Microsoft Fixed 421 Flaws. Or 400. Only One Is Being Exploited.
Three different totals are circulating for the same Patch Tuesday, and all are defensible. The one number that matters i...
ASEAN edition · Tue, 18 Aug 2026 · Signal over noise
AI-curated tech news, ASEAN business intelligence, and cybersecurity updates — written for the region.
Three different totals are circulating for the same Patch Tuesday, and all are defensible. The one number that matters i...
Birmingham researchers surveyed 26 devices and found nine expose an interface that lets the SIM issue modem commands. Th...
Every vulnerability CISA catalogued in the first week of August carried a three-day federal deadline. We measured the ca...
No plugin update was published. Attackers reached BdThemes storage, poisoned a feed the plugins pull into the admin dash...
Ransomware crews are now chaining two SonicWall SMA1000 flaws that CISA gave federal agencies three days to fix. If your...
Klaviyo's signup form was misconfigured so third-party marketing trackers captured what users typed, including passwords...
CERT Polska has documented the first real-world use of a private APN as a route into operational technology. Thirty wind...
Framework and Tally were both breached on 3 August through a zero-day in Metabase, the business-intelligence tool they u...
Water systems in at least twelve US states have been broken into, with attackers changing controller passwords and IP ad...
China's Cybersecurity Review Office opened a formal review into Palo Alto Networks products on 6 August — seven months a...
MIT researchers showed that Spectre v2 mitigations can be stepped around on current Intel and AMD processors, breaking K...
N-able patched a critical authentication bypass in N-central, attackers found a path the patch did not block, and a seco...
Three flaws in CatchPulse, the worst letting an unprivileged local user bypass policy enforcement. Reported 26 June, pat...
Two flaws score 9.8. The 9.3 lets an attacker with admin rights inside a virtual machine execute code on the host beneat...
CVE-2026-34486 exists because of the fix for CVE-2026-29146. CSA reports active exploitation, and the catalogue lists th...
CVE-2026-9198 gives unauthenticated remote code execution on default Langflow deployments. CISA allowed three days; CSA...
A Singapore Land Authority test dataset created in 1998 was meant to hold only mock records. It held real names, NRIC nu...
CISA gave three days to fix an actively exploited N-able bypass. Across the catalogue, the three-week remediation window...
AI code scanning has pushed disclosures to 45,207 in seven months. Our own count of the exploited-vulnerabilities catalo...
A coordinated attack reached operational technology at more than 30 municipal water systems. One plant went offline for...
CVE-2026-50522 was exploited hours after proof-of-concept code appeared, and stolen machine keys survive the patch. Our...
The advisory is exemplary and the hotfix shipped the same day. The pattern behind it is the story: two of Check Point's...
We measured every deadline in the KEV catalog's 1,653 entries. The 21-day window was retired on 5 March; BOD 26-04 arriv...
On 7 July 2026, CISA added an actively-exploited vulnerability in Langflow — a popular open-source framework for buildin...