Security Intelligence

Blog

Technical depth on vulnerability management, AI-powered remediation, and TRIS™ scoring. Written by practitioners, for practitioners.

Oracle PeopleSoft PSEMHUB pre-authentication remote code execution exploited by ShinyHunters
Zero-Day Active Exploitation

CVE-2026-35273: Oracle PeopleSoft Pre-Auth RCE Zero-Day Lets ShinyHunters Breach 100+ Organizations Across a Two-Week Exploitation Window

A CVSS 9.8 pre-authentication RCE in the Oracle PeopleSoft Enterprise PeopleTools Updates Environment Management component (PSEMHUB) was exploited as a zero-day by ShinyHunters (UNC6240) from May 27 through June 9, 2026. Oracle shipped an out-of-band Security Alert on June 10. ShinyHunters claims 100 plus breached organizations across 300 vulnerable internet-facing instances, with 40 GB of student and billing data confirmed stolen from the University of Nottingham.

Check Point VPN IKEv1 authentication bypass exploited by Qilin ransomware affiliate
CISA KEV Active Exploitation

CVE-2026-50751: Check Point VPN IKEv1 Auth Bypass Lets a Qilin Ransomware Affiliate In Without a Password, CISA KEV Deadline June 11

A CVSS 9.3 certificate validation logic error in Check Point Remote Access VPN and Mobile Access gateways lets unauthenticated attackers establish a VPN session without a valid password. Exploited in the wild since May 7, 2026, with at least one Qilin ransomware affiliate intrusion already confirmed.

The shift from vulnerability management to exposure management and resiliency
Field Notes Exposure Management

Why Vulnerability Management Teams Are About to Become Exposure Management Teams

Field notes from the Gartner Security & Risk Management Summit. Under the agentic-AI hype, every serious conversation circled back to one word: resiliency. The identity shift to exposure management, the tools getting it right, and why defenders should build it.

Cisco Catalyst SD-WAN Manager privilege escalation zero-day
Zero-Day Active Exploitation

CVE-2026-20245: Cisco's 7th 2026 SD-WAN Zero-Day Walks netadmin Straight to Root, No Patch Available

Cisco's June 5 advisory cisco-sa-sdwan-privesc-4uxFrdzx confirms in-the-wild exploitation of a CVSS 7.8 privilege escalation in Catalyst SD-WAN Manager that lets a netadmin operator reach root on the controller. No fix exists today, and the bug chains off two earlier 2026 netadmin disclosures.

Miasma worm hijacks official Red Hat Cloud Services npm packages
Supply Chain Threat Intel

Miasma Worm Hijacks 96 Versions of 32 Official @redhat-cloud-services npm Packages to Sweep Cloud Credentials

On June 1, 2026 the Miasma variant of the Shai-Hulud npm worm rode Red Hat's own GitHub Actions OIDC trust to republish 96 versions of 32 official @redhat-cloud-services packages, sweeping AWS, GCP, Azure, npm, and CI credentials at install time.

Palo Alto PAN-OS GlobalProtect authentication bypass
CISA KEV Active Exploitation

CVE-2026-0257: Forged GlobalProtect Cookies Drop Attackers Inside Enterprise VPNs as CISA Deadline Hits Today

An authentication bypass in Palo Alto Networks PAN-OS GlobalProtect lets unauthenticated attackers forge override cookies and claim internal VPN IP addresses. Active exploitation. CISA KEV deadline June 1.

Megalodon GitHub Actions supply chain campaign
Supply Chain Threat Intel

Six Hours, 5,561 Repos: Megalodon Backdoored GitHub Actions to Harvest CI/CD Secrets

A threat actor tracked as TeamPCP pushed 5,718 malicious commits into 5,561 GitHub repositories in six hours, injecting backdoored Actions workflows to steal CI/CD secrets. No CVE. Named in a CISA advisory.

Poisoned Nx Console extension supply chain breach
Supply Chain Threat Intel

An 18-Minute Window: Poisoned Nx Console Extension Breaches 3,800 GitHub Internal Repos

A malicious Nx Console VS Code extension (nrwl.angular-console v18.95.0) lived 18 minutes, silently auto-updated to roughly 6,000 developers, and led to the breach of about 3,800 GitHub internal repos. CVE-2026-48027. Confirmed exploitation.

TrapDoor weaponizes AI coding assistants
Supply Chain AI Security

TrapDoor: 34 Malicious Packages Weaponize Your AI Coding Assistant to Steal Crypto Wallets and Cloud Keys

A cross-ecosystem credential stealer planted 34 packages and 384+ versions across npm, PyPI, and Crates.io, poisoning AI assistant config files to exfiltrate wallet keys, SSH keys, and cloud credentials. No CVE. Confirmed active.

Exposure-driven patch triage
Supply Chain AI Security

Patch Everything Is Dead: AI Teams Are Shipping Software They Cannot Secure

AI expanded the build and dependency surface faster than security maturity could follow. Why context engineering and exposure-driven prioritization replace the patch-everything treadmill.

Composer package hijack credential stealer
Supply Chain Threat Intel

Laravel-Lang Composer Packages Hijacked via Git Tag Rewrite to Deploy Cross-Platform Credential Stealer

Attackers rewrote 502 git tags across four Composer packages to execute a credential stealer on every composer install. No CVE. Confirmed exploitation.

TRIS v2 12-layer intelligence engine
TRIS v2 Patent Pending Scoring

TRIS v2: The 12-Layer Vulnerability Intelligence Engine Built by Analysts, Not Cloud Vendors

CVSS tells you severity. EPSS predicts exploitation. Cloud engines score in someone else's building. TRIS v2 runs on your hardware across twelve layers, five of them brand new. Your data never leaves your network.

ctem implementation framework
Pillar Guide CTEM Framework

The CTEM Implementation Framework: A Practitioner's Guide to Continuous Threat Exposure Management

Everything you need to build a Continuous Threat Exposure Management program, stage by stage. All 5 Gartner CTEM stages. Integration patterns. Tool selection. Metrics. Pitfalls. A framework you can actually follow.

siem detection rules
SIEM MITRE ATT&CK

Building High-Fidelity Detection Rules: A SIEM Rule Engineering Guide

Master the art of building effective SIEM detection rules that reduce alert fatigue and catch real threats. Sigma rules, MITRE ATT&CK mapping, and practical examples.

mssp case study aegis shield
Case Study MSSP

Aegis Shield Security: 76% Fewer False Positives, $412K Saved

How a regional MSSP managing 180 SMB clients eliminated per-asset pricing, cut false positives by 76%, and recovered margins with CVEasy AI.

The CVEasy AI Command Center with risk posture and a TRIS priority queue
How-To Getting Started

How to Run Your First Vulnerability Scan with CVEasy AI

Thirty minutes from a cold install to knowing your real exposure. A practitioner walkthrough of importing a scan, reading the Command Center, triaging findings, and prioritizing fixes by TRIS.

A CVEasy AI CVE detail page showing the TRIS ring, EPSS and CISA KEV status
Scoring How-To

How to Read Your TRIS Score (and Stop Drowning in CVSS)

CVSS tells you how bad a vulnerability could be in theory. TRIS tells you what to do about it today. How to read the score, the action bands, and the Sprint Board, with a Log4Shell example.

The CVEasy AI Triage Queue kanban moving CVEs from New to Resolved
Workflow How-To

From Scan to Remediation in 30 Minutes

A timeboxed walk through the full loop. Get data in, read your risk, triage, prioritize by TRIS, fix, and prove it, in one sitting. Run it weekly and exposure stops being a fire drill.

vulnerability prioritization frameworks
Prioritization EPSS · SSVC

Beyond CVSS: Modern Vulnerability Prioritization Frameworks Compared

CVSS vs EPSS vs SSVC vs KEV vs TRIS™ , what each framework measures, what it misses, and how to layer them for composite scoring.

breach attack simulation
BAS Purple Teaming

Breach & Attack Simulation: Validating Your Defenses Continuously

What BAS is, MITRE ATT&CK mapping, automated vs manual testing, ROI measurement, and the open-source BASzy™ AI option.

kubernetes security scanning
Kubernetes Container Security

Kubernetes Security: From Cluster to Container Vulnerability Management

RBAC misconfigs, container image scanning, admission controllers, network policies, etcd security, and a hardening checklist.

api security testing
API Security OWASP API Top 10

API Security Testing: Finding Vulnerabilities Before Attackers Do

OWASP API Top 10, BOLA/BFLA testing, authentication bypass, rate limiting, GraphQL security, and building an API testing program.

devsecops vulnerability management
DevSecOps Developer Security

DevSecOps Vulnerability Management: Integrating Security Into Every Sprint

Security champions, PR scanning, automated dependency updates, security debt tracking, and metrics that prove DevSecOps maturity.

zero trust vulnerability management
Zero Trust Architecture

Zero Trust + Vulnerability Management: A Practical Implementation Guide

How VM fits into ZTA: micro-segmentation, continuous verification, device posture scoring, and a phased implementation roadmap.

mssp vulnerability management
MSSP Managed Security

MSSP Vulnerability Management: Building a Profitable Service Offering

Multi-tenant scanning, client reporting, SLA management, pricing models, and scaling from 10 to 100 clients profitably.

ot ics vulnerability management
OT / ICS SCADA Security

OT/ICS Vulnerability Management: Securing Critical Infrastructure

SCADA systems, the Purdue model, air-gapped scanning, ICS-CERT advisories, and compensating controls for systems that cannot be patched.

sbom vulnerability management
SBOM Supply Chain

SBOM + Vulnerability Management: The Complete Guide for 2026

NTIA minimum elements, CycloneDX vs SPDX, and how to operationalize SBOMs as the missing layer in your VM program.

cicd security scanning
DevSecOps CI/CD

CI/CD Security Scanning: Shift-Left Without Slowing Down

SAST, DAST, and SCA pipeline integration patterns, false positive management, and gate policies that developers will actually follow.

Attack surface and perimeter exposure
Attack Surface Asset Discovery

Attack Surface Management: From Discovery to Remediation

External attack surface discovery, asset inventory automation, continuous monitoring, and risk-based prioritization for the assets you didn't know you had.

ai red teaming
AI Security Red Teaming

AI Red Teaming: Testing LLM Security with BASzy™ AI

OWASP LLM Top 10, jailbreak testing, prompt injection detection, guardrail bypass, and agent security testing with BASzy™ AI.

vulnerability management for startups
Startups Budget Security

Vulnerability Management for Startups: Enterprise Security on a Budget

Right-sizing VM for small teams: the complete low-cost toolchain, minimum viable program, and SOC 2 compliance on a startup budget.

cloud security posture
Cloud Security CSPM

Cloud Security Posture Management: Bridging the VM Gap

CSPM vs traditional VM, cloud-native vulnerability classes your scanner misses, and how to unify both in one prioritization pipeline.

vulnerability remediation automation
Remediation Automation

Vulnerability Remediation Automation: From Scan to Fix in Minutes

Automated patching workflows, AI-generated fix guidance, SLA tracking with escalation, and the metrics that prove remediation velocity.

ciso board reporting
Executive Reporting Risk Quantification

CISO Board Reporting: Translating Vulnerabilities into Business Risk

Board-level metrics, FAIR risk quantification, executive dashboards, and the 5-slide framework that gets security budgets approved.

why i built cveasyai
Founder Story

Why I Built CVEasy AI on a Thursday Afternoon

I wasn't trying to start a company. I was tired of watching CVSS 6.5 vulnerabilities get skipped while teams chased 9.8s that nobody exploited.

stop paying 40k for vuln management
Enterprise Pricing

Stop Paying $40,000 a Year for Vulnerability Management

A direct comparison of Rapid7 InsightVM and SentinelOne Singularity VM, and why the price gap no longer makes sense in 2026.

ctem framework
CTEM

Continuous Threat Exposure Management (CTEM): The Gartner Framework Your Security Team Needs in 2026

The 5 stages of CTEM, how EPSS+KEV+asset criticality map to each stage, and an implementation roadmap by org size.

mitre attack vm
MITRE ATT&CK

Using MITRE ATT&CK for Vulnerability Prioritization: A Practical Playbook

Map CVEs to ATT&CK techniques. Score vulnerabilities by detection coverage. Patch what attackers actually exploit.

soc2 vm requirements
SOC 2

SOC 2 Type II Vulnerability Management: What Your Auditor Will Actually Check

CC7.1 explained: scan frequency, SLA documentation, evidence collection, and the gap between Vanta/Drata automation and human auditor scrutiny.

container security cves
Container Security

Container CVE Management: Docker Images and Kubernetes Clusters

Layer inheritance, SBOM generation with Syft and Grype, Cosign image signing, and automation with Dependabot and Renovate.

nvd osv ghsa compared
NVD · OSV · GHSA

NVD vs OSV vs GHSA: Which Vulnerability Database Should You Trust?

Coverage gaps, enrichment delays post-2024, ecosystem strengths, and how to build a multi-source aggregation pipeline.

fedramp vulnerability management
FedRAMP

FedRAMP Vulnerability Management: Scanning Requirements, SLAs, and Continuous Monitoring

RA-5 control requirements, mandatory CVSS-based SLA tiers, POA&M documentation, ConMon reports, and CSP vs 3PAO responsibilities.

threat intel integration
Threat Intel OSINT

Building a Threat Intelligence Pipeline: How to Feed OSINT Into Your Vulnerability Program

OTX, MISP, Shodan, GreyNoise, KEV, EPSS, how to correlate feeds, map IOCs to CVEs, weight sources, and set alert thresholds.

patch automation pipelines
Patch Automation

Patch Automation Pipelines: From CVE to Deployed Fix Without Human Bottlenecks

The 5-stage pipeline, Ansible playbooks, Kubernetes rolling updates, canary deployments, rollback triggers, and SLA tracking automation.

Local-first AI vulnerability intelligence
AI Architecture

Local-First LLM Architecture: Why Your AI Shouldn't Phone Home

The data sovereignty and privacy case for running vulnerability AI on your own infrastructure.

alert fatigue
Triage Strategy

Alert Fatigue Is Killing Your Security Team. Here's the Fix

How correlated intelligence cuts signal-to-noise ratio and surfaces the vulnerabilities that are actually on fire.

ransomware triage
Ransomware EPSS

Ransomware Triage: Using EPSS + KEV to Patch Before You're Breached

The predictive framework for patching the vulnerabilities ransomware actors exploit most, before they get there.

epss kev scoring
EPSS KEV

EPSS + KEV + Enterprise Context: The New Vulnerability Scoring Stack

A deep dive into the three-layer scoring model that replaces CVSS-only prioritization.

zero day exploits
Zero-Day Threat Intel

Zero-Day Exploits: What Happens in the Window Before the Patch Drops

Understanding the exploit lifecycle and how to reduce your exposure before CVEs are even published.

patch tuesday triage
Patch Management

Patch Tuesday Survival Guide: Triaging 100+ CVEs Before Wednesday Morning

A repeatable 5-step workflow for turning Microsoft's monthly release into a ranked, defensible patch order in under two hours.

build vm program
Program Building

Building a Vulnerability Management Program from Scratch

A practitioner's guide to the four pillars of VM: asset discovery, assessment, prioritization, and remediation.

cisa kev deep dive
CISA KEV Compliance

CISA KEV Deep Dive: The 14-Day Clock That Should Drive Your Patch Queue

BOD 22-01 created a mandatory patch timeline for federal agencies, and a best-practice model for everyone else.

mttr metrics
Metrics

Mean Time to Remediate: The Metric Your CISO Asks For. And Why It's Not Enough

MTTR is easy to game and hard to act on. Here are five metrics that actually drive security outcomes.

supply chain cves
Supply Chain Threat Intel

Supply Chain CVEs: Log4Shell, XZ Utils, and the Vulnerabilities You Can't Scan For

Traditional scanners struggle with supply chain vulnerabilities. Here's why, and what to do about it.

CVSS vs EPSS vs TRIS
Vulnerability Scoring

CVSS vs EPSS vs TRIS: Which Vulnerability Scoring System Should You Trust?

CVSS measures severity. EPSS predicts exploitability. TRIS v2 combines 12 layers, including attack-path, supply-chain, defense efficacy, and FAIR-based financial impact, for the complete picture.

Red Teaming Tools
Red Teaming

Red Teaming Tools and Techniques: A Practitioner's Guide for 2026

From Cobalt Strike to BASzy AI. Manual red teaming vs automated BAS, why you need both.

Top VM Tools
Tools

Top 10 Vulnerability Management Tools Compared (2026)

Tenable, Qualys, Rapid7, Wiz, CrowdStrike and more, side-by-side with pricing and deployment.

CVEasy vs Tenable
Comparison

CVEasy AI vs Tenable: The Local-First Alternative

No per-asset pricing. No cloud dependency. TRIS v2 12-layer scoring vs the industry incumbent.

CVEasy vs Qualys
MSSP

CVEasy AI vs Qualys: Why MSSPs Are Moving to Local-First

Predictable pricing, data sovereignty, and built-in attack simulation for MSSPs.

On-Premise VM
Deployment

On-Premise Vulnerability Management: The Complete Guide

Air-gapped, local-first, zero cloud. The definitive guide for restricted environments.

per asset pricing trap
Pricing & Licensing

The Per-Asset Pricing Trap: Why Your Vulnerability Scanner Bill Keeps Growing

Per-asset pricing creates perverse incentives that make organizations less secure. Here's the math, and a better model.

compliance mapping
Compliance HIPAA · PCI · SOC 2

Mapping CVEs to Compliance Frameworks: HIPAA, PCI-DSS, and SOC 2

Turn vulnerability scan results into audit evidence. How to align your VM program with the controls that actually get tested.

executive reporting
Reporting

Executive Vulnerability Reporting: Explaining Security Risk to People Who Don't Speak CVE

A practical framework for translating scanner output into reports that drive decisions instead of confusion.

nessus to ers
Nessus Scan Analysis

From Nessus to TRIS score: Turning Raw Scan Output Into Prioritized Remediation

A Nessus XML export is a raw data dump. Here's how to cross-reference with EPSS/KEV and produce a ranked remediation queue.

air gapped security
Air-Gapped Architecture

Running Vulnerability Management in Air-Gapped Environments

Why SaaS VM tools fail in classified networks, and how to run a full VM program with zero internet connectivity.

vulnerability sla
SLA Program Building

Vulnerability SLAs That Actually Get Patches Done

A 7-tier SLA framework built on EPSS and KEV, not CVSS, with escalation paths that IT will actually follow.

threat intel feeds
Threat Intel OSINT

Threat Intelligence Feeds for VM: What to Track and What to Ignore

KEV, EPSS, NVD, MITRE ATT&CK, ISACs, what each feed tells you, what it doesn't, and how to avoid feed overload.

CVSS severity creates patch backlog
Vulnerability Scoring

Why CVSS Alone Is Creating Your Patch Backlog. And What to Do Instead

CVSS was designed to score severity in isolation. But "severity" without context creates noise, not signal. Here's how correlated intelligence changes everything.

No articles found matching your search.

Stay ahead of the next CVE

Weekly vulnerability intelligence, zero spam, pure signal. Join security professionals who get actionable insights delivered every Monday.