<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Vulnerability on Tenu Tech Brief</title>
    <link>https://cluster-site.onrender.com/tags/vulnerability/</link>
    <description>Recent content in Vulnerability on Tenu Tech Brief</description>
    <generator>Hugo -- 0.146.0</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 25 Feb 2026 09:56:00 +0000</lastBuildDate>
    <atom:link href="https://cluster-site.onrender.com/tags/vulnerability/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Claude&#39;s New AI Vulnerability Scanner Sends Cybersecurity Shares Plunging</title>
      <link>https://cluster-site.onrender.com/posts/claudes-new-ai-vulnerability-scanner-sends-cybersecurity-shares-plunging/</link>
      <pubDate>Wed, 25 Feb 2026 09:44:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/claudes-new-ai-vulnerability-scanner-sends-cybersecurity-shares-plunging/</guid>
      <description>• The stocks of major cybersecurity companies have fallen sharply after AI firm Anthropic unveiled a new security capability for its Claude LLM.Anthropic announced on Friday that i</description>
    </item>
    <item>
      <title>Open Redirects: A Forgotten Vulnerability&amp;#x3f;, (Tue, Feb 24th)</title>
      <link>https://cluster-site.onrender.com/posts/open-redirects-a-forgotten-vulnerability%23x3f-tue-feb-24th/</link>
      <pubDate>Tue, 24 Feb 2026 18:04:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/open-redirects-a-forgotten-vulnerability%23x3f-tue-feb-24th/</guid>
      <description>• Open Redirects: A Forgotten Vulnerability? • In 2010, OWASP added &amp;lsquo;Unvalidated Redirects and Forwards&amp;rsquo; to its Top 10 list and merged it into &amp;lsquo;Sensitive Data Exposure&amp;rsquo; in 2013 [ow</description>
    </item>
    <item>
      <title>VMware Aria Operations Vulnerability Could Allow Remote Code Execution</title>
      <link>https://cluster-site.onrender.com/posts/vmware-aria-operations-vulnerability-could-allow-remote-code-execution/</link>
      <pubDate>Tue, 24 Feb 2026 14:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vmware-aria-operations-vulnerability-could-allow-remote-code-execution/</guid>
      <description>• Broadcom has released patches for several vulnerabilities affecting VMware Aria Operations, including high-severity flaws.The most important of the newly patched vulnerabilities</description>
    </item>
    <item>
      <title>HCP Packer adds SBOM vulnerability scanning</title>
      <link>https://cluster-site.onrender.com/posts/hcp-packer-adds-sbom-vulnerability-scanning/</link>
      <pubDate>Tue, 24 Feb 2026 00:31:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/hcp-packer-adds-sbom-vulnerability-scanning/</guid>
      <description>• HCP Packer adds SBOM vulnerability scanning Mitchell Ross HCP Risk &amp;amp; compliance Packer Feb 17, 2026 Mitchell Ross Share article Twitter share LinkedIn share Facebook share Copy U</description>
    </item>
    <item>
      <title>Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning</title>
      <link>https://cluster-site.onrender.com/posts/anthropic-launches-claude-code-security-for-ai-powered-vulnerability-scanning/</link>
      <pubDate>Sat, 21 Feb 2026 07:58:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/anthropic-launches-claude-code-security-for-ai-powered-vulnerability-scanning/</guid>
      <description>• Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning Artificial intelligence (AI) company Anthropic has begun to roll out a new security feature for Clau</description>
    </item>
    <item>
      <title>In Other News: Ransomware Shuts US Clinics, ICS Vulnerability Surge, European Parliament Bans AI</title>
      <link>https://cluster-site.onrender.com/posts/in-other-news-ransomware-shuts-us-clinics-ics-vulnerability-surge-european-parliament-bans-ai/</link>
      <pubDate>Fri, 20 Feb 2026 15:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/in-other-news-ransomware-shuts-us-clinics-ics-vulnerability-surge-european-parliament-bans-ai/</guid>
      <description>• SecurityWeek&amp;rsquo;s cybersecurity news roundup provides a concise compilation of noteworthy stories that might have slipped under the radar.We provide a valuable summary of stories th</description>
    </item>
    <item>
      <title>VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)</title>
      <link>https://cluster-site.onrender.com/posts/vshell-and-sparkrat-observed-in-exploitation-of-beyondtrust-critical-vulnerability-cve-2026-1731/</link>
      <pubDate>Thu, 19 Feb 2026 23:00:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vshell-and-sparkrat-observed-in-exploitation-of-beyondtrust-critical-vulnerability-cve-2026-1731/</guid>
      <description>• Executive Summary On Feb. • 6, 2026, BeyondTrust released a security advisory regarding CVE-2026-1731. • BeyondTrust is an identity and access management platform. • This specifi</description>
    </item>
    <item>
      <title>AI agents are accelerating vulnerability discovery. Here&#39;s how AppSec teams must adapt.</title>
      <link>https://cluster-site.onrender.com/posts/ai-agents-are-accelerating-vulnerability-discovery.-heres-how-appsec-teams-must-adapt./</link>
      <pubDate>Thu, 19 Feb 2026 21:31:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-agents-are-accelerating-vulnerability-discovery.-heres-how-appsec-teams-must-adapt./</guid>
      <description>• We&amp;rsquo;re so glad you&amp;rsquo;re here. • You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game. • Check</description>
    </item>
    <item>
      <title>ZDI-26-111: MLflow Use of Default Password Authentication Bypass Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-111-mlflow-use-of-default-password-authentication-bypass-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-111-mlflow-use-of-default-password-authentication-bypass-vulnerability/</guid>
      <description>• Advisory Details MLflow Use of Default Password Authentication Bypass Vulnerability ZDI-26-111ZDI-CAN-28256 This vulnerability allows remote attackers to bypass authentication on</description>
    </item>
    <item>
      <title>ZDI-26-120: GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-120-gimp-icns-file-parsing-heap-based-buffer-overflow-remote-code-execution-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-120-gimp-icns-file-parsing-heap-based-buffer-overflow-remote-code-execution-vulnerability/</guid>
      <description>• Remote attackers can execute arbitrary code via GIMP ICNS file parsing. • Exploit requires user interaction: opening malicious file or visiting malicious page. • Vulnerability du</description>
    </item>
    <item>
      <title>HCP Packer adds SBOM vulnerability scanning</title>
      <link>https://cluster-site.onrender.com/posts/hcp-packer-adds-sbom-vulnerability-scanning/</link>
      <pubDate>Thu, 19 Feb 2026 00:46:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/hcp-packer-adds-sbom-vulnerability-scanning/</guid>
      <description>• HCP Packer adds SBOM vulnerability scanning Mitchell Ross HCP Risk &amp;amp; compliance Packer Feb 17, 2026 Mitchell Ross Share article Twitter share LinkedIn share Facebook share Copy U</description>
    </item>
    <item>
      <title>National analysis maps German hospital vulnerability to flood-driven traffic disruptions</title>
      <link>https://cluster-site.onrender.com/posts/national-analysis-maps-german-hospital-vulnerability-to-flood-driven-traffic-disruptions/</link>
      <pubDate>Wed, 18 Feb 2026 22:30:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/national-analysis-maps-german-hospital-vulnerability-to-flood-driven-traffic-disruptions/</guid>
      <description>• Due to climate change, extreme weather events such as flooding are expected to increase in Germany in the future. • This poses hidden risks to the health care system that have ha</description>
    </item>
    <item>
      <title>Checkmarx Extends Vulnerability Detection to AI Coding Tool from AWS</title>
      <link>https://cluster-site.onrender.com/posts/checkmarx-extends-vulnerability-detection-to-ai-coding-tool-from-aws/</link>
      <pubDate>Wed, 18 Feb 2026 22:15:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/checkmarx-extends-vulnerability-detection-to-ai-coding-tool-from-aws/</guid>
      <description>• Checkmarx this week revealed it has added support for the Kiro artificial intelligence (AI) coding tool provided by Amazon Web Services (AWS) to its Checkmarx Developer Assist th</description>
    </item>
    <item>
      <title>Telegram channels expose rapid weaponization of SmarterMail flaws</title>
      <link>https://cluster-site.onrender.com/posts/telegram-channels-expose-rapid-weaponization-of-smartermail-flaws/</link>
      <pubDate>Wed, 18 Feb 2026 16:27:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/telegram-channels-expose-rapid-weaponization-of-smartermail-flaws/</guid>
      <description>• SmarterMail CVE-2026-24423 and CVE-2026-23760 enable remote code execution and auth bypass. • Attackers weaponized these flaws within days of disclosure, sharing exploits on Tele</description>
    </item>
    <item>
      <title>Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration</title>
      <link>https://cluster-site.onrender.com/posts/vulnerabilities-in-popular-pdf-platforms-allowed-account-takeover-data-exfiltration/</link>
      <pubDate>Wed, 18 Feb 2026 13:16:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vulnerabilities-in-popular-pdf-platforms-allowed-account-takeover-data-exfiltration/</guid>
      <description>• 16 critical, high, and medium‑severity vulnerabilities found in Foxit and Apryse PDF platforms. • Flaws include DOM XSS, SSRF, path traversal, and OS command injection. • Attacke</description>
    </item>
    <item>
      <title>ZDI-26-107: Autodesk AutoCAD MODEL File Out-Of-Bounds Write Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-107-autodesk-autocad-model-file-out-of-bounds-write-remote-code-execution-vulnerability/</link>
      <pubDate>Wed, 18 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-107-autodesk-autocad-model-file-out-of-bounds-write-remote-code-execution-vulnerability/</guid>
      <description>• Remote code execution via out-of-bounds write in AutoCAD MODEL file parsing. • Requires user to open malicious file or visit malicious page. • Exploit writes past allocated buffe</description>
    </item>
    <item>
      <title>VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence</title>
      <link>https://cluster-site.onrender.com/posts/vulncheck-raises-25-million-in-series-b-funding-to-scale-vulnerability-intelligence/</link>
      <pubDate>Tue, 17 Feb 2026 16:00:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vulncheck-raises-25-million-in-series-b-funding-to-scale-vulnerability-intelligence/</guid>
      <description>• Vulnerability intelligence company VulnCheck announced on Tuesday that it has raised $25 million to meet demand for its solutions.The Series B funding round, which brings the tot</description>
    </item>
    <item>
      <title>Reduce Vulnerability Noise with VEX: Wiz &#43; Docker Hardened Images</title>
      <link>https://cluster-site.onrender.com/posts/reduce-vulnerability-noise-with-vex-wiz--docker-hardened-images/</link>
      <pubDate>Thu, 05 Feb 2026 23:25:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/reduce-vulnerability-noise-with-vex-wiz--docker-hardened-images/</guid>
      <description>• Reduce Vulnerability Noise with VEX: Wiz + Docker Hardened Images Open source components power most modern applications. • A new generation of hardened container images can estab</description>
    </item>
    <item>
      <title>Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529</title>
      <link>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</link>
      <pubDate>Fri, 30 Jan 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</guid>
      <description>• CVE-2024-54529: type confusion in CoreAudio&amp;rsquo;s com.apple.audio.audiohald Mach service, causing crashes. • Exploitation involved manipulating Mach messages to fetch wrong HALS_Obje</description>
    </item>
    <item>
      <title>Microsoft releases update to address zero-day vulnerability in Microsoft Office</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-releases-update-to-address-zero-day-vulnerability-in-microsoft-office/</link>
      <pubDate>Thu, 29 Jan 2026 14:43:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-releases-update-to-address-zero-day-vulnerability-in-microsoft-office/</guid>
      <description>• Microsoft releases update to address zero-day vulnerability in Microsoft Office Microsoft has published three out-of-band (OOB) updates so far in January 2026. • One of these upd</description>
    </item>
    <item>
      <title>Foxit, Epic Games Store, MedDreams vulnerabilities</title>
      <link>https://cluster-site.onrender.com/posts/foxit-epic-games-store-meddreams-vulnerabilities/</link>
      <pubDate>Thu, 22 Jan 2026 13:54:57 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/foxit-epic-games-store-meddreams-vulnerabilities/</guid>
      <description>• Cisco Talos uncovered 25 critical vulnerabilities across Foxit PDF Editor, Epic Games Store, and MedDreams PACS. • Foxit PDF Editor had privilege escalation via Microsoft Store i</description>
    </item>
    <item>
      <title>How we mitigated a vulnerability in Cloudflare&#39;s ACME validation logic</title>
      <link>https://cluster-site.onrender.com/posts/how-we-mitigated-a-vulnerability-in-cloudflares-acme-validation-logic/</link>
      <pubDate>Mon, 19 Jan 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-we-mitigated-a-vulnerability-in-cloudflares-acme-validation-logic/</guid>
      <description>• How we mitigated a vulnerability in Cloudflareâ s ACME validation logic 2026-01-19 Hrushikesh Deshpande Andrew Mitchell Leland Garofalo This post was updated on January 20, 2026.</description>
    </item>
    <item>
      <title>Threat Brief: MongoDB Vulnerability (CVE-2025-14847)</title>
      <link>https://cluster-site.onrender.com/posts/threat-brief-mongodb-vulnerability-cve-2025-14847/</link>
      <pubDate>Tue, 13 Jan 2026 20:30:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-brief-mongodb-vulnerability-cve-2025-14847/</guid>
      <description>• Executive Summary On Dec. • 19, 2025, MongoDB publicly disclosed MongoBleed, a security vulnerability (CVE-2025-14847) that allows unauthenticated attackers to leak sensitive hea</description>
    </item>
    <item>
      <title>No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480</title>
      <link>https://cluster-site.onrender.com/posts/no-place-like-localhost-unauthenticated-remote-access-via-triofox-vulnerability-cve-2025-12480/</link>
      <pubDate>Mon, 10 Nov 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/no-place-like-localhost-unauthenticated-remote-access-via-triofox-vulnerability-cve-2025-12480/</guid>
      <description>• No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480 Mandiant Written by: Stallone D&amp;rsquo;Souza, Praveeth DSouza, Bill Glynn, Kevin O&amp;rsquo;Flynn,</description>
    </item>
    <item>
      <title>Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider</title>
      <link>https://cluster-site.onrender.com/posts/ransomware-actors-exploit-unpatched-simplehelp-remote-monitoring-and-management-to-compromise-utility-billing-software-provider/</link>
      <pubDate>Thu, 12 Jun 2025 14:29:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ransomware-actors-exploit-unpatched-simplehelp-remote-monitoring-and-management-to-compromise-utility-billing-software-provider/</guid>
      <description>• Ransomware actors target unpatched SimpleHelp RMM to breach utility billing software provider customers. • Vulnerability CVE-2024-57727, a path traversal flaw, exploited in Simpl</description>
    </item>
    <item>
      <title>The threat from commercial cyber proliferation</title>
      <link>https://cluster-site.onrender.com/posts/the-threat-from-commercial-cyber-proliferation/</link>
      <pubDate>Wed, 12 Mar 2025 11:20:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-threat-from-commercial-cyber-proliferation/</guid>
      <description>• Commercial software proliferation expands attack surface, increasing vulnerability exposure across enterprises. • Open-source components in commercial stacks introduce hidden bac</description>
    </item>
  </channel>
</rss>
