Vulnerabilities & exploits
Disclosed flaws and their exploitation in the wild, tracked from primary advisories and vendor bulletins rather than from other coverage.
Reporting
5 storiesOmdia survey: AI risks and stolen credentials dominate software supply chain concerns
An Omdia report from February 2026 found that 77% of organizations experienced supply chain incidents in the prior 12 months, with AI technology ranked as the top risk and 35% reporting stolen developer credentials.
GitLab Security Review Flow detects authorization flaws in code diffs
GitLab's AI-powered code review tool identifies broken object and function level authorization, business logic errors, and other vulnerabilities before merge, now in public beta.
GitLab automates fixing breaking changes in dependency updates
Dependency Scanning Auto-Remediation resolves one in eight breaking changes automatically across build ecosystems, with an improved fingerprinting algorithm reducing duplicate vulnerability tracking by 43%.
GitHub expands malware detection across eight package ecosystems
GitHub's advisory database now ingests malware reports from OpenSSF's malicious-packages repository, extending coverage beyond npm to Python, Java, Ruby, .NET, Go, Rust, and PHP.
Four CISA industrial control advisories detail critical code execution and authentication bypasses
Johnson Controls, ABB and Acrisure systems face multiple vulnerabilities ranging from hardcoded credentials to unauthenticated arbitrary code execution.
