Vulnerability Disclosures Will Pass Last Year's Record by August. The Share Anyone Actually Exploits Is Falling
AI code scanning has pushed disclosures to 45,207 in seven months. Our own count of the exploited-vulnerabilities catalo...
ASEAN edition · Fri, 2 Oct 2026 · Signal over noise
AI-curated tech news, ASEAN business intelligence, and cybersecurity updates — written for the region.
AI code scanning has pushed disclosures to 45,207 in seven months. Our own count of the exploited-vulnerabilities catalo...
A coordinated attack reached operational technology at more than 30 municipal water systems. One plant went offline for...
CVE-2026-50522 was exploited hours after proof-of-concept code appeared, and stolen machine keys survive the patch. Our...
The advisory is exemplary and the hotfix shipped the same day. The pattern behind it is the story: two of Check Point's...
We measured every deadline in the KEV catalog's 1,653 entries. The 21-day window was retired on 5 March; BOD 26-04 arriv...
Japan's privacy regulator recorded 19,417 breach notifications in FY2025, the second-highest on record but down 7.6% yea...
SentinelLabs reports that suspected China-nexus and India-nexus groups ran separate espionage campaigns against Pakistan...
Taiwanese investigators have issued deferred prosecution orders against two executives who, prosecutors allege, leased l...
Two Scattered Spider members were sentenced to five and a half years each on 16 July for the 2024 Transport for London a...
Microsoft's July update fixed more than 600 CVEs — its biggest ever — including two zero-days already under attack in AD...
Nichirei, Japan's largest cold-chain logistics operator, was hit by a cyberattack on 13 July. Containing it meant discon...
An extortion group posted files it claims come from a Kudankulam contractor's servers. India says no nuclear safety syst...
Australia's privacy regulator closed its inquiry into the 2025 Qantas breach on 16 July without opening a formal investi...
Nissan, NAIC and a wave of universities are disclosing breaches that trace to one Oracle PeopleSoft zero-day, CVE-2026-3...
A forum seller claims to have taken 35GB of Accenture source code and cloud credentials; Accenture acknowledges an isola...
CISA added a maximum-severity Adobe ColdFusion path-traversal flaw to its exploited-vulnerabilities catalog on 7 July, w...
On 7 July 2026, CISA added an actively-exploited vulnerability in Langflow — a popular open-source framework for buildin...
CVE-2026-8451 is a CitrixBleed-class, unauthenticated memory-overread flaw in Citrix NetScaler ADC and Gateway appliance...
Google's Threat Intelligence Group, working with the FBI, Lumen and other partners, has disrupted NetNut — a residential...
CISA added CVE-2026-45659, a CVSS 8.8 deserialization remote-code-execution flaw in on-premises Microsoft SharePoint Ser...
Cisco disclosed CVE-2026-20245 on 5 June 2026, a high-severity command-injection flaw in Catalyst SD-WAN Manager that Ma...
FortiBleed is a large-scale credential-exposure campaign against internet-facing Fortinet FortiGate firewalls and SSL VP...
CVE-2026-46331, nicknamed pedit COW, is a Linux kernel local privilege-escalation flaw in the traffic-control act_pedit...
CISA added CVE-2026-12569, a critical remote code execution flaw in PTC Windchill PDMLink and FlexPLM, to its Known Expl...