Authorization gaps, hard-coded secrets and invented package names are reaching production repositories faster than human review can absorb them.
Latest news
Latest cybersecurity dispatches
Fresh reporting on active vulnerabilities, security patches, incident response, and threat research for defenders.
Service accounts, CI/CD runners, workload certificates and AI-agent principals form a sprawl traditional joiner-mover-leaver programs never governed.
*A conceptual view of Jenkins as the high-privilege control plane of the software factory—and of plugins as the supply-chain links that can break it.*
The chain moves from Safari RCE through sandbox escape to kernel read/write, exfiltrates data within minutes, then cleans up and exits with no user interaction.
Microsoft and CISA confirmed exploitation on 14 July 2026 and shipped same-day patches. SharePoint Online is unaffected; self-hosted farms need action now.
Roughly triple June's previous record, the release is led by CVE-2026-50518, an unauthenticated Windows DHCP Server RCE rated Exploitation More Likely.
Patched in the record July 2026 Patch Tuesday, the flaw puts finance, supply-chain and operations systems at risk wherever ERP login endpoints remain reachable.
Golden SAML still threatens hybrid identity via AD FS token-signing keys. Learn how to harden DKM access, detect key theft, and lock down federation servers.