Vulnerabilities and CVEs CVE-2026-28318: exploited SolarWinds Serv-U DoS flaw
CVE-2026-28318 lets an unauthenticated attacker crash SolarWinds Serv-U with a crafted POST request. Review affected versions, Hotfix 1 and mitigations.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs CVE-2026-28318 lets an unauthenticated attacker crash SolarWinds Serv-U with a crafted POST request. Review affected versions, Hotfix 1 and mitigations.
Vulnerabilities and CVEs CVE-2026-41089 is an actively exploited unauthenticated Netlogon RCE on Windows domain controllers. Review affected systems and response steps.
Vulnerabilities and CVEs CVE-2026-42897 executes JavaScript after a crafted email is opened in on-premises OWA. Review scope, fixes and new OWAReaper evidence.
AI Security DeepMind proposes TRAIT&R, detection levels and 15 safeguards for AI agents. It is a control model for privileged systems, not evidence of AI rebellion.
Governance and Compliance The EU approved a code for AI-generated content transparency. Learn what AI Act Article 50 requires from 2 August and how companies should prepare.
AI Security After temporarily disabling Fable 5, Anthropic described new safeguards and the proposed CJS 0–4 scale. Learn how to assess jailbreak severity.
Identity and Access Credentials linked to more than 70,000 FortiGate devices were leaked. FortiBleed is not a new zero-day: learn the confirmed facts and response steps.
Human Security CERT Polska reports an intense UNC1151/Ghostwriter Gmail campaign. Fake security alerts steal passwords and real-time 2FA codes from Polish users.
AI Security GPT-5.6 is more capable but more likely to exceed user intent in agent tasks. We analyse OpenAI's tests and practical controls for safe deployment.
AI Security Natural AI voices make explicit disclosure essential. We connect GPT-Live's launch with AISI research on whether models reveal their identity consistently.
AI Security NIST explains why finite rule sets cannot guarantee universal protection against adaptive prompts and how to build continuously tested, layered AI controls.
Human Security OpenAI's local model detects and masks PII, but it does not guarantee anonymisation or GDPR compliance. Build a safer pipeline for European data.
Threats and Incidents Operation Endgame targeted 326 servers and 142 domains linked to SocGholish, Amadey and StealC. What the action achieved and defenders should do.
Supply Chain Security AI found hundreds of potential flaws across major open-source projects, but triage, reproduction, safe patches and maintainer review remain essential.
Human Security FBI and CISA warn that Russian-linked actors are phishing Signal backup recovery keys. Learn how the attack works and how to respond safely.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.