National Vulnerability Database
PulseAugur coverage of National Vulnerability Database — every cluster mentioning National Vulnerability Database across labs, papers, and developer communities, ranked by signal.
2 day(s) with sentiment data
-
Four MCP Servers Ship Unauthenticated CVEs; mcp-atlassian Sees 29 Flaws
This week, four different Model Context Protocol (MCP) servers were found to have critical unauthenticated vulnerabilities, allowing unauthorized access to sensitive data and system functions. These issues, including a …
-
Security flaws in MCP stdio launch boundary enable unauthorized server execution
A security analysis highlights critical authorization flaws in the MCP stdio launch boundary, arguing that current security practices focus on tool call authorization rather than the initial server launch. The author po…
-
AI exacerbates software vulnerability crisis, pushing CTEM adoption
The increasing volume of software vulnerabilities, exacerbated by AI's ability to discover and weaponize them, is overwhelming traditional patch-and-forget methods. Experts like Drew Vanover from Horizon3 highlight that…
-
AI Agents Suffer Security Flaws Due to Market Rush, Mirroring IoT Issues
AI agents are being released with security vulnerabilities due to a rush to market, mirroring security flaws found in IoT devices years ago. This 'AI Agents Security Debt' arises because development teams often fail to …
-
AI accelerates cybersecurity, shows mixed impact on math and AI research · 2 sources tracked
A recent analysis from METR suggests that while AI has significantly accelerated progress in cybersecurity, its impact on mathematics research is less pronounced and harder to quantify, and its effect on AI research its…
-
Jira Ticket Vulnerability Allows Server Command Execution
A security vulnerability, identified as CVE-2026-73498, has been disclosed where a Jira ticket could be manipulated to execute commands on a server. This exploit leveraged a tool within the MCP Atlassian server to read …
-
Critical macOS Screen Sharing flaw exploited for Monero cryptojacking
A critical vulnerability in macOS Screen Sharing, identified as CVE-2026-65400, is being actively exploited by attackers to gain remote root access on Macs. The flaw allows unauthorized authentication, leading to the in…
-
NIST plans AI-era overhaul of National Vulnerability Database amid funding concerns
The National Institute of Standards and Technology (NIST) is initiating a project to re-envision its National Vulnerability Database for the age of artificial intelligence. This overhaul aims to create a new blueprint f…
-
AI accelerates discovery rate, especially for cyber vulnerabilities · METR analysis
A new analysis from METR suggests that the rate of publicly disclosed discoveries has accelerated, particularly in the realm of cybersecurity vulnerabilities. While AI's contribution is evident in some areas, such as a …
-
NIST flags LLM threat to National Vulnerability Database processes · 2 sources tracked
The National Institute of Standards and Technology (NIST) has expressed concern regarding the evolving capabilities of large language models (LLMs) in discovering and exploiting software vulnerabilities. NIST believes t…
-
Generative AI tool AegisShield democratizes cyber threat modeling
Researchers have developed AegisShield, a generative AI tool designed to automate and simplify cyber threat modeling, particularly for organizations with limited resources. The tool integrates the STRIDE framework and M…
-
AI discovers vulnerabilities faster than humans can fix them
AI is discovering software vulnerabilities at a rate far exceeding human capacity for remediation. A recent analysis indicates that over 90% of AI-identified vulnerabilities are valid, yet only 6% are being patched. Thi…
-
China flags 'backdoor' vulnerabilities in Anthropic's Claude Code
China's National Vulnerability Database has issued a warning regarding Anthropic's Claude Code, alleging that certain versions contain security backdoor vulnerabilities. The government claims a monitoring mechanism with…
-
China flags 'backdoor' risks in Anthropic's Claude Code; AI firm responds
China's Ministry of Industry and Information Technology (MIIT) has issued a warning regarding security risks associated with Anthropic's Claude Code AI tool, citing a "backdoor" that could transmit sensitive user data. …
-
New knowledge graph links software vulnerabilities to attack behaviors
Researchers have developed a new knowledge graph, CVE-TTP KG, designed to link software vulnerabilities with attacker tactics and techniques. This system aims to improve threat interpretation by connecting information f…
-
Security expert warns against AI agents for alert overload
A security expert argues against deploying AI agents to manage the overwhelming volume of cybersecurity alerts, particularly in the wake of the National Vulnerability Database (NVD) pipeline collapse. The expert emphasi…
-
CyberGraph RAG uses TigerGraph to improve LLM cybersecurity analysis
Researchers developed CyberGraph RAG, a system designed to improve how large language models handle cybersecurity data by leveraging graph databases. Unlike traditional RAG which struggles with the relational nature of …
-
AI security tools may hallucinate vulnerabilities from training data
Large language models used for AI-assisted vulnerability discovery can falsely present information from their training data as novel findings. This occurs because LLMs cannot distinguish between recalling information ab…
-
CyberSecQwen-4B: Small, specialized model offers local defense for cybersecurity
A new, specialized language model named CyberSecQwen-4B has been developed for defensive cybersecurity tasks. This model is designed to be small, runnable locally, and handle sensitive data without needing external APIs…
-
New AI tool automates threat modeling for cyber-physical systems
Researchers have developed SMSI, a novel pipeline that automates threat modeling for cyber-physical systems. This system translates architectural models into actionable security control recommendations by mapping system…