Common Vulnerability Scoring System
PulseAugur coverage of Common Vulnerability Scoring System — every cluster mentioning Common Vulnerability Scoring System across labs, papers, and developer communities, ranked by signal.
6 day(s) with sentiment data
-
CISA discontinues weekly vulnerability bulletin for risk-based approach · 2 sources tracked
The US Cybersecurity and Infrastructure Security Agency (CISA) has announced it will no longer publish its weekly vulnerability bulletin. This decision stems from a shift towards a more dynamic, risk-based prioritizatio…
-
Linux and open-source software receive critical security updates
This article discusses the recent updates and security patches for Linux and open-source software, highlighting an urgent hotfix with a critical CVSS score. It also touches upon the release of 113 packages and the chall…
-
New research tackles multilingual AI efficiency and capabilities
Researchers are developing new methods to improve the efficiency and capabilities of multilingual AI models. One study explores token merging for multilingual speech recognition, showing it can significantly reduce comp…
-
Critical CVSS-rated vulnerability prompts Debian and Void updates
A critical vulnerability, rated with a perfect CVSS score and no available workarounds, has been identified. Debian has released 107 updates, while Void has issued 113. The exact source of these updates remains unclear.
-
Critical Mastodon vulnerability (CVSS 10/10) allows server takeover via .prompty file
A critical vulnerability, rated 10 out of 10 on the Common Vulnerability Scoring System (CVSS), has been discovered in the Mastodon platform. This security flaw could be exploited through a seemingly harmless .prompty f…
-
AI exacerbates software vulnerability crisis, pushing CTEM adoption
The increasing volume of software vulnerabilities, exacerbated by AI's ability to discover and weaponize them, is overwhelming traditional patch-and-forget methods. Experts like Drew Vanover from Horizon3 highlight that…
-
Developer builds AI tool for vulnerability triage despite limited understanding of scoring systems
A developer built a vulnerability triage tool called triage-lens, which automates the prioritization of security risks. The tool uses data from CVSS, EPSS, and CISA KEV to rank vulnerabilities. While the developer initi…
-
Non-coder uses Claude Code to build vulnerability triage tool
A security consultant who admits to not being able to read code has successfully developed a vulnerability triage CLI tool named triage-lens, with Claude Code generating all of the code. The consultant established a set…
-
AI Agent Security Flaw: Audit Logs Tamperable, Cryptographic Receipts Proposed
Recent AI agent incidents, including a supply chain attack on filesystem-pro-plus and vulnerabilities in RufRoot and Microsoft UFO, highlight a critical security flaw: audit logs are generated by the systems they are me…
-
Microsoft patches critical Entra ID vulnerability with CVSS score of 10.0
Microsoft has patched a critical vulnerability in its Entra ID service that received a perfect CVSS score of 10.0. This security flaw would have allowed remote code execution without any user interaction. The company ha…
-
Critical macOS Screen Sharing flaw exploited for Monero cryptojacking
A critical vulnerability in macOS Screen Sharing, identified as CVE-2026-65400, is being actively exploited by attackers to gain remote root access on Macs. The flaw allows unauthorized authentication, leading to the in…
-
Samsung confirms 38 Android security fixes ahead of Google
Samsung has released its August 2026 Security Maintenance Release bulletin, detailing 38 Common Vulnerabilities and Exposures (CVEs) that Google provided for Android devices. This proactive disclosure by Samsung contras…
-
Critical 'Ruflo' vulnerability exposes OpenAI and Anthropic API keys
A critical vulnerability, rated CVSS 10.0, has been discovered that could expose API keys for major AI companies like OpenAI and Anthropic. The vulnerability, named "Ruflo," was identified by Luigi Zullo and poses a sig…
-
Anthropic proposes Cyber Jailbreak Severity scale with industry partners
Anthropic, in collaboration with partners like Amazon, Microsoft, and Google, has released a draft framework called the Cyber Jailbreak Severity (CJS) scale. This scale, inspired by the Common Vulnerability Scoring Syst…
-
Claude 3.5 Sonnet leads in AI code auditing benchmark, beating GPT-4o and Llama 3
A recent benchmark evaluated GPT-4o, Claude 3.5 Sonnet, and Llama 3 70B for their effectiveness in automated code auditing, specifically for detecting vulnerabilities in smart contracts. Claude 3.5 Sonnet emerged as the…
-
Critical CVE-2026-6875 vulnerability found in ServiceNow AI Platform
A critical vulnerability, CVE-2026-6875, has been identified in the ServiceNow AI Platform. This vulnerability carries a high CVSS score of 9.5, indicating a severe security risk. It allows for pre-authentication remote…
-
99.9% of AI package vulnerabilities with patches remain unaddressed, report finds
A July 2026 report by Orca Security, analyzing data from over 1200 organizations in Q2 2026, revealed that 99.9% of AI package vulnerabilities with available patches remain unaddressed. The study found that 81% of organ…
-
USAP tool enforces verifiable evidence for AI security verdicts
A new open-source tool called USAP has been developed to address the flaw in AI security analysts where correct and incorrect verdicts are indistinguishable. USAP enforces an "evidence gate" pattern, requiring every ver…
-
Prompt Injection and Missing Auth Create Free LLM Abuse Vector
A security researcher discovered a vulnerability in an AI translation API that allowed for free, unauthenticated abuse of the underlying large language model. The vulnerability stemmed from a combination of missing auth…
-
AI-driven vulnerability discovery creates noise, not safety, for security teams
The increasing use of AI in vulnerability discovery is overwhelming security teams with a flood of findings, which does not necessarily equate to improved security. While AI accelerates the identification of weaknesses …