Intelligence / Cybersecurity
Cybersecurity Intelligence
Live cybersecurity intelligence from CISA, NIST, NVD, SEC EDGAR, BLS, and other authoritative sources. DecipherU is a cybersecurity career platform; every item here connects to career implications for security professionals.
CVE-2026-1255, The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Expos...
Read moreCVE-2026-85658, The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User ...
Read moreCVE-2026-4327, The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution i...
Read moreCVE-2026-15664, The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for ...
Read moreCVE-2026-92807, The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitra...
Read moreCVE-2026-87909, The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execut...
Read moreCVE-2026-13354, The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stor...
Read moreCVE-2026-93923, SiYuan through 3.8.4 fails to escape heading style attributes when rendering out...
Read moreCVE-2026-93922, SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker...
Read moreFriday Squid Blogging: On Squid Egg Sacs
Read moreCVE-2026-84034, IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulne...
Read moreCVE-2026-82896, IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to...
Read moreCVE-2026-82893, IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated ...
Read moreCVE-2026-82892, IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit...
Read moreCVE-2026-82887, IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to...
Read moreCVE-2026-82885, IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to...
Read moreCVE-2026-81937, IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerabi...
Read moreCVE-2026-81933, IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability...
Read moreCVE-2026-81669, IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerabi...
Read moreCVE-2026-81656, IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability...
Read moreCVE-2026-81626, IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability...
Read moreCVE-2026-17619, IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send sp...
Read moreCVE-2026-11727, IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remo...
Read moreCVE-2026-11726, IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac...
Read moreCVE-2026-11725, IBM MQ could allow an authenticated attacker to cause a denial of service or pot...
Read moreCVE-2026-11716, IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac...
Read moreCVE-2017-20284, Caucho Resin contains a path traversal vulnerability in the documentation webapp...
Read moreCVE-2021-48008, Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows ...
Read moreCVE-2019-25776, Weaver E-cology contains an unauthenticated SQL injection vulnerability that all...
Read moreCVE-2026-93749, source-map-js through 1.2.1 fails to validate the per-section offset line value ...
Read moreCVE-2026-93559, A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0...
Read moreCVE-2026-91149, A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this...
Read moreCVE-2026-93690, uri-js through 4.4.1 contains a denial of service vulnerability in the removeDot...
Read moreCVE-2026-93688, SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV tra...
Read moreCVE-2026-81942, PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bef...
Read moreWhere the field is heading
AI is compressing entry-level SOC Tier-1 work (alert triage, routine log review) faster than it's creating junior roles to replace it: SANS' 2026 workforce survey found 52% of security professionals expect AI to reduce entry-level demand specifically. The roles growing instead sit on top of that compression: adversarial testing of the AI systems doing the compressing, and governing how they get deployed.
AI Red Teamer career guide →NIS2, DORA, and the EU AI Act have created what European recruiters describe as a sustained compliance-hiring wave, not a spike, because none of the three are optional and all three require role-specific, documented, auditable training. Each EU member state transposes NIS2 into its own national law on its own timeline, so tracking which version applies where is now a real part of the job.
NIS2 transposition tracker →"AI security" is splitting into distinct disciplines rather than staying a sub-skill inside general security work: adversarial testing, model governance, and third-party AI risk are becoming separate hiring lines with their own job titles.
NIS2 & DORA Compliance Manager career guide →