CVE
TrialTechniques
Common Vulnerabilities and Exposures, a standard identifier system for publicly known security vulnerabilities.
Why it's here
Placed in Trial: 7 article(s) of evidence from 3 source(s), led by security coverage, with 2 in the last 30 days. Confidence 61%.
Evidence (7)
- 7The New Stack·8/3/2026securityApple caps open security reports as AI-assisted bug findings surge
Apple has introduced limits on how many security reports some researchers can keep open at once, with a 30-day wait after the cap is reached. The policy change comes after an influx of AI-assisted submissions, including a real macOS vulnerability reported by Bynario using GPT-5.5 that Apple later fixed as CVE-2026-43760.
- 7The New Stack·7/28/2026securityAI is reshaping open source security and maintainer support
Frontier AI models are increasing the volume of security findings in open source software, creating a backlog that maintainers and enterprises must triage and fix faster. The article argues that first-party support from project maintainers is becoming a more important part of enterprise risk management because AI has made vulnerability discovery far faster than traditional workflows.
- 7The New Stack·7/10/2026securityRapidFort and ReversingLabs pair up on supply-chain package validation
RapidFort announced a partnership with ReversingLabs to offer a curated open-source dependency library catalog with hardening and independent validation. The goal is to help developers avoid malicious packages that may have no CVEs but still compromise builds, credentials, or CI pipelines.
- 7The New Stack·7/9/2026securityCISA pushes deeper SBOM checks for hardened images
The article discusses updated 2025 CISA guidance saying SBOMs should include all components, including transitive dependencies, with no minimum depth, plus configuration files and fork lineage. It argues that security teams should validate hardened container images with quick “sniff tests” to catch incomplete inventories, improve vulnerability response, and reduce supply chain risk.
- 8Hacker News·7/8/2026securityOpenBSD use-after-free bug enables local root escalation
A vulnerability identified as CVE-2026-57589 affects OpenBSD through version 7.9 in sys/kern/sysv_sem.c. The flaw is a use-after-free in sys_semget() that can allow a local attacker to escalate privileges to root, with a MITRE-assessed CVSS 3.1 score of 7.4 high.
- 8Hacker News·7/8/2026securityHidden authentication backdoor found in multiple Tenda firmware versions
CERT/SEI reports that several Tenda firmware versions contain an undocumented backdoor in the web management login flow, allowing admin access without valid credentials. The issue is tracked as CVE-2026-11405, and mitigation is limited to workarounds because no vendor patch is available yet.
- 8GitHub Blog·6/29/2026securityGitHub Advisory Database faces record vulnerability backlog
GitHub says its Advisory Database processed a record volume of vulnerability reports in May 2026, driven by surges in private vulnerability reports, repository advisories, and CVE requests. Review times have lengthened, but published advisories remain human-validated and existing alerts continue to work normally.