<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/highlights/security" -->

---
title: Highlights | daily.dev
description: daily.dev is the easiest way to stay updated on the latest programming news. Get the best content from the top tech publications on any topic you want.
canonical: https://daily.dev/highlights/security
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:url: https://daily.dev/highlights/security
og:site_name: daily.dev
og:title: Highlights | daily.dev
og:description: Curated highlights from across the developer ecosystem. Stay on top of the most important stories, releases, and discussions.
og:type: website
og:image: https://media.daily.dev/image/upload/s--VAY5ToZt--/f_auto/v1724209435/public/daily.dev%20-%20open%20graph
---

curl 8.22.0 ships with 9 security fixes and 10 new CVEs8m ago

CrowdStrike launches SafeMind agentic security system built on open Nemotron models3h ago

Law enforcement and CrowdStrike disrupt Sality botnet via sinkholing6h ago

AI models successfully port ICS exploit across PLC models in 8.5 hours6h ago

FBI investigates Nexus dark web service selling 153M drivers license scans6h ago

AI-generated phishing click-through rates jump from 12% to over 60% in one year7h ago

X warns of mass account targeting after X Money payments launch9h ago

Attacker drains $600K in AI credits from METR using stolen API key undetected for weeks9h ago

ClickHouse acquires security data platform RunReveal11h ago

Memory-safety bug in PostGIS address\_standardizer affects Databricks and Neon managed Postgres11h ago

Fable 5.1 agent fabricates user permission quote to bypass delete safety limit11h ago

Slim 4.15.3 patches route parameter constraint bypass vulnerability12h ago

Leaked materials reveal Russian university pipeline funneling graduates into Sandworm and GRU cyber units13h ago

Flock Safety faces wave of contract cancellations over unauthorized surveillance access14h ago

Researchers dispute X's claim that Chinese bots drove US data center opposition14h ago

Tampered Exodus wallet installer deploys modular RAT with Azure dead-drop C215h ago

Fastify details a year of npm supply chain hardening after GitHub OSS Fund audit16h ago

Security roundup: AI coding agents weaponized in ransomware attacks and supply chain poisoning in August 202616h ago

Unauthenticated exploit chain in UNISOC baseband grants full Android kernel access16h ago

Cursor flaws expose developers to code execution and API secret theft17h ago

WordPress narrows vulnerability disclosure scope to high-impact privilege escalations17h ago

33-hour BGP hijack of Softaculous traffic forces credential reset scramble18h ago

Microsoft details TerminalFix campaign using fake Cloudflare CAPTCHAs to plant reverse tunnels19h ago

Meta removes banking malware ads in India only after repeated prompting20h ago

OpenAI agents escape sandboxes and hit real organizations during safety evaluations20h ago

Mirage Kitten APT targets software engineers with trojanized npm packages via fake job challenges23h ago

ContextLeak attack tricks AI agents into leaking runtime context via malicious tool descriptions24h ago

Researchers train Opus-sized model that generalizes reward hacking into cyberattacks and safety evasion30h ago

Apple court filing alleges ex-engineer used confidential chip schematics with AI agent at OpenAI31h ago

Pirate streaming boxes secretly enroll home networks into residential proxy networks31h ago

Traefik HTTP/3 timeout bypass lets attackers exhaust backend connection pools32h ago

Windows Defender bug falsely reports antivirus is off across Windows 10 and 1133h ago

Amazon Cognito adds M2M token API without requiring a user pool domain34h ago

Multiple US military base commissaries report simultaneous refrigeration outages35h ago

13 malicious Packagist themes deliver iOS spyware stealing crypto wallet seeds38h ago

Express.js patches six vulnerabilities across hbs, multer and morgan middleware38h ago

Istio 1.31.0 ships with agentgateway waypoint support and FIPS 140-3 compliance38h ago

Reform UK proposes scrapping UK GDPR in favour of New Zealand privacy model40h ago

Check Point reverse-engineers JSCeal V8 bytecode infostealer and open-sources toolkit40h ago

Anthropic research shows Claude fixed all 10 alignment failures but cheated in 2.4% of trials41h ago

ValleyRAT backdoor spreads via signed adware installer using DLL sideloading44h ago

Spring Ring vishing campaign hits 150 employees across 10 companies via Microsoft Teams44h ago

19 Chrome and Edge extensions weaponized in supply chain campaign targeting 70K users44h ago

Servo 0.5.0 ships aarch64 Linux binaries, 55% canvas speedup and Android 10 support44h ago

Symfony 6.4, 7.4 and 8.1 ship coordinated security hardening releases56h ago

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage63h ago

METR and Redwood Research publish findings on OpenAI agent coordination incident3d ago

FreeBSD 14.5-RC1 ships with local privilege escalation fixes ahead of September release3d ago

AI crawlers consume 20% of Linux kernel git infrastructure capacity3d ago

Sony Music and Warner Chappell sue Anthropic in multi-billion dollar copyright case4d ago

Russian-linked malware campaign hides in 52 fake GitHub repos impersonating AI and security tools4d ago

Redis patches critical use-after-free RCE in TLS processing across 8 versions4d ago

Cursor quietly removes transparency language about code indexing and metadata storage from terms4d ago

ShinyHunters claims 284 million patient records stolen from McKesson via Okta SSO attack4d ago

Supply chain worm Trinitite hits npm TanStack Query codegen package with 150K weekly downloads4d ago

Prompt injection in Gemini CLI triage workflow exposed Google Cloud Editor credentials4d ago

GiveWP WordPress donation plugin gets max-severity RCE patch after prior breach4d ago

Meta updates Ray-Ban glasses to stop recording when LED is covered5d ago

WordPress launches Core Security Initiative to handle AI-driven surge in vulnerability reports5d ago

Linux kernel patches CVE-2026-80590 across eight stable releases simultaneously5d ago

Linux kernel CVE count approaches 2,000 per release as AI scanning accelerates5d ago

Google open-sources giflib-rs after AI-assisted C-to-Rust rewrite catches real CVE5d ago

AI-generated bug reports flood bounty platforms, forcing curl to shut down its program5d ago

Threat actors weaponize Claude and ChatGPT shared links to deliver malware5d ago

GitHub Copilot changes billing rules and unifies chat experience from September 20265d ago

Hasbro discloses employee data breach exposing Social Security numbers and financial data5d ago

JetBrains discloses Cadence breach exposing customer source code and AWS secrets5d ago

ServiceNow patches three max-severity RCE and SQL injection flaws in AI Platform5d ago

Windows 11 KB5120998 adds taskbar repositioning, removes WMIC utility5d ago

Germany's Sovereign Tech Agency invests €508K in Flatpak sandboxing and portals5d ago

Metabase patches chained SQL injection zero-day that compromised cloud customers5d ago

US sanctions Italian hacker collective Autistici/Inventati as terrorist organization5d ago

ZBT router backdoors found in devices sold worldwide under dozens of brand names5d ago

Black Hat 2026 centers on CVE program scaling failures and rogue AI agents5d ago

CRPx0 ransomware-as-a-service claims victim count grew fivefold to 48 organizations5d ago

Kubernetes 1.37 retires kube-dns, IPVS mode and cgroup v1 support5d ago

Google runs first double-blind evaluation of Gemini using confidential computing5d ago

AI coding agents exploited as malware delivery systems via poisoned repos5d ago

rsync 3.5.0 security audit ships 33 fixes including a HIGH-severity CVE5d ago

PaperCut patches zero-day under active exploitation in NG and MF print software5d ago

Rust Foundation names Jess Izen as Engineer in Residence to harden crates.io security5d ago

Researcher details cleartext credential recovery technique in ServiceNow6d ago

Brave launches accounts system using OPAQUE protocol so passwords never reach servers6d ago

Manchester Airports Group confirms customer data stolen in breach6d ago

Over 100 tech organizations sign open letter calling for global cyber defense surge6d ago

Apache Tomcat, Chrome 152 and asyncssh receive critical security patches6d ago

TONTOU attack bypasses Spectre defenses on Intel and AMD processors6d ago

Kimi K3 faces US sanctions threat, chip smuggling accusations and benchmark fraud claims6d ago

Istio patches control-plane DoS and BackendTLSPolicy fail-open plaintext bug6d ago

Telstra's July outage traced to unpatched NTP server GPS rollover bug from 20006d ago

Russian group BlueDelta targets European defense orgs with HOOKEDGE backdoor6d ago

Nvidia reportedly in acquisition talks to buy Hugging Face for $12.9 billion6d ago

Fake Bloomberg journalist accounts target crypto users with malicious video call apps6d ago

Hidden HTML tricks AI email summarizers into falsifying invoice amounts and deadlines6d ago

Russian state hackers shift spear-phishing to Signal and WhatsApp targeting EU officials6d ago

Australian police arrest TeamPCP members behind LiteLLM and open source supply chain attacks6d ago

AppArmor in Linux 7.3 adds user-space compressed policy support with 30% speed gain6d ago

OpenAI disrupts Cambodia-based AI-powered scam network using ChatGPT6d ago

Cloudflare Wallets launches for AI agent payments but most features still pending6d ago

UK energy attack and US water utility breaches expose critical infrastructure security gaps6d ago

ATF confirms major incident after Qilin ransomware gang claims breach6d ago

Researchers find TEE attacks targeting Signal contact discovery enclaves6d ago

Quarkus 3.39 adds post-quantum cryptography support to TLS registry6d ago

Two Ruby resolv gem CVEs enable memory exhaustion and SSRF hostname bypass6d ago

Command injection and SQL injection patched in spatial\_features Ruby gem6d ago

Anthropic adds built-in Chromium browser to Claude desktop app6d ago

Critical RCE chain in Avada WordPress theme patched after agentic exploit discovery6d ago

pnpm 12 ships as full Rust rewrite with no migration required6d ago

GPUThor attack defeats NVIDIA ECC protection on Ampere workstation GPUs6d ago

Researcher finds HTML tag names can execute JavaScript across all major browsers6d ago

Anthropic launches Claude in Chrome browser agent to general availability7d ago

GitHub Actions suffers degraded performance with recovery underway7d ago

Unauthenticated RCE chain found in Veeam Service Provider Console affects all 9.x builds7d ago

ShinyHunters' 24.8M Carhartt breach claim shrinks to 12.9M after synthetic data found in dump7d ago

Ericsson submits 1,400 upstream fixes to comply with EU Cyber Resilience Act7d ago

Attackers register hallucinated package names to deliver malware via AI coding agents7d ago

FBI disrupts Chinese espionage proxy network used against US military and infrastructure7d ago

Huntress documents five North Korean operatives hired into healthcare and financial services roles7d ago

Boston Scientific discloses cybersecurity incident disrupting global order processing7d ago

US corporate attacks shift from data theft to production disruption in 20267d ago

Ubiquiti patches three max-severity unauthenticated RCEs across UniFi product line7d ago

Linus Torvalds says AI-generated patches are flooding Linux kernel maintainers7d ago

Joint Tenable and SentinelOne analysis finds 79% overlap in edge vendors exploited by state actors and ransomware groups7d ago

Researchers propose two-layer detector for AI-hallucinated Python package slopsquatting7d ago

Chinese state hackers use DeepSeek to double attack volume against EU targets7d ago

Microsoft tests per-app camera and microphone controls for Windows 11 desktop apps7d ago

Dark Caracal deploys Go-based GoCaracal malware with blockchain-based C2 fallback7d ago

Actively exploited Gitea RCE flaw added to CISA KEV with August 28 patch deadline7d ago

Keycloak CVE-2026-18963 lets unauthenticated attackers reset any user password7d ago

Ray CVE-2025-62593 allows RCE on developer laptops via DNS rebinding, CISA flags active exploitationAug 25

Minimus shuts down hardened container registry with 60-day migration windowAug 25

Researcher shows C2PA camera provenance is broken on fully-patched Pixel devicesAug 25

Brazil fines ByteDance $29.9m over children's data including guest sessionsAug 25

X sends cease-and-desist to Nitter demanding permanent shutdown after seven yearsAug 25

Hackers abuse npm mirrors to host phishing redirect pages on trusted domainsAug 25

AnonyMousKIT PhaaS uses AI voice agents to steal iPhone passcodes at scaleAug 25

NVIDIA NemoClaw flaw exposes Ollama API to DNS rebinding attacks, fix pending on WindowsAug 25

Alice raises $140mn to red-team AI models from Anthropic, Google and CohereAug 25

Python Software Foundation security engineers report escalating PyPI supply chain attacksAug 25

x402 payment protocol moves to Linux Foundation with 40 member organizationsAug 25

Next.js patches two critical unauthenticated RCE vulnerabilities in August security releaseAug 25

Ethereum Glamsterdam upgrade reprices state access opcodes, some contracts may breakAug 25

DDoS attack disrupts Norway government digital services for third time this yearAug 25

Attackers use fake Microsoft Teams update prompt to deliver Teams SDK-based malwareAug 25

WhatsApp adds alphanumeric passwords, multiple passkeys and scam call warningsAug 25

Cisco becomes Teleport's largest strategic investor in infrastructure identity pushAug 25

Spring Framework update fixes 91 vulnerabilities across 209,000 affected componentsAug 25

InjecMEM attack plants persistent hidden instructions in AI agent memory via single promptAug 25

Windows Defender's own boot driver can be used to disable Defender before it startsAug 25

AWS Lambda adds full IAM resource-based policies for multi-principal access controlAug 25

OpenAI bans Russian accounts running fake Israel-based think tank influence campaignAug 25

JPEG XL support converges across all major browsers with Firefox and Chromium aligningAug 25

Unpatched Calix router flaw lets attackers bypass NAT and expose internal devicesAug 24

WordlistLoader malware hides shellcode in English word lists to evade detectionAug 24

Researchers show encrypted LLM reasoning traces can be extracted and replayed across modelsAug 24

Attackers exploit miniOrange WordPress plugin auth bypass to forge admin sessionsAug 24

GitLab 19.3 ships agentic AI gateway for self-managed dedicated environmentsAug 24

Microsoft SharePoint RCE CVE-2026-63520 chains with auth bypass for unauthenticated exploitAug 24

Abandoned Atlas VPN affiliate domain now serves infostealer malwareAug 24

Steam game ID scam lets buyers push malware updates to existing players, FBI investigatingAug 24

ReliaQuest confirms ShinyHunters breach was blocked at view-only access by device-trust controlsAug 24

Twitch and Amazon face class action over using creator livestreams to train AIAug 24

Microsoft Teams rolls out admin policy to automatically block external bots from meetingsAug 24

CISA orders federal agencies to patch actively exploited Zimbra RCE within three daysAug 24

Certighost CVE-2026-54121 lets low-privileged users compromise Active Directory domains via AD CSAug 24

Open VSX blocklist flaw lets reclaimed malicious extension IDs pass as legitimateAug 24

StepSecurity tracks 56 open source supply chain attacks in the past yearAug 23

JFrog Boost flaw let a single Always Allow click grant blanket shell access in Cursor and Claude CodeAug 23

Supply chain attack turns Android car head units into proxy botnet nodesAug 23

ToxicPanda 2.0 banking trojan blocks Google Play Protect and targets 349 financial appsAug 23

Google open-sources HEIR compiler for running AI inference on encrypted dataAug 23

Malicious PR injected wipe command into Amazon Q Developer, reached nearly 1 million VS Code usersAug 23

Citrix NetScaler SAML heap overflow CVE-2026-8452 confirmed exploitable with detection probeAug 23

Ceph ships emergency hotfixes for CephX authentication bypass and three other CVEsAug 23

Linux NTFS3 driver flaw lets malicious USB drive grant root accessAug 22

TikTok agrees to pay $400mn to settle US children's privacy caseAug 22

SynkLoader malware spreads via Microsoft Teams IT help desk phishingAug 22

Cloudflare launches Bot Preference Sync to auto-update robots.txt from dashboard settingsAug 21

Anthropic releases Mythos 5 exclusively through Claude Security vulnerability scannerAug 21

PHP Foundation launches ecosystem security team backed by Alpha-Omega grantAug 21

Heroku rolls out fine-grained access control to all customersAug 21

Researchers use AI to design synthetic bacteriophages more effective than natural virusAug 21

Anthropic makes Computer Use browser tool and Skills API generally availableAug 21

Truffle Security finds 9,300 active AWS keys exposed in public repos and datasetsAug 21

Cloudflare open-sources OPKSSH to replace SSH keys with SSO identity tokensAug 21

Researcher buys expired domain and logs hundreds of thousands of calls to military basesAug 21

Apollo Global confirms data breach exposing SSNs in social engineering campaign targeting financial firmsAug 21

CISA orders federal agencies to patch actively exploited TrueConf Server flawsAug 21

Microsoft patches max-severity Entra ID flaw CVE-2026-69836 already exploited in attacksAug 21

New Windows RATs use FTP banners and Pinterest pins as covert C2 channelsAug 21

Azure DevOps Remote MCP Server reaches GA but blocks Claude, ChatGPT and CursorAug 21

Wiz finds S3-compatible neoclouds lack AWS security guaranteesAug 21

ChatGPT desktop app gains iMessage access and can summarize your conversationsAug 21

Canonical funds three-year PhD research into automated C-to-Rust translationAug 20

Critical sandbox escape patched in isolated-vm with 1M weekly npm downloadsAug 20

AliExpress anti-fraud scripts silently occupy audio path to block Bluetooth switchingAug 20

Project Valhalla value classes land in JDK 28 as preview featuresAug 20

Hackers target security researchers with fake crypto conference lure at Black HatAug 20

Next.js critical security patch scheduled for August 26Aug 20

CISA replaces CVSS with SSVC and mandates three-day fixes for critical flawsAug 20

N-able Passportal flaw exposed master keys for 2,500 MSP password vaultsAug 20

Cloudflare launches task-based OAuth scope customization for developersAug 20

Spring deserialization flaw lets remote attacker terminate JVM via System.exitAug 20

Log4j2 AmqpAppender disables TLS hostname verification by defaultAug 20

Spring SerializingHttpMessageConverter gets RCE patch for unsafe Java deserializationAug 20

Google Cloud KMS adds quantum-safe key import to counter store-now-decrypt-later attacksAug 20

Azure SQL Database and Managed Instance get automatic WORM backup immutability by defaultAug 20

GitHub code scanning adds Mitigated alert dismissal reasonAug 20

CodeQL 2.26.3 adds GitHub Actions security queries and Vue.js supportAug 20

Pakistan's Transparent Tribe deploys new Go and C++ backdoors in Afghan and Indian attacksAug 20

Better Auth 1.7 ships OAuth overhaul with DPoP, back-channel logout and MCP 2026 profileAug 20

Critical Elementor Pro file upload flaw allows unauthenticated RCE on WordPress sitesAug 20

NSA and CISA warn of AI-assisted attacks on Siemens S7 PLCs across critical infrastructureAug 20

Percona PMM patches unauthenticated SQL execution and AWS metadata chain in Grafana ClickHouse sourceAug 20

ChainDrop npm worm variant hijacks 444 packages with 2 billion monthly downloadsAug 20

Google details three Russian espionage clusters abusing OAuth and app-password flowsAug 20

Teltonika patches unauthenticated heap overflow and privilege escalation in network devicesAug 20

Grok leaks user chat history via encrypted prompt injection attackAug 20

Grandoreiro banking trojan resurfaces with new Mexico campaignAug 20

OpenAI systems breached Hugging Face in intrusion undetected for nearly a weekAug 20

OpenAI previews Private Safety Processing to preserve zero data retention for enterpriseAug 20

Check Point finds Windows Defender boot driver weaponizable as kernel primitive across Windows 7 to 11Aug 20

Alation confirms cyberattack on systems serving half the Fortune 1000Aug 20

Munich Re acquires cyber-insurer At-Bay for $575M, less than half its 2021 valuationAug 20

Citrix patches critical NetScaler authentication bypass CVE-2026-19490 with 22,000 instances exposedAug 20

ClarityCheck face-search service exposes 9 million photos in unprotected storage bucketAug 20

CISA confirms active exploitation of critical MLflow SSRF flaw CVE-2026-64849Aug 20

Slack and Teams abuse quadruples as attackers exploit trusted chat channelsAug 20

Manic Android malware exfiltrates data via nearby infected devices over Wi-Fi DirectAug 20

Rust supply chain attack hits arrayref 0.3.10 via typosquatted proc-macro1 crateAug 20

Raspberry Pi Pico 2 exploit targets unpatchable BootROM bug in Apple devicesAug 20

Litigant embeds prompt injection in court filing to manipulate AI reviewersAug 20

77 Firefox extensions linked to coordinated crypto wallet and credential theft campaignAug 20

Critical sandbox escape in kobako gem allows guest scripts to run arbitrary Ruby on hostAug 19

Guardrail-free AI platform Kriminal stitches together Grok, Claude and Llama for cybercrime servicesAug 19

Ransomware affiliate poses as recovery service to double-extort victimsAug 19

AI coding config files weaponized to exfiltrate secrets via hidden Unicode instructionsAug 19

Sakura Internet breach exposes data of up to 1.36 million accountsAug 19

Hackers compromise 14,500 Dahua IP cameras in 35-day global campaignAug 19

Go 1.27 ships with generic methods, post-quantum crypto and encoding/json/v2Aug 19

US agencies warn of AI-assisted attacks on Siemens PLCs in critical infrastructureAug 19

T-Mobile physically cut a network cable to expel Salt Typhoon hackers in 2024Aug 19

OpenAI previews Private Safety Processing for zero data retention API customersAug 19

Flock Safety AI tool lets police search suspects by driving behavior with no plate or nameAug 19

US charges 17 Iranians over $3.4B academic and IP theft campaignAug 19

Cloudflare researchers demonstrate cross-tenant memory leak in Workers via remote Spectre attackAug 19

Grok CLI caught silently uploading local codebases and secrets to cloud storageAug 19

Password spraying attacks surge 155x as attackers bypass MFA via legacy OAuthAug 19

Open-source tools to strip Anthropic's EU AI Act watermark appear within days of launchAug 19

CareCloud confirms 3.75M patient records stolen in AWS breachAug 19

PSF warns PyPI is a supply chain risk as infrastructure team shrinks to one engineerAug 19

Gogs 0.14.3 patches RCE via path traversal in organization usernamesAug 19

Cursor Origin lacks enterprise controls as analysts weigh it against GitHubAug 19

Microsoft fixes Windows Defender crash bug triggered by recent security updateAug 19

CISA confirms active exploitation of critical Windows IKE RCE flaw CVE-2026-33824Aug 19

CISA reports Medusa ransomware has hit over 500 critical infrastructure orgsAug 19

MIT researchers find AI image attribution decays as diffusion models scaleAug 19

OpenAI patches Codex bug that let GPT-5.6 delete user files during cleanupAug 19

Oracle August 2026 security patch fixes 925 CVEs across 23 product familiesAug 19

Amazon Corretto ships critical security patches for Java 8 through 26Aug 18

GitHub Enterprise Cloud adds per-token-type credential revocationAug 18

Google ships formal verification framework for CEL using Z3 theorem proverAug 18

Mistral deprecates native Google Drive and SharePoint connectors by August 31Aug 18

Black Hat and DEF CON highlight AI agents as emerging attack surfaceAug 18

Inside the five-year hunt that ended in arrest of alleged Exchange mass-hackerAug 18

Malvertising campaign hits 29 orgs via fake Claude Desktop app on BingAug 18

Passenger 6.2.0 patches four CVEs and fixes Watchdog API auth bypassAug 18

EU Cyber Resilience Act vulnerability reporting obligations begin September 2026Aug 18

Active credential stuffing campaign compromises 30 organizations via SonicWall VPN devicesAug 18

Scammers abuse Shopify's own notification system in fake refund campaignAug 18

N-able N-central RCE vulnerability under active exploitation by MSP attackersAug 18

MacSync stealer hijacks Google Ads to target Claude users with six-stage macOS RATAug 18

LSHIY password-spraying campaign abuses OAuth ROPC grant to bypass MFA at scaleAug 18

Cloudflare finds two Tier-1 networks stripping BGP OTC attribute, undermining route leak protectionAug 18

Bluesky confirms day-long outage was caused by DDoS attackAug 18

North Korean group PurpleDelta uses AI personas to infiltrate companies via fake remote jobsAug 18

Apple patches image-processing vulnerability exploitable for spyware across iPhones, Macs and Vision ProAug 18

Microsoft Copilot flaw let researchers extract hidden parameters and exfiltrate data via one-click linkAug 18

StopAndProtect campaign uses 2,000 hacked WordPress sites to hit 6,000+ victimsAug 18

TWINLOOT malware hides C2 traffic inside SharePoint, Teams and EdgeAug 18

npm removes 2FA bypass tokens as survey maps 2FA gaps across package registriesAug 18

Ransomware gangs now exploiting Windows Task Host privilege escalation flawAug 18

CISA orders three-day patch for actively exploited Ray AI framework RCE flawAug 18

AI models top out at 68% security pass rate as offense-defense gap widensAug 18

Microsoft removes WMIC from Windows 11, completing deprecation of long-abused LOLBINAug 18

China fast-tracks Windows removal from government agencies in favor of domestic Linux distrosAug 18

Google gains control over anonymization of Spirit Airlines bankruptcy dataAug 18

GitLab patches critical unauthenticated code injection via GraphQL directiveAug 17

OpenAI releases GPT-5.6-Cyber, a cybersecurity-focused modelAug 17

Pokémon Center and Steam customers exposed in CEVA Logistics breachAug 17

Deno open-sources claw patrol, a security firewall for AI agents with production accessAug 17

Microsoft research finds AI agent skill libraries leak sensitive data through the model itselfAug 17

AI agent credential sprawl creates supply chain attack surface as malicious packages hit 500KAug 17

FortiGuard identifies Evooo1Bot botnet exploiting ten CVEs across legacy network devicesAug 17

Safari Technology Preview 250 adds explicit resource management and ReadableStream uploadsAug 17

Hardware wallet data breaches expose thousands to physical theft and seed phrase attacksAug 17

Millions of records allegedly stolen from corporate Azure tenants listed for saleAug 17

NIST proposes AI-powered NVD overhaul as 42,000 CVEs go unenrichedAug 17

Ethereum Glamsterdam testnet Platåberget launches ahead of August 20 forkAug 17

AI safety labs report multiple cases of models escaping test sandboxes and causing real-world harmAug 17

FreeBSD patches kTLS local privilege escalation vulnerability CVE-2026-45257Aug 17

SafePal discloses breach exposing data of nearly 40,000 crypto wallet customersAug 17

Anthropic publishes research on goals spreading between AI agentsAug 16

DDoS attacks disrupt Threema secure messaging serviceAug 16

Jamf finds AmnesiaStealer macOS malware hijacking browser sessions liveAug 16

Audit finds five CVEs in Markdown Preview Enhanced VS Code extensionAug 16

Researchers document North Korea's Kimsuky group testing local LLM tooling for attacksAug 16

Trump authorizes US firms to conduct offensive cyber operationsAug 16

Researchers demo coin-sized device tampering with Boeing 737 avionics busAug 16

Anthropic discloses year-long lapse in bioweapon safety filtersAug 15

GitHub adds OAuth app token expiry and multiple redirect URIsAug 14

Iranian-linked hackers disrupt US water utilities across a dozen statesAug 14

Police arrest suspects over €30 million Commerzbank fraud schemeAug 14

Vercel CDN adds automatic Encrypted Client Hello supportAug 14

UK AISI reports Claude agent nearly executed autonomous supply-chain attackAug 14

Apple patches actively exploited macOS Screen Sharing flaw CVE-2026-65400Aug 14

Researchers detail VMware ESXi hypervisor escape via VMXNet3 flawsAug 14

French tax authority confirms breach exposing 2 million recordsAug 14

Anthropic releases stateless MCP protocol revisionAug 14

Flock Safety overhauls license plate reader policies after abuse reportsAug 14

Cyera acquires Oasis Security for about $1 billion for AI agent identity controlAug 14

RingCentral confirms ShinyHunters breach exposing 1.6 million accountsAug 14

HoneyMyte adds signed kernel rootkit to CoolClient backdoorAug 14

Cl0p ransomware group claims mass hack of Shell and Philips via Oracle flawAug 14

Researchers detail pre-auth RCE chain in Citrix NetScaler SAML handlingAug 14

npm 12 disables install scripts by default to curb supply chain attacksAug 14

Zai releases GLM-5.3 with security-focused code auditing capabilitiesAug 14

Apple expands mercenary spyware threat notifications to 110 more countriesAug 13

Akira ransomware crashes own payload after triggering Windows Safe ModeAug 13

Attackers probe unpatched GeoServer zero-day SQL injection flawAug 13

GitHub sources dependency license data directly from package registriesAug 13

Researcher shows AMD memory controller flaw bypasses memory protectionAug 13

Docker patches sandbox flaw letting agents bypass read-only mountsAug 13

Attackers actively exploit critical VMware vCenter RCE flaw for SSH backdoorsAug 13

Brave 1.93 blocks GPU and graphics-driver fingerprinting by defaultAug 13

EU AI Act Article 50 labelling rules for AI content take effect August 2026Aug 13

Researchers find shadow dependency flaw in VS Code and Open VSX extension packsAug 13

Trezor discloses data breach affecting 14,000 customers via vendor hackAug 13

Researcher demonstrates DRAM controller aliasing bypasses AMD memory protectionsAug 13

CodeRabbit raises $143m for AI code review governance platform at $1.5bn valuationAug 13

White House allows vetted private firms to conduct offensive cyber operationsAug 13

Rsync 3.5.0 fixes 33 security issues in path handling and daemon protocolAug 13

Cloudflare launches certificate transparency monitoring generally availableAug 13

Researchers detail SCCM privilege escalation chain still exploitable after patchAug 13

Microsoft ships Azure Linux 3.0.20260809 with 233 CVE fixesAug 13

Jewelbug hacking group blends state espionage with crypto theftAug 13

Taiwan says AI agents helped hackers breach government systems in four daysAug 13

Brazil orders Discord to suspend livestreaming featureAug 13

Claude Code auto mode becomes default for Pro, Max and Team tiersAug 13

Researchers detail RCE flaws in Belgium's national eID browser extensionAug 13

Python patches security releases in 3.12.14, 3.11.16 and 3.10.21Aug 13

Group-IB details WindRelay NFC relay malware paired with SpyNote trojanAug 12

City-Forum campaign steals data from Salesforce and ServiceNow guest portalsAug 12

Researcher bypasses patched Microsoft Defender privilege escalation flawAug 12

Adobe Commerce flaw actively exploited to hijack customer accountsAug 12

LiteLLM supply chain attack hit 2,500 companies and 434,000 CI/CD pipelinesAug 12

Researchers detail Plug and Pwn USB attacks for Windows SYSTEM accessAug 12

Researchers detail U-Boot secure boot bypass via stack underflowAug 12

UK criminal records office ACRO reprimanded after 7-month undetected breachAug 12

Octopi 365 phishing kit bypasses Microsoft 365 MFA via device code flowAug 12

Attackers exploit new SharePoint JWT bypass CVE-2026-55040 in the wildAug 12

Uber Freight investigates breach after hackers claim million-file leakAug 12

Fake CCleaner installer hijacks Chrome via malicious extensionAug 12

Researcher discloses ShieldBreak zero-day granting SYSTEM privileges via DefenderAug 12

Researchers identify AI harness orchestration code as a critical new attack surfaceAug 12

Zbtlink routers ship with factory-installed backdoor opening unauthenticated root shellsAug 12

Google Chrome blocks 7 billion unwanted Android notifications per dayAug 12

737 fake VPN Chrome extensions route traffic through Russian SOCKS5 proxiesAug 12

Zoom patches two zero-click RCE flaws affecting all meeting participantsAug 11

DeadLock ransomware uses Polygon blockchain to resist law enforcement takedownsAug 11

Chrome ships Device-Bound Session Credentials to block session cookie theftAug 11

Sandworm targets IT admins with trojanized WireGuard VPN client in fake job campaignAug 11

GitHub Enterprise Server 3.22 release candidate adds Copilot CLI for air-gapped environmentsAug 11

Microsoft releases August security patches for Azure DevOps Server 2022Aug 11

Cisco warns of actively exploited ASA and FTD VPN denial-of-service flaw CVE-2026-20349Aug 11

Intel releases CPU microcode 20260811 fixing eight security vulnerabilitiesAug 11

Vercel Enterprise Managed Users reaches general availabilityAug 11

Lazarus Group exploits Windows zero-day CVE-2026-68820 in Operation Dream Job campaignAug 11

Trail of Bits details how Signal's Automatic Key Verification auditor worksAug 11

Black Hat USA 2026 highlights AI agent governance and attack path analysis as top security prioritiesAug 11

Google Cloud publishes post-quantum cryptography roadmap targeting full PQC readiness by 2029Aug 11

Wesco confirms cloud CRM breach after ExfilSquad publishes 2.6M stolen recordsAug 11

Cloud Native Buildpacks graduates from CNCF incubation to production-ready projectAug 11

Delta investigates fake Wi-Fi network set up by passenger mid-flightAug 11

GitHub Copilot MitM analysis finds secrets leaking via .env files and unencrypted local chat storeAug 11

Lab experiments demonstrate quantum voting with entangled photons over 50km fiberAug 11

Researchers extract chain-of-thought reasoning from Anthropic, OpenAI and Google models via cross-model replayAug 11

Chrome 147 brings Device Bound Session Credentials to macOS via Secure EnclaveAug 11

Flatpak 1.19 and 1.18.1 patch sandbox escape and local root privilege escalationAug 11

FBI confirms North Korean IT worker infiltrated unnamed US federal agencyAug 11

Technical analysis and PoC published for SharePoint JWT auth bypass CVE-2026-55040Aug 11

Rapid7 and Microsoft disclose unauthenticated RCE chain in SharePoint via CVE-2026-63520Aug 11

Cloudflare H1 2026 DDoS report shows 1 Tbps attacks up 519% quarter-over-quarterAug 11

Researchers release open-source GitHub Threat Detector with 22 detection rules for supply chain attacksAug 11

CISA confirms ransomware gangs actively exploiting Microsoft SharePoint RCE flawAug 11

Mozilla revokes Firefox signing key after unencrypted copy exposed on GitHubAug 11

Cisco patches seven ClamAV DoS flaws including two with public exploitsAug 11

Project CAV3RN espionage framework uses Google Apps Script as stealthy C2 relayAug 11

Kimwolf v7 botnet adds HTTP/2 DDoS floods and blockchain-based C2 resilienceAug 11

US and South Korea warn of Gunra ransomware targeting government agenciesAug 11

Researchers find standards-compliant SIMs can shut down phones and downgrade 5G to 2GAug 11

Lovable launches enterprise trust centers and Lloyd's insurance for AI-built appsAug 11

PortSwigger open-sources HTTP Terminator after AI system finds 700 vulnerable targetsAug 11

OpenAI expands Daybreak cybersecurity program with Blue and Red access tiersAug 11

Russian hackers attack Polish heat plant via misconfigured cellular APN in first documented OT pivotAug 10

Researcher buys noreply.net and receives 700 sensitive emails per day from misconfigured systemsAug 10

Botnet uses Polygon blockchain smart contracts as C2 infrastructure, resisting takedownsAug 10

BdThemes supply chain hack creates rogue WordPress admins across 100,000+ installsAug 10

Security research shows single slow x86 instruction can break SMM and unlock 100+ dormant CVEsAug 10

Microsoft identifies StormEncryptor ransomware exploiting N-able N-central auth bypassAug 10

Nation-state iOS exploit chains Coruna and DarkSword spread to organized cybercrimeAug 10

OpenAI launches GPT-5.6-Cyber model for authorized cybersecurity workAug 10

Cloudflare for Government achieves FedRAMP High authorizationAug 10

Kimsuky uses offline LLMs to automate spear-phishing document creationAug 10

Klaviyo sign-up page leaked plaintext passwords to Facebook, Google and others for 21 monthsAug 10

UK court jails Com member for blackmail and sextortion targeting 117 minorsAug 10

LexisNexis takes Diligence, Metabase API and Newsdesk offline after server breachAug 10

Valve notifies Steam hardware customers in Europe of data breach via shipping partnerAug 10

Python cryptography library adds ML-KEM and ML-DSA post-quantum primitivesAug 10

Kaspersky Q2 2026 report finds 2,538 new ransomware variants and 400M blocked attacksAug 10

Linux 7.3 removes SGI GRU and XP drivers over undisclosed security concernsAug 10

CISA adds Progress LoadMaster command injection CVE to known exploited listAug 10

US lawmakers push 68% increase in military quantum spending to $567MAug 10

AI agent autonomously exploits gym booking system in first known case in AustraliaAug 10

Ruby JSON gem 2.21.2 patches heap-use-after-free in ResumableParserAug 10

Savannah police fire six after Flock license plate reader misuse investigationAug 10

Anthropic claims Claude largely solved prompt injection, security researchers push backAug 09

Researcher demos adversarial patterns that defeat Flock, Axon, and Clearview AI detectionAug 09

PortSwigger researcher exposes CSS-only attacks that steal tokens and passwords from webmailAug 09

CERT Polska reveals second energy sector target in December 2025 OT cyberattackAug 08

Gentoo Bugzilla taken offline after LLM scrapers make it unusableAug 08

Head Mare hackers trojanize TrueConf installers with PhantomCore backdoorAug 08

Researchers identify unauthorized file access and data leaks as top security risks in AI coding toolsAug 08

AI bot Sashiko finds critical and high severity bugs in Linux kernel HWMON subsystemAug 08

Rosenbridge reveals hardware backdoor in VIA C3 x86 CPUs allowing ring 3 to ring 0 escalationAug 08

Cloudflare launches Precursor behavioral bot detection engine in open betaAug 08

Hugging Face CEO says company was attacked using unreleased proprietary AI modelsAug 07

Citizen Lab confirms Pegasus hacked MEP investigating Pegasus spyware abusesAug 07

Healthcare software breach at Unlimited Technology Systems exposes 3.8 million patient recordsAug 07

Trojanized AI agent skills rack up 1.7M installs in credential-stealing supply chain attackAug 07

Langflow CVE-2026-34046 lets any authenticated user read or delete other users' flowsAug 07

Flooding Dropper campaign publishes 850 malicious npm packages with multi-stage malwareAug 07

OpenAI says upcoming Astra model may have crossed critical cyberattack capability thresholdAug 07

Elastic Security Labs documents Claude Code and Cursor enabling reverse tunnels and persistence on macOSAug 07

Shai Hulud supply chain worm hits npm again, infecting keyv and 400+ packagesAug 07

JetBrains confirms active exploitation of TeamCity RCE CVE-2026-63077Aug 07

Kimi K3 escapes cybersecurity testing sandbox, joining growing list of AI model escapesAug 07

Software Stewardship Lab launches as nonprofit for open source sustainability researchAug 07

North Carolina Ports Authority confirms cyberattack disrupting port operationsAug 07

Stolen AI API credentials sold on Chinese black market for as little as 8 cents on the dollarAug 07

Phishing attack on US defense supplier exposes engineering and export-controlled files via Microsoft 365Aug 07

Illinois law requires OS makers and app stores to implement age verification by 2028Aug 07

Linux 7.2-rc7 fixes eight-year-old race condition causing use-after-free in PTDUMPAug 07

Oracle backports post-quantum cryptography to all supported Java LTS releasesAug 07

Check Point finds five memory corruption bugs in Cloudflare Workers runtime workerdAug 07

Framework laptop confirms data breach via Metabase exposing customer PIIAug 07

npm staged publishing reaches GA with human approval step before packages go liveAug 07

Researchers expose mass exploitation flaws in tens of millions of GPS smartwatchesAug 07

Zapscape KVM flaw lets guest VMs escape to host with root RCE, PoC releasedAug 07

Storm-2755 AiTM phishing campaign targets Microsoft 365 accounts across healthcare and governmentAug 06

OpenAI launches Codex Security Review for GitHub pull requests in research previewAug 06

Researcher demonstrates C2-style attack chain against ChatGPT sandbox at Black Hat 2026Aug 06

Google GTIG links hedge fund cyberattacks to UNC6671 extortion group using vishing and MitM phishingAug 06

LightSpy spyware expands to 13 countries including US with new router and device-wipe capabilitiesAug 06

AWS launches Dogwood open-source temporal policy language for AI agent authorizationAug 06

NatJack attack class breaks NAT security assumptions across 32 products at Black HatAug 06

AWS cryptographer claims polynomial-time quantum algorithm that could threaten post-quantum standardsAug 06

Swiss government SharePoint breach compromises 200 accounts via July Patch Tuesday CVEsAug 06

Six stable Linux kernels patched for speculative execution data leak CVE-2026-68480Aug 06

OpenBao v2.6 ships namespace sealing, auto-unseal plugins and a new workflow engineAug 06

Black Hat 2026: undocumented Windows Defender kernel driver and 12 AI framework CVEs disclosedAug 06

Canadian hacker pleads guilty to breaching 165 Snowflake customers and stealing billions of recordsAug 06

GitHub Dependabot expands malware advisory detection to eight package ecosystemsAug 06

GitLab Secrets Manager adds Kubernetes ESO, Terraform, and API access in public betaAug 06

US OMB replaces federal logging mandate with risk-based approach in M-26-14Aug 06

macOS malware uses fake CAPTCHA to drain crypto wallets via TerminalAug 06

Linux kernel lockdown mode left legacy I/O and memory interfaces exposed since 2019Aug 06

Suno adds audio watermarking and copyright detection amid RIAA lawsuits and data breach falloutAug 06

China opens cybersecurity review into Palo Alto NetworksAug 06

Three critical RCE and privilege escalation flaws patched in Paperclip AI agent platformAug 06

Temporal open-sources Deputy, a CLI supply chain security toolchain with policy-as-codeAug 06

Bundler 4.0.18 extends supply chain cooldown protection to bundle lock and cacheAug 06

Researchers find Apple iCloud Private Relay leaks real IP addresses via passkeysAug 06

Chinese router maker Zbtlink pauses firmware downloads after backdoor allegationsAug 06

Black Hat research finds no perfect fix for AI browser prompt injection attacksAug 06

Rust Coreutils 0.10 ships security hardening and 93.48% GNU test suite compatibilityAug 06

HD Moore reveals dozen BMC flaws exposing enterprise servers to remote backdooringAug 06

Ransom Cartel ransomware creator sentenced to 16 years in federal prisonAug 06

CSS keyloggers demonstrated against webmail platforms at Black Hat 2026Aug 05

Attackers embed post-exploitation toolkit inside Oracle database using built-in JVMAug 05

Django 6.1 released with model field fetch modes and database-level delete optionsAug 05

Ryde reports a data breachAug 05

Anthropic launches inference hooks letting enterprises intercept Claude prompts via DLP serversAug 05

Ghostty adds OSC8 URL classifier to block malicious terminal hyperlink attacksAug 05

Phishing campaign exploits COLDCARD vulnerability fears to install remote access toolAug 05

OpenAI AI agents breached real systems during sandboxed security evaluationsAug 05

Major organizations' machines found participating in VoIP fraud botnetAug 05

CISA flags actively exploited RCE in Langflow AI framework and two other flawsAug 05

Vercel expands Sandbox egress firewall to free Hobby planAug 05

40 million fake commits per day flood GitHub's public event feedAug 05

Researchers propose first efficient unclonable encryption scheme using quantum no-cloning theoremAug 05

Open-weight AI models match frontier capability but lag far behind on safety benchmarksAug 05

House report finds Chinese carriers kept network footholds in US after licence revocationsAug 05

Microsoft, Apple and Google overhaul bug bounty programs as AI floods submissionsAug 05

Cloudflare open-sources its internal AI agent workspace platformAug 05

Cloudflare AI Gateway adds identity-aware controls and rogue agent detectionAug 05

Beacon CRM breach exposes donor data held by UK charitiesAug 05

Critical Bluetooth flaws in KARR car alarm expose 2 million US vehicles to remote unlockAug 05

Quarkus 3.38.1 patches HTTP authorization bypass via encoded path charactersAug 05

Quarkus patches DoS CVE-2026-16308 in emergency LTS releasesAug 05

Bugtraq mailing list revived after years of silenceAug 05

Tails 7.10.1 patches kernel privilege escalation that could deanonymize usersAug 05

Researcher finds SQL injection extraction technique via Snowflake compile-time constant foldingAug 05

WebKit DNS prefetch, WebAuthn and WebTransport leak real IPs past proxy and iCloud Private RelayAug 05

City of Munich funds libexpat maintainer to fix 5 known vulnerabilitiesAug 05

INTERPOL report finds AI powers 55% of cybercrime in Africa as losses hit $484MAug 04

UK AI Security Institute reports LLM agents autonomously attacking GitHub projectsAug 04

TP-Link patches 15 Omada ZTP flaws enabling full network compromiseAug 04

Greatness PhaaS platform adds AiTM attacks to steal Microsoft 365 tokens via RingCentral spoofingAug 04

EFF finds Android ad SDKs share precise user location data without developer knowledgeAug 04

AWS Security Hub Extended adds supply chain security category with Chainguard and SocketAug 04

Smoke#Screen campaign abuses ScreenConnect RMM to gain persistent access on Windows and macOSAug 04

77 malicious extensions found harvesting developer data on Open VSX marketplaceAug 04

vlt 1.0 ships as npm replacement with malware blocking and hosted package registryAug 04

Deel acquires deepfake detection startup Clarity for up to $50M to combat fake hiresAug 04

Prompt injection tops OWASP GenAI Top Ten for third year as excessive agency jumps to #3Aug 04

Chrome Enterprise adds agent security controls including action veto and DLP inspectionAug 04

Nvidia launches Open Secure AI Alliance with 75 founding members to secure agentic AIAug 04

China privately alarmed by Anthropic's Mythos model over offensive cyber capabilitiesAug 04

Advanced Custom Fields 6.8.7 patches multiple security vulnerabilitiesAug 04

Government and WordPress sites hijacked to spread ClickFix malware and Phantom Enigma backdoorAug 04

Django patches four CVEs including high-severity RCE risk in spatial lookupsAug 04

Snowflake launches Cortex AI Gateway and enterprise AI security features at Black Hat 2026Aug 04

Thales launches Luna 8 HSM with post-quantum cryptography supportAug 04

Ciena and Toshiba trial 1.6 Tb/s quantum-safe encryption on live commercial networkAug 04

GitGuardian finds 321 valid n8n API tokens exposed and critical file-read CVE in Git nodeAug 04

Phishing campaign impersonates Bank of America to deliver ScreenConnect RAT via UAC bypassAug 04

QuickFox VPN installer trojanized to deploy FDMTP implant via DLL sideloadingAug 04

Linux Foundation and Open Secure AI Alliance propose shared AI security incident databaseAug 04

Palo Alto Unit 42 AI system finds 14,090 unknown vulnerabilities in 3,915 open-source projectsAug 04

AI-generated security article incorrectly labels Elixir RCE vector as safe and ranks first on GoogleAug 04

Firebase misconfiguration in tl;dv exposes government and corporate meeting calls to any userAug 04

US drafts ban on Chinese-made devices in data centresAug 04

Phishing campaigns abuse Cloudflare, Vercel and GitHub Pages to host AitM attacksAug 04

CodeQL 2.26.2 adds Swift 6.3.3 and Kotlin 2.4.10 supportAug 04

FCC bans new imports of foreign mobile robots over 2 kg on national security groundsAug 04

Keyv and related npm packages compromised in supply chain attack affecting hundreds of millions of downloadsAug 04

Linux kernel staging area bans LLM-generated patches except security fixesAug 04

Erlang OTP 28.5.0.5 patches SSH CBC cipher CVE-2008-5161 regressionAug 04

Erlang OTP 27.3.4.16 patches SSH CBC cipher vulnerability CVE-2008-5161Aug 04

pgAdmin 4 v9.17 patches seven CVEs including OS command injection and SQL injectionAug 04

RHEL 10.2 kernel scheduler regression causes 93% throughput loss on multi-NUMA systemsAug 04

Researchers disclose Pass-ta-key attacks that extract Google-synced passkeys from Chrome memoryAug 04

Apple caps bug report submissions after AI tools flood pipeline with unverified CVEsAug 03

Forgejo Runner v13.0.0 removes insecure workflow commands and raises Docker minimum to 25.0Aug 03

DOUBLECUP loader-as-a-service hides malware in browser-cached PNG imagesAug 03

Apple challenges second UK government demand for iCloud encryption backdoorAug 03

Linux 7.3 set to upstream FailFS for complete filesystem state sheddingAug 03

NuGet.org cuts API key maximum lifetime to 30 days starting August 17Aug 03

N-able N-central authentication bypass under active exploitation with emergency hotfix releasedAug 03

Red team research shows compromised LiteLLM admin credential enables API key theft and tool-call injectionAug 03

Chinese threat actor deploys DeepSeek AI agent in five-day autonomous proxyjacking campaignAug 03

Iranian-linked actors target water utilities in Georgia and MichiganAug 03

zlib-rs 0.6.7 fixes use-after-free vulnerability and adds LoongArch optimizationsAug 03

ICE collected DNA from nearly 1 million people in 2025 including young childrenAug 03

INC ransomware group actively exploits critical SonicWall SMA1000 zero-daysAug 03

UK Police National Legal Database breach exposes officers' data on dark webAug 03

OSTIF security audit of Cortex finds 7 vulnerabilities, all now patchedAug 03

UK government investment arm exposes officials' contact details for 40 hoursAug 03

HashiCorp ships public beta of Vault Kubernetes Key Management pluginAug 03

RFC 9851 places TLS 1.2 in feature freeze and directs post-quantum work to TLS 1.3Aug 03

curl maintainer calls month-long vulnerability report pause a success and plans to repeat itAug 03

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
```

