Wordfence Bug Bounty Program Monthly Report – June 2026
In June 2026, the Wordfence Bug Bounty Program received 1066 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the…
Coverage tagged "Open source".
In June 2026, the Wordfence Bug Bounty Program received 1066 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the…
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S.
A crook has been using three open source AI harnesses to target hundreds of online retailers and other companies, swiping more than 600,000 credit card records and installing card-stealing skimmers -…
Serial number: AV26-808 Date: August 12, 2026 Updated: September 24, 2026 As of August 11, 2026, Adobe is affected by vulnerabilities in the following products: Adobe Campaign Classic Prior to or…
A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including…
Posted by E. Kellinis on Sep 22 Karma Pro is an open source code review tool that can assist code reviewers with a multitude of useful tools. Karma Pro is a macOS source-code security scanner (AST…
arXiv:2609.22664v1 Announce Type: new Abstract: Research on large language model agents for penetration testing is evaluated almost entirely by capability: whether the agent captures a flag or…
Despite the concern that advanced AI models’ bug-hunting prowess will lead to attackers exploiting more newly uncovered CVEs, fewer than 0.5 percent of the vulnerabilities linked to Anthropic or…
Serial number: AV26-503 Date: May 25, 2026 Updated: September 21, 2026 On May 24, 2026, Roundcube published security advisories to address vulnerabilities in the following product: Roundcube Webmail…
Posted by Tomas Hoger on Sep 21 Is GitHub going to assign a CVE here? I think GitHub assignment would be ok per this part of the GitHub CNA scope definition: "vulnerabilities affecting open source…
Be alert: targeted attacks on prominent Rustaceans Important warning from Adam Harvey and the crates security team: We believe that there is an ongoing campaign targeting rust-lang members and owners…
In response to a new European Union law, AI platforms are implementing new schemes for watermarking the content they generate. Anthropic recently disclosed its future Claude models will use…
China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August…
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal…
In May 2026, the Wordfence Bug Bounty Program received 1095 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the…