Pen Test Partners says the battery maker declined to fix exposed older installs and did not act when the UK regulator asked. On 9 April 2026 it entered administration.
Publishers:pentestpartners.com
Reality
- Evidence44
- Adoption28
- Hype gap+16
- Incentives68
- Confidence52
build1 distinct publisher Adversa says it hid data-exfiltration instructions in AES-256-GCM ciphertext and let Grok decrypt them in its own Python sandbox. The plaintext version of the same attack was refused.
Publishers:thenewstack.io
Reality
- Evidence42
- Adoption20
Two disclosed DoS techniques turn HTTP/3-to-HTTP/1.1 conversion at six major CDNs into up to 350x load on the origin, with no configuration change by the customer.
Publishers:thehackernews.com
Reality
- Evidence66
- Adoption34
The vendor reports 10-plus CVEs and up to 200,000 exposed instances, and says Anthropic declined to change the protocol, describing the behaviour as expected.
Publishers:ox.security
Reality
- Evidence32
- Adoption34
CISA's advisory for its own network traffic analysis suite lists denial of service and arbitrary code execution: unbounded archive extraction, traversal in two layers, and uploads that run PHP as www-data.
Publishers:cisa.gov
Reality
- Evidence78
- Adoption30
build1 distinct publisher CVE-2026-19478 needs no login and no click. CVE-2026-19650 needs a user to open a link. Self-managed operators on 18.11, 19.0, 19.1 and 19.2 have to patch anyway.
Publishers:dev.to
Reality
- Evidence58
- Adoption24
build1 distinct publisher A dev.to post argues most "read-only" Kubernetes MCP servers filter the tools/list response while the write path stays callable. One such filter is now a CVE at CVSS 8.8.
Publishers:dev.to
Reality
- Evidence38
- Adoption58
build1 distinct publisher CVE-2026-71368 affects F-RevoCRM 7.3.0 through 8.0.3 and runs attacker script inside the CRM's own origin. JVN rates it Medium; the published remedy is a version bump.
Publishers:dev.to
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+8
build1 distinct publisher CVE-2026-69414 is an unpatched local escalation in the Malware Protection Engine, and it exists because the fix for CVE-2026-50656 was incomplete. Applying that earlier update bought nothing.
Publishers:dev.to
Reality
- Evidence24
- Adoption9
Huntress says a public proof of concept needs only an IP address to pull any file off unpatched Macs, driving a helper process that carries Full Disk Access.
Publishers:huntress.com
Reality
- Evidence68
- Adoption42
Nine of eleven MCP marketplaces accepted proof-of-concept malware with zero review, and a fake agent skill cleared both Cisco's and NVIDIA's scanners to reach roughly 26,000 corporate agents.
Publishers:scworld.com
Reality
- Evidence24
- Adoption38