Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Zero-Day Attack Prevention: Catching Unknown Vulnerabilities Before Threat Actors Do

On September 1, 2026, OpenAI announced that its Astra model had reached the Critical tier for cyber capability under the company’s Preparedness Framework, a first for its systems. While working through an internal benchmark of 20 recently disclosed vulnerabilities in Google’s V8 engine, the model found two zero-days that no one had asked it to look for and used them in a working exploit chain. OpenAI is disclosing both flaws and restricting the capability to vetted testers.

WordPress CVE-2026-87902: Unauthenticated RCE Exploited Within Hours

WordPress patched CVE-2026-87902 on September 22, 2026. Attackers were exploiting it the same day. Within hours of disclosure, attackers progressed from reconnaissance to active exploitation attempts, including attempts to write malicious PHP files to disk. The vulnerability is critical, with a CVSS v4.0 score of 9.2. Unauthenticated attackers can exploit it remotely. A public scanning template is already in circulation, and CISA has added the vulnerability to its KEV catalog.

Next.js CVE-2026-94545: Critical ImageResponse Vulnerability Enables RCE via SVG

A critical remote code execution vulnerability was disclosed in Next.js on September 22, 2026, and an out-of-band security update was released to fix it. CVE-2026-94545 is a remote code execution vulnerability in next/og, the feature Next.js applications use to generate images on demand. The GitHub advisory rates it 9.5 on CVSS v4.0. An unauthenticated attacker can reach it over the network, and the root cause is an upstream SVG-escaping vulnerability that applications inherit without realizing it.

Day in the Life of a Cyber Research Communicator: From Threats to Takeaways

Cybersecurity research, threat intel, and novel findings produce no shortage of information. Every day brings new vulnerabilities, malware campaigns, proof-of-concept exploits, threat reports, headlines, and predictions about what comes next. But what has proven difficult is sorting through the noise to determine what's worth following. That's a big part of my role as Manager of the SpiderLabs Communications team at LevelBlue.

AI Security: Are We in the Lull Before the Storm?

AI adoption is accelerating, cyber attacks are increasing and organisations are transforming faster than their security can keep up. In this Razorwire Raw, James Rees looks at why cybersecurity could be in the lull before the storm. AI agents, vibe coding and automation are changing business at extraordinary speed, while attackers are using the same technology to find vulnerabilities and accelerate attacks.

How to Evaluate and Choose the Best TPRM Software in 2026

Evaluating third-party risk management (TPRM) software in 2026? Every platform says it tracks your vendors. What a demo will not show you is whether it finds those vendors on its own, including the AI tools and shadow IT nobody logged, or waits for you to type them in. This video follows one vendor from the day it shows up in your environment through five criteria for judging any TPRM platform, and the question to ask a vendor on each one.

What is HIPAA compliance: Guidelines for becoming compliant

HIPAA compliance requires healthcare providers and their business associates to safeguard protected health information (PHI) through privacy and security rules, risk assessments, and breach notifications. Covered entities must implement administrative, technical, and physical safeguards, including access controls, encryption, auditing, and workforce training. Noncompliance can result in steep fines and reputational damage, making strong data governance and adherence to NIST-aligned safeguards essential.

Ask your PAM vendor this one question

Here's a test you can run in about five minutes. Pull up a privileged account in your directory, one that was used in a session yesterday. Is the account still there? Does it still hold the same privileged group memberships it had yesterday? I'd bet good money the answer to both is yes. That's not a criticism of your PAM tool. It's what traditional credential rotation was built to do, and more importantly, what it was never designed to do.