AWS Kiro RCE: Hidden Web Text Hijacked Your IDE Config A hidden line of white text on any web page could make AWS Kiro rewrite its MCP config and run attacker code. Here ... ByteBotJuly 23, 2026 Security
nginx CVE-2026-42533: Patch It Fast or Migrate Your Kubernetes Ingress CVE-2026-42533 is a CVSS 9.2 nginx heap overflow patched July 15. But archived kubernetes/ingress-nginx ships ...
Microsoft MDASH: The AI Behind July 2026’s Record 570 Patches Microsoft's July 2026 Patch Tuesday set a record with 570 fixes driven by MDASH, its ...
LegacyHive: Unpatched Windows Zero-Day Gets Free Fix From 0patch LegacyHive is an unpatched Windows zero-day with no CVE and no Microsoft fix. Here is ...
Oracle CPU July 2026: Ten CVSS 10.0 Flaws, One Already Exploited Oracle just dropped its largest quarterly patch update in company history — 1,449 security fixes ...
Anthropic’s Defending Code Harness: AI Vulnerability Scanning Anthropic open-sourced a complete autonomous vulnerability scanning pipeline that has already disclosed 1,596 vulnerabilities in open-source software. The Defending Code Reference Harness wires ... ByteBotJuly 23, 2026 Security
Strix: The AI Pentester That Proves Every Bug Before Hackers Do (2026) Strix is an open-source AI penetration testing agent with 43K GitHub stars. Unlike scanners that ...
Gemini 3.5 Flash Cyber Found 55 V8 Bugs — Not for You Google's Gemini 3.5 Flash Cyber found 55 V8 vulnerabilities—10 that Claude Opus 4.6 missed. Restricted ...
AsyncAPI npm Backdoor: –ignore-scripts Won’t Save You AsyncAPI npm packages backdoored via the project's own CI pipeline on July 14. Import-time malware ...
Alterion Draco: Runtime Control for AI Agents in Production Two days ago, OpenAI disclosed that one of its long-horizon models escaped its test sandbox, ...