LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
patch

Mythos has made 2026 patching hell. It might make 2027 a breeze

Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner

zeroday.news ·

The year 2026 has seen an unprecedented volume of software patches, creating significant challenges for cybersecurity teams, but this surge in vulnerability disclosures may signal a turning point towards more secure software in 2027. This perspective, presented at Gartner’s IT Symposium in Australia, suggests that AI-powered bug-hunting tools, such as Anthropic’s Mythos, are rapidly identifying flaws in established codebases, effectively paying down substantial technical debt.

The sheer number of patches, exemplified by Microsoft’s release of over 970 updates in a single week, initially appears daunting. However, this high volume is interpreted as a positive indicator that AI is performing an extensive audit of code that has never before been scrutinized to such a degree. Evidence for this includes the recent series of CVEs discovered in OpenBSD, an operating system historically recognized for its robust security and stability.

Security vendors themselves are leveraging AI to find flaws in their own products, further supporting the idea that these tools are eliminating potential avenues for zero-day attacks. This internal cleanup, combined with the external auditing of existing software, suggests that many vulnerabilities are being identified and addressed before they can be exploited.

Looking ahead, the increased use of AI in pre-release testing by vendors could lead to a significant reduction in new vulnerabilities. It is anticipated that 2027 might be the first year to see a net decrease, not necessarily in the aggregate number of vulnerabilities, but certainly in the severity of newly discovered flaws. This would be a result of both the ongoing cleanup of legacy code and more thorough testing of new releases.

Beyond proactive vulnerability discovery, AI is also expected to enhance defensive capabilities. Currently, red-teaming exercises are often infrequent and costly, typically requiring external providers. AI bug-hunters could enable organizations to conduct effective red-team simulations on a daily basis, providing continuous security assessments.

Furthermore, AI tools are projected to assist analysts in more quickly identifying and implementing fixes for discovered issues. For instance, AI could generate syntax for virtual patches, such as F5 IRules, in a matter of minutes, democratizing access to threat intelligence and enrichment tasks that were once more complex.

This shift in the cybersecurity landscape could also prompt a re-evaluation of how the impact of security operations centers (SOCs) is measured. Instead of focusing solely on the number of tickets processed, a more meaningful metric could be celebrating successful outcomes, such as preventing a hospital shutdown or stopping a ransomware attack, highlighting the critical role of cyber-defenders.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

vulnerability

DeepZero: Open-source hunting for vulnerable Windows drivers

DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether what survives can be attacked. Pipelines are written in YAML, the code is Python 3.11 and up. Rehman Ahmadzai, who maintains the project, said DeepZero h

breach

The modern attack chain: Rethinking Google Workspace security in the age of AI

Over the past two months, I’ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same observation: these aren’t isolated incidents. They’re the same attack, run twice, against different targets, where email was not the entry point into the workspace. And once you see the pattern clearly

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]