Shift from CVE counts to risk-based vulnerability management in the AI era
AI accelerates exploit creation, making static severity scores insufficient. Teams must prioritize vulnerabilities based on actual production exposure and reachability.
Daily coverage of AI, developer tools and infrastructure. Each story explains what happened and why it matters, with a link to the original source.
AI accelerates exploit creation, making static severity scores insufficient. Teams must prioritize vulnerabilities based on actual production exposure and reachability.
GitLab released urgent fixes for CVE-2026-90970, a critical vulnerability in self-hosted AI Gateways that allows command execution via crafted prompt templates.
CISA adds CVE-2026-104286 to its KEV catalog as attackers exploit a critical path traversal flaw in Fortinet FortiMail to write arbitrary files.
OpenSSL released fixes for CVE-2026-84782, a high-severity flaw in DTLS that can leak heap memory or crash services. Updates are available for supported branches, but older versions require premium su