Category: Vulnerabilities & Alerts

Bulletins on critical vulnerabilities, exploitation analyses and alerts tracked as they break. Microsoft Patch Tuesday, the CISA KEV catalogue, CERT-FR and CERT-UA advisories, actively exploited zero-days, Sigma, YARA and Suricata detection rules, and patch prioritisation.

VINCE-NT and the Nationalization of the Bug: When CISA Cuts the Academic Cord

CISA officially migrated its Coordinated Vulnerability Disclosure (CVD) platform on September 17. Behind the acronym VINCE-NT (Vulnerability Information and Coordination Environment – New Technology), which replaces the venerable VINCE operated since 2020 by the CERT/CC, lies much more than a mere interface facelift or a welcome alignment with CSAF status frameworks. This is an act…

Oracle’s September 2026 CSPU: 673 security patches

Oracle released 673 security patches on 15 September 2026, 247 of them for vulnerabilities that are remotely exploitable without authentication. Six carry the maximum score of 10.0, five of those in Fusion Middleware. TLP:CLEAR   PAP:CLEAR   Unlimited disclosure, no restriction on use. Published 16 September 2026 Subject Oracle, September 2026 CSPU Distribution Public Confidence…

RoguePlanet: a new Microsoft Defender zero-day disclosed in the wake of Patch Tuesday

RoguePlanet: a new Microsoft Defender zero-day disclosed in the wake of Patch Tuesday Threat Intelligence · Vulnerability June 10, 2026 · Marc-Frédéric Gomez · 6 min read Just hours after the June 2026 fixes shipped, the researcher Nightmare Eclipse published a new exploit targeting Microsoft Defender. It works against Windows systems that are already up…

Project Glasswing

Artificial Intelligence — vulnerabilities-anthropic What the First Public Update on Claude Mythos Reveals Anthropic published on May 22, 2026 the results of the first month of its defensive initiative. More than 10,000 vulnerabilities of high or critical severity identified, a bottleneck that has shifted from detection to remediation, and an access strategy that draws a…

Two Windows zero-days disclosed without coordination

CTI Analysis · Critical Vulnerability BitLocker Is No Longer a Promise: What the YellowKey Case Reveals Two Windows zero-days disclosed without coordination, a researcher openly challenging Microsoft, and a phantom component in the Windows Recovery Environment whose true nature, bug or backdoor, no one can yet determine. Published May 14, 2026 Reading time 15 minutes…