Common Vulnerabilities and Exposures (CVE) stories
Cloud breaches driven by identity failures & process flaws
This month
#
cve
ReliaQuest reveals identity compromises and process flaws, not zero-day exploits, drive most cloud breaches, with 99% of cloud identities still over-privileged.
Rapid7 adds AI risk summaries to Command Platform for faster response
Last month
#
cve
Rapid7 has added AI-generated risk summaries to its Command Platform, helping security teams speed up prioritisation and remediation of vulnerabilities.
Study finds CVE security scores flawed, with third unsubstantiated
Last month
#
cve
Nearly one-third of CVE entries are unverified, revealing flaws in how organisations assess software security risks and reliance on CVSS scores.
Azul launches TAP Program to boost global Java innovation & security
Wed, 24th Sep 2025
#
cve
Azul launches its Technology Alliance Partner Program to enhance global Java innovation, boosting performance, security, and cost-efficiency for enterprises.
Preemptive cybersecurity to reach 50% of IT security spend by 2030
Fri, 19th Sep 2025
#
cve
Preemptive cybersecurity is set to command 50% of IT security spend by 2030, driven by AI and machine learning to counter rising cyber threats, says Gartner.
Global ransomware attacks rise as healthcare faces surge in cyber threats
Fri, 22nd Aug 2025
#
cve
Ransomware attacks surge to 20 daily incidents in 2025H1, with healthcare facing increased cyber threats and hackers targeting overlooked IoT devices worldwide.
Black Kite unveils ASI for targeted third-party cyber risk
Sat, 9th Aug 2025
#
cve
Black Kite has launched its Adversary Susceptibility Index to help firms spot which suppliers are most exposed to specific cyber threat actors, enhancing risk management.
Aqua Security unveils Trivy Partner Connect to boost open source
Tue, 8th Jul 2025
#
cve
Aqua Security launches Trivy Partner Connect to strengthen the ecosystem around its popular open source security scanner, Trivy, boosting collaboration and innovation.
BackBox 8.0 automates hybrid network security & compliance
Thu, 26th Jun 2025
#
cve
BackBox 8.0 unifies and automates security and compliance across hybrid networks, helping firms manage on-premise and cloud assets with a single dashboard.
Multiple brother devices: Multiple vulnerabilities (FIXED)
Thu, 26th Jun 2025
#
cve
Security researcher Rapid7 has uncovered 8 vulnerabilities in 742 printer models from Brother, FUJIFILM, Ricoh, and Toshiba, with fixes now available.
Azul enhances Java security detection, cutting false positives by 99%
Fri, 13th Jun 2025
#
cve
Azul's new Java security tool cuts false positives by 99%, boosting detection accuracy and helping DevOps teams focus on real risks in production code.
Azul boosts Java security with improved runtime vulnerability detection
Fri, 13th Jun 2025
#
cve
Azul’s Intelligence Cloud now cuts Java security false positives by up to 99%, using runtime data to boost vulnerability detection accuracy for DevOps teams.
Azul unveils Java tool to cut false positives by up to 99%
Wed, 11th Jun 2025
#
cve
Azul has launched a Java vulnerability tool that cuts false positives by up to 99%, improving threat detection accuracy for production environments.
Picus launches tool for real-time validation of exploitable risks
Fri, 23rd May 2025
#
cve
Picus Security launches Exposure Validation, a tool using real-time attack simulations to identify which vulnerabilities are truly exploitable in organisations.
IP Fabric unveils upgrade to boost firewall visibility & compliance
Thu, 22nd May 2025
#
cve
IP Fabric launches version 7.2 to enhance firewall visibility and compliance, aiding enterprises in detecting misconfigurations and enforcing security policies.
Red Hat launches Advanced Developer Suite with focus on AI
Wed, 21st May 2025
#
cve
Red Hat launches Advanced Developer Suite on OpenShift, enhancing developer productivity, AI integration, and application security with new tools and templates.
Red Hat Enterprise Linux 10 brings AI & post-quantum security
Wed, 21st May 2025
#
cve
Red Hat launches Enterprise Linux 10, featuring AI integration, enhanced security with post-quantum cryptography, and hybrid cloud support for enterprises.
Emojis used to hide attacks & bypass major AI guardrails
Wed, 7th May 2025
#
cve
Mindgard reveals emoji smuggling can bypass AI guardrails from Microsoft, Meta, Nvidia, and others with up to 100% attack success, raising serious security concerns.
Black Kite launches tool for third-party vulnerability insight
Fri, 2nd May 2025
#
cve
Black Kite launches Vulnerability Intelligence Briefs to help organisations identify and manage third-party cyber risks, enhancing supply chain security.
Minimus launches with USD $51 million to cut 95% of CVEs
Wed, 30th Apr 2025
#
cve
Minimus launches with USD $51 million to cut 95% of CVEs in software supply chains, offering secure components and faster vulnerability reduction.