What is CVE remediation in 2026?
Annual CVE disclosures are projected to pass 60,000 in 2026, and AI has made finding vulnerabilities cheap, but the NVD has stopped scoring most CVEs, making remediation the bottleneck. The convention…
Annual CVE disclosures are projected to pass 60,000 in 2026, and AI has made finding vulnerabilities cheap, but the NVD has stopped scoring most CVEs, making remediation the bottleneck. The convention…
The Forum of Incident Response and Security Teams (FIRST) announced VulnOptiCON 2026, a three-day technical colloquium scheduled for September 23-25, 2026, in Luxembourg, to address vulnerability trac…
Researchers trained a multi-label classifier on a curated gold dataset of 1,207 CVEs from expert MITRE Center for Threat-Informed Defense mappings, achieving recall@5 of 0.673 ± 0.019 for mapping CVEs…
X-cmd v0.9.14 adds two command-line modules, `x cve` and `x cwe`, for querying CVE vulnerability IDs and CWE weakness categories, respectively. Founder and CEO Edwin Lee argues that as AI agents mass-…
Prescryb, a new open-source MCP server, enables natural-language-driven vulnerability and compliance remediation by connecting AI assistants to SSH-based host inventory, CVE matching, advisory lookups…
A new multi-agent pipeline using large language models and knowledge graphs is transforming risk management in critical infrastructure by converting natural-language system descriptions into audit-rea…
Researchers have developed a CVE-TTP Knowledge Graph linking software vulnerabilities to attacker behaviors using the MITRE ATT&CK framework. Transformer-based models like CySecBERT achieved high F1-s…
The Linux Foundation announced Akrites, a coordinated effort to remediate vulnerabilities in open source software. The initiative provides a shared Security Incident Response Team to handle vulnerabil…
The National Institute of Standards and Technology (NIST) announced on April 15, 2026, that the National Vulnerability Database (NVD) will adopt a risk-based triage model, abandoning universal enrichm…
The rise of AI-driven software development and CI/CD pipelines is challenging traditional vulnerability management systems like CVE and CVSS, as codebases are rapidly rewritten and vulnerabilities are…
Swamp, initially built for infrastructure automation, has evolved into a domain-agnostic automation primitive as users applied it to security scanning, cost analysis, and infrastructure validation. Th…
WitnessAI launched Agentic Control on June 17, 2026, a single control plane to discover, monitor, govern, and restrict AI agent behaviors and their interactions with tools and Model Context Protocol (…
The Forum of Incident Response and Security Teams (FIRST) released its 2026 Mid-Year Vulnerability Forecast, revealing actual CVE disclosures are running 46.3% above projections from four months ago, …
Five Linux local privilege escalation vulnerabilities were disclosed and exploited within weeks this spring, with attackers using AI to scan kernel subsystems and find bugs like the "Copy Fail" vulner…
Hackers on the Hill returns to Washington DC on June 16, 2026, as the first Capitol-side researcher-to-policymaker gathering of the year. The White House signed the Mythos-era AI cybersecurity executi…
Endoflife.ai has added an "Add to Calendar" button to every product and version page with a future end-of-life date, allowing users to download a standard calendar file with reminders set at 90, 30, a…
Researchers have developed FORGE, a multi-agent system that bridges vulnerability exploitation, prioritization, and detection rule engineering by using graduated exploitation depth. The system achieve…
Anthropic disclosed 1,596 security vulnerabilities across 281 open-source projects as of May 22, 2026, after using an early snapshot of its Claude Mythos Preview AI model to find the flaws in February…
Researchers have developed FuzzingBrain V2, a multi-agent large language model system that automatically discovers and reproduces software vulnerabilities. The system achieved a 90% detection rate on …
AMAS (AI Multi-Agent Security Analysis System) uses causal reasoning to teach AI models to understand logical vulnerabilities like IDOR, privilege escalation, and workflow bypasses, rather than relyin…