Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The article discusses the impact of AI (specifically Anthropic's Mythos model) on vulnerability management, arguing that while AI compresses exploit timelines and accelerates attacker capabilities, the fundamental problem remains ineffective prioritization. Most security teams were not winning the prioritization battle before Mythos, and compressed timelines simply raise the cost of existing failures.
CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM), that updates and replaces the minimum elements for an SBOM published by the National Telecommunications...
CISA released updated 2026 guidance on minimum elements for Software Bill of Materials to strengthen software supply chain security. The new standards expand SBOM requirements for dependency tracking and vulnerability data.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CISA, along with other agencies, released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), updating the 2021 NTIA document. The guidance incorporates stakeholder feedback and reflects current SBOM tools, serving as a key building block for software security and supply chain risk management.
Researchers discovered a critical vulnerability (CVE-2026-10702) in Firefox's JIT compiler that allowed arbitrary code execution simply by visiting a malicious webpage, affecting both Firefox and Tor Browser users. The flaw, rated High by Mozilla, was patched in Firefox 151.0.3, but any Tor Browser release incorporating vulnerable Firefox versions (147 through 151.0.2) was also at risk.