#CVSS
6 stories taggedCVSS.

Your Scariest Vulnerabilities Might Not Be the Ones That Get You Hacked
Scanner reports full of 'critical' flags are drowning security teams. The real question is which of those flags actually give an attacker a path in.

AI Found Thousands of Flaws in Days. Humans Can't Patch Them Fast Enough.
Anthropic's Claude Mythos model discovered more security holes in major software than years of human review had caught. That's good news for defenders in theory, but the gap between finding a flaw and fixing it was already brutal before AI joined the hunt.

Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical
An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

Veeam Console Bug Hands Over Agent Credentials; Terraform MCP Server Leaks Tokens Between Users
Eleven fixes across HashiCorp, Veeam and Django include a 9.5-rated Veeam flaw and a cross-tenant Terraform MCP Server bug that hands one customer's cloud token to the next caller.

What is a CVE and how does vulnerability scoring work?
CVEs are the universal ID system for software flaws, and CVSS scores tell you how bad each one actually is.

Security Debt Is Growing Faster Than Companies Can Fix It. Here Is What That Means.
Eight in ten organisations carry a backlog of unresolved security flaws older than a year. A practical framework explains how to turn that reality into a board-level conversation.