Topic: vulnerability reporting
-
ArmorCode Helps Manufacturers Prepare for EU Cyber Resilience Act
ArmorCode has launched new capabilities for its Agentic AI Platform to help manufacturers of products with digital elements comply with the EU Cyber Resilience Act (CRA), which mandates strict cybersecurity standards and vulnerability reporting deadlines. The CRA requires companies to report acti...
Read More » -
CISA Opens KEV Nomination Form to Vendors and Researchers
CISA has launched a new online nomination form for security researchers and vendors to directly report known exploited vulnerabilities for inclusion in its Known Exploited Vulnerabilities (KEV) catalog, replacing the previous email-only submission process. The agency aims to accelerate the catalo...
Read More » -
NIST Ends NVD Updates for Older Vulnerabilities
The NVD is shifting its focus to prioritize enriching data for recently disclosed and actively exploited vulnerabilities due to an overwhelming volume of new CVEs. This change means older, less critical flaws will receive less detailed analysis, though the NVD will remain the authoritative public...
Read More » -
Chinese Hackers Exploiting VMware Zero-Day Since 2025
A critical privilege escalation vulnerability (CVE-2025-41244) in Broadcom's VMware software has been actively exploited since October 2024, allowing attackers to gain root-level control over affected virtual machines. The exploitation has been attributed to UNC5174, a Chinese state-sponsored thr...
Read More » -
Tata Motors Patches Security Flaws That Exposed Customer Data
A security researcher discovered and reported critical vulnerabilities in Tata Motors' E-Dukaan portal, including exposed AWS private keys that could access sensitive customer and corporate data. The breach risked exposing extensive information such as customer invoices with personal details, MyS...
Read More » -
Delve Customer Hit by Major Security Breach
Delve, the compliance startup at the center of security scandals, handled certifications for Context AI, whose security incident led to a breach at Vercel, and has lost customers like Lovable and LiteLLM after whistleblower allegations of fabricating data and rubber-stamping audits. The situation...
Read More » -
Urgent Apple Update Fixes Critical Security Exploits
Apple has released urgent security patches for two actively exploited zero-day vulnerabilities (CVE-2025-14174 and CVE-2025-43529) in its WebKit browser engine, which is used across iPhones, iPads, and Macs. The flaws, discovered through a collaboration between Apple and Google, could allow memor...
Read More »