The Verizon 2026 DBIR shows vulnerability exploitation has overtaken credential abuse as the top initial access vector. Patching is now a capacity problem, not a discipline one.
Anthropic's Claude Mythos Preview found 10,000+ zero-days in a month. Only 97 are patched. The 90-day disclosure window just stopped making sense.
A three-day AI pipeline found 300+ WordPress plugin zero-days at $20 each. The disclosure infrastructure isn't ready, and attackers are already running the same playbook.
TeamPCP exfiltrated 3,800 GitHub internal repos through a poisoned Nx Console extension live for 18 minutes. The real story is how platform teams price developer tooling risk.
A highly critical Drupal Core flaw, CVE-2026-9082, lets anonymous attackers hit PostgreSQL-backed sites with SQL injection that can escalate to remote code execution.
A spoofing zero-day in Exchange OWA is being actively exploited, CISA has it on KEV, and Microsoft has no patch ETA. The boring bugs keep winning.
CVE-2026-44578 turns the Next.js WebSocket upgrade path into an attacker's proxy. Self-hosted apps are exposed, Vercel deployments are not. Patch now.