lived malicious LiteLLM releases.
-
SAP Commerce attacks follow patch by days
Attack traffic is already targeting a maximum-severity SAP Commerce Cloud vulnerability only days after SAP released fixes for the unauthenticated code-execution flaw.
-
Intel and AMD issue broad security updates
Intel and AMD have released extensive August security updates spanning processor firmware, wireless software, AI tooling, trusted computing and development environments.
-
ShieldBreak tests Microsoft Defender patch boundary
A public proof of concept named ShieldBreak can elevate a local Windows user to SYSTEM and is claimed to bypass Microsoft’s earlier fix for the Defender flaw CVE-2026-50656.
-
Adobe patches critical Commerce authorisation flaw
Adobe has fixed a critical unauthenticated authorisation vulnerability in Commerce and Magento Open Source that can allow privilege escalation without administrator access or user interaction.
-
Ransomware fragments as data theft gains ground
Check Point recorded 2,139 ransomware leak-site victims in Q2 2026 as active groups reached a record 93 and smaller affiliate-driven operations gained ground.
-
Microsoft August patch load tops 400 flaws
Microsoft’s August security release covers 421 vulnerabilities, including an exploited Windows privilege-escalation flaw, as enterprise patch volumes remain far above historic norms.
-
Zoom patches meeting-based code execution flaw
Zoom has patched a high-severity annotation vulnerability that could allow one meeting participant to execute code on another participant’s device through network interaction.







