
Responding to the Five Eyes guidance on AI and cyber risk
The Five Eyes AI guidance urges organizations to strengthen software supply chain security. Learn how Chainguard helps teams stay ahead.
2432 articles

The Five Eyes AI guidance urges organizations to strengthen software supply chain security. Learn how Chainguard helps teams stay ahead.

Stop writing manual API calls and hand-rolling token refresh logic. Learn how to accelerate your production setups using the Auth0 SDK, Auth0 CLI, and Infrastructure as Code.

Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as “critical.”

Security Hub is our foundation for full-stack enterprise security across clouds. It centralizes your security operations and turns raw signals into prioritized insights, so your team spends its time managing real risk instead of stitching tools together. Today that foundation grows in two directions our customers asked for most. We are adding purpose-built protection for

AI agents are part of the modern development workflow. They write code, review pull requests, generate tests, call tools, interact with MCP servers, and help developers move faster. But behind every useful agent, there is something just as important as the model itself: the context that tells the agent how to behave. That context can

The Cloud Security Alliance (CSA) has unveiled the AI Controls Matrix (AICM) v1.1, enhancing its framework for secure AI systems. This latest version broadens control coverage, introduces a dedicated Model Security domain, and incorporates AI-specific security controls. Additionally, it provides comprehensive mappings to major AI governance frameworks globally, further solidifying its commitment to promoting trustworthy AI practices in the industry.

As AI agents and automated tools increasingly access web applications, distinguishing legitimate bot traffic from malicious attempts has become a critical security challenge. Traditional approaches such as IP-based filtering and reverse DNS lookups fail in multi-tenant systems (such as Amazon Bedrock AgentCore) where thousands of distinct workloads share the same IP space. Attackers can easily

ABB has acknowledged a vulnerability, CVE-2026-31431, in certain versions of its Ability Edgenius products that could allow a locally authenticated user to gain elevated root privileges on systems using a compromised Linux kernel. This flaw could enable attackers to control the affected system entirely. ABB has released an update (version 3.2.4.1) to address the issue and recommends immediate application of this fix. It is advised to limit access to the affected systems and implement additional security measures, as successful exploitation requires local access.

ABB has identified a vulnerability in certain versions of its Advant Master Online Builder products, where an incorrect version of the Online Builder was included, potentially allowing unauthorized execution of code. The affected versions have been documented, and an update has been released to remediate the issue. ABB recommends users upgrade to the fixed versions, enforce strong password policies, and restrict access to unauthorized users to mitigate risks associated with this vulnerability.

ABB has identified vulnerabilities in its T-MAC Plus version 4.0-24 products, which could allow attackers to compromise systems through various methods, including file disclosure, unauthorized access, cross-site scripting, and denial-of-service attacks. Affected users are urged to update to version 4.0-25 to resolve these critical and high-severity issues. Specific mitigations and workarounds are suggested, but the vulnerabilities require proper updates for full resolution. The vulnerabilities were responsibly disclosed and do not appear to have been exploited publicly prior to the advisory.

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting active exploitation risks. The vulnerabilities include server-side request forgery and code injection for SonicWall SMA1000 Appliances, as well as access control and authentication issues in Microsoft Active Directory and SharePoint Server. The Binding Operational Directive 26-04 mandates federal agencies to prioritize rapid remediation of these high-risk vulnerabilities. CISA urges all organizations to adopt similar risk-based management practices and encourages submissions for additional vulnerabilities meeting specific criteria.

CISA has updated its Alert regarding vulnerabilities impacting on-premises SharePoint Server versions, including CVE-2026-58644, which was added to the Known Exploited Vulnerabilities Catalog on July 16, 2026. Active exploitation is noted for multiple vulnerabilities, enabling unauthorized access and malware deployment. Organizations are advised to apply the latest patches, utilize security measures, and monitor for unusual activity. CISA recommends strengthening security around SharePoint Servers and encourages reporting any anomalies.