Vulnerabilities
Curated coverage and analysis in this editorial area.

Qualys Unveils Risk Operations Center for the 'Day Minus Seven' Era
Qualys published a product-tech blog post on July 8, 2026 introducing the Risk Operations Center (ROC) as an operational response to w…

CISA Orders 3-Day Patch for CVE-2026-55255 in Langflow
An IDOR in Langflow's /api/v1/responses endpoint lets authenticated attackers steal LLM and cloud credentials from other users' flows.…

IRIS C2: Convicted Fraudsters Run Zero-Day Exploit Startup
IRIS C2, a McLean, Virginia startup offering up to $7 million for zero-day vulnerabilities, is operated by Jacob Wohl and Jack Burkman…

KDDI: Zero-Day in Third-Party Software Exposes 12,233,087 Email Addresses
KDDI confirmed a zero-day attack in third-party software compromised the shared email platform of five Japanese ISPs, exposing over 12…

Ubiquiti Patches CVE-2026-50746, Maximum-Severity Flaw in UniFi OS
Ubiquiti released security updates on July 8, 2026 for seven critical vulnerabilities in UniFi OS. The most severe, CVE-2026-50746, ca…

GhostLock: 15-Year Linux Kernel Bug Now Publicly Exploitable, Guarantees Root
CVE-2026-43499 enables root escalation and container escape on nearly every Linux distribution since 2011. Nebula Security published t…

Gartner: By 2028, 60% of Enterprises Will Drop Annual Pentesting for Continuous Validation
Gartner formalizes the COST framework for continuous vulnerability validation. Exploit time has compressed to under 10 hours, and 53%…

X.Org Server: A Forgotten Bug Returns as Privilege Escalation — The ZDI-26-395 Case
A use-after-free flaw in SyncChangeCounter enables local privilege escalation to root on X.Org Server. The bug mirrors a pattern alrea…

Nissan Employees in Four Countries Exposed by Oracle PeopleSoft Zero-Day
Nissan Americas confirmed that attackers exploited CVE-2026-35273, a zero-day vulnerability in Oracle PeopleSoft PeopleTools, to steal…

Exploitarium: The Speed Paradox — Public Exploits for Already-Patched Flaws
Pseudonymous researcher 'bikini' dumped 30+ zero-day PoCs on GitHub without coordinated disclosure. CVE-2026-55200 in libssh2 had a fi…

CSE Discloses Three Offensive Cyber Operations in Rare 2025 Report
Canada's Communications Security Establishment (CSE) revealed in its 2025 annual report that it conducted three authorized offensive c…

Januscape: 16-Year-Old KVM Bug Enables Guest-to-Host Escape on Intel and AMD
CVE-2026-53359 strikes the shared shadow MMU code in Linux KVM used by both Intel and AMD. The flaw has existed since 2010 and require…