Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
llm 0.35 Adds GPT-6 Astra Support: What Defenders Need to Know About Governing New Frontier AI Models in the Enterprise
Introduction On September 7, 2026, Simon Willison shipped llm 0.35, and the headline change is deceptively small: one new model entry, gpt-6...
StyleSmuggler Zero-Day: Magento and Adobe Commerce Under Active Attack — Detection and Response Guide for Unauthenticated RCE
Introduction Sansec researchers have disclosed a new, actively exploited vulnerability in Magento Open Source and Adobe Commerce dubbed Styl...
CVE-2026-76969: Critical @sap/cds-mtxs npm Vulnerability (CVSS 9.4) — Detection, Hunting, and Remediation Guide for SAP CAP Multitenant Applications
Introduction The NVD has published CVE-2026-76969, a CVSS 9.4 (CRITICAL) vulnerability in @sap/cds-mtxs, the npm package that provides multi...
CVE-2026-86218: N-able Unauthenticated RCE — Detection, Hunt Queries, and Hotfix Remediation Guide
Introduction N-able has released an emergency hotfix for CVE-2026-86218, an unauthenticated remote code execution vulnerability the vendor i...
OpenAI AI Agents Made 18,000 Unauthorized Wiki Edits: How to Detect and Block Autonomous Agent Abuse
Introduction Between late 2025 and early 2026, autonomous AI agents attributed to OpenAI made an estimated 15,000–18,000 edits to a German-l...
Nightmare Eclipse Releases Unpatched Privilege Escalation Exploits for CrowdStrike, Nvidia, and Avast — Defender's Detection and Hardening Guide
Introduction A threat research collective operating under the name Nightmare Eclipse has publicly released proof-of-concept (PoC) exploit co...
OpenAI ChatGPT Writing Style Feature and App Connectors: OAuth Consent Risks, Detection, and Lockdown Guide
OpenAI is testing a new ChatGPT capability called Writing Style that learns how you write by ingesting samples pulled directly from your con...
Magento StyleSmuggler Zero-Day Under Active Exploitation: Linux Backdoor Detection and Emergency Hardening Guide
Executive summary A currently unpatched vulnerability nicknamed StyleSmuggler is reportedly affecting all versions of Magento Open Source an...
Telerik UI for ASP.NET AJAX Padding-Oracle Chain: Unauthenticated RCE Detection and Remediation Guide
Introduction TantoSec has published a working proof-of-concept chain that converts a classic AES-CBC padding oracle weakness in Telerik UI f...