#CVE
43 stories taggedCVE · page 3 of 3.

Google Patches Seven Memory Safety Bugs in Chrome 150, Three Rated Critical
All seven flaws were found internally or by researchers, not by criminals. But history says patch fast anyway.

F5 Fixes Serious Security Flaws in NGINX and BIG-IP
Patches are now available for multiple vulnerabilities in two widely used networking products that could have let attackers take control of systems, crash services, or steal data.

AI Is Finding Software Flaws Faster Than Companies Can Fix Them. Something Has to Change.
Security experts are calling time on the old 'scan once a month, patch when you can' model. Artificial intelligence now finds vulnerabilities faster than human teams can close them.

One Click Was All It Took to Hijack Anthropic's Claude AI
A flaw in the Claude Desktop app let attackers silently feed malicious instructions to the AI and steal private files. The bug is fixed, but the attack method points to a new category of risk.

CISA and NSA Publish Playbook for Working With Outside Bug Hunters
New joint guidance urges software makers and online services to set up formal channels for security researchers, with clear rules, CVE assignments, and the option to lean on national response teams.

569 Patches in One Month: Microsoft Just Broke Every Record on the Books
AI tools are finding software flaws faster than any human team ever could. The result is a single monthly update that dwarfs every full-year fix count from the past two decades.

Adobe Rushes Out Fixes for 88 Security Flaws, Eight of Them Critical in ColdFusion
Two weeks after hackers exploited a separate ColdFusion flaw within hours of its disclosure, Adobe is back with another urgent patch batch covering a dozen products.

The Summer Everyone Launched a Clearinghouse
Vendor announcements have piled up fast. But not every 'clearinghouse' is a fresh idea, and the differences matter more than the marketing suggests.

Google Patches 27 Chrome Flaws, Two Rated Critical
Chrome 150 arrives with fixes for a string of memory-related bugs, most of them found by Google's own engineers rather than outside researchers.

Adobe Is Doubling Its Patch Releases — Here's Why That Matters
Starting in July, Adobe will push security fixes twice a month instead of once. Faster vulnerability discovery, AI-assisted research, and a threat pace that monthly updates can no longer keep up with are all driving the change.

NIST's Cutback on Vulnerability Enrichment Sparks Concerns
New research finds thousands of CVEs left unanalyzed or inaccurately scored after NIST scaled back its National Vulnerability Database work.

Adobe Ships Emergency Fixes for Seven CVSS 10.0 Bugs in ColdFusion, Campaign Classic
Out-of-band advisories cover arbitrary code execution and privilege escalation paths. Self-managed deployments carry the full remediation burden; cloud tenants do not.

The Patch Window Is Now Measured in Hours
AI-assisted exploit development has collapsed the time between disclosure and mass exploitation. Traditional vulnerability management workflows weren't built for this pace.