#CVE
43 stories taggedCVE · page 2 of 3.

August 2026 ICS Patch Tuesday: Siemens, Schneider Electric and Phoenix Contact Fix Serious Flaws in Factory Equipment
A batch of August security updates covers industrial control systems that run factories, power networks and buildings. One Siemens flaw scores the maximum possible severity rating and lets attackers run any code they like on a connected device without needing a password.

Some of the Bugs That Hid Inside Everyday Software for Decades
From a print-spooler flaw that Stuxnet quietly exploited to a 30-year-old graphics library hole, a handful of the most stubborn software vulnerabilities ever found show how long danger can lurk unnoticed.

AI Found Thousands of Flaws in Days. Humans Can't Patch Them Fast Enough.
Anthropic's Claude Mythos model discovered more security holes in major software than years of human review had caught. That's good news for defenders in theory, but the gap between finding a flaw and fixing it was already brutal before AI joined the hunt.

AI Patches Security Flaws Correctly Only 26% of the Time, 1Password Study Finds
An internal evaluation by the security company 1Password found that AI coding tools produce flawed or incomplete security fixes more than half the time, and sometimes make things worse.

Google Patches 41 Security Flaws in Chrome 151, Six Rated Critical
The latest Chrome update fixes a cluster of memory-safety bugs that could let attackers crash your browser or run malicious code on your device. Here is what happened and what you should do.

Google Patches 370 Security Flaws in Chrome 151, Including Seven Critical Bugs
The browser update is one of Google's largest single releases of the year, fixing flaws that could let attackers take control of your browser or crash it entirely.

Can You Still Patch Your Way to Safety? Why the Old Playbook Is Breaking Down
Artificial intelligence can now turn a published vulnerability description into a working attack faster than most IT teams run their patch cycles. That changes the math for every organisation still relying on traditional schedules.

What is a CVE and how does vulnerability scoring work?
CVEs are the universal ID system for software flaws, and CVSS scores tell you how bad each one actually is.

What is a zero-day vulnerability? A plain-English guide
Zero-days are unpatched security flaws the software vendor doesn't know about yet, making them among the most dangerous bugs in existence.

Microsoft Wants You to Patch in Three Days. Security Teams Say That's Not How It Works.
Microsoft is telling IT administrators to apply security fixes within 72 hours, citing AI tools that find and exploit software flaws faster than ever. Experts agree on the threat. They disagree, sharply, on whether three days is workable.

Oracle Patches 1,434 Flaws in One Go. AI Probably Found Most of Them.
Oracle's July 2026 quarterly security update is the largest in the company's history, covering hundreds of products used by hospitals, banks, retailers, and governments worldwide.

AI Security Scanners Are Drowning Teams in False Alarms, and the Fix Isn't More AI
More than 60% of flagged security flaws are noise. A researcher who tested over a dozen tools says AI models make the problem worse because they lack the context to tell a real threat from a ghost.

Cisco Builds Cheaper AI Tools to Hunt Security Flaws in Software Code
The company's new Antares models scan source code for known vulnerabilities at a fraction of what larger AI systems cost. Here is what that means for businesses that write or buy software.

Empirical Raises $25 Million to Predict Cyber Attacks Before They Happen
A Chicago startup says its AI tools can spot which security flaws are most likely to be exploited next. Investors just bet $25 million that it's right.

The Real Mythos Problem Isn't New Bugs. It's How Long Yours Stay Open.
Anthropic's AI-driven vulnerability finder has flooded the pipeline since April. But the harder question for defenders is how many days a known flaw sits unpatched on their own network.