Index live· 1,284 files · 148 editions
ForensicPost

Search the index

11 results
Try
Results for “Vulnerabilities”Newest first
26-0817
File

Unisoc Modem Flaw Gives Android Kernel Access Through a Video Call, With No Fix

A video call reaches the Android kernel on three Unisoc chipsets, and the vendor has not replied.

VoLTE modem firmware to kernelTechnologyVulnerabilities
Sev 4TargetUnisoc-based Android devicesActorUnattributedNot established
26-0524
File

CVE Submissions Rose 263% Between 2020 and 2025

Four different things drive the 263%, and only one is bad news. The count measures workload, not software quality.

UnattributedVolume growthMultipleVulnerabilities
Sev 3TargetVulnerability disclosure ecosystemActorUnattributed
26-0506
File

The Disclosure-to-Exploitation Window Is Closing on the Patch Window

Exploitation is arriving before organisations can deploy. Patching in twenty days is worth less than surviving a compromised appliance.

MultipleRapid exploitationMultipleVulnerabilities
Sev 4TargetEnterprise patch managementActorMultiple
26-0412
File

NIST Moves Vulnerability Database to Triage, Enriching 15-20% of CVEs

Enrichment now covers 15–20% of incoming CVEs on published criteria. Sound criteria — and they are not your criteria.

UnattributedProcess changeMultipleVulnerabilities
Sev 4TargetVulnerability management pipelineActorUnattributed
26-0410
File

Only 97 of 1,596 Vulnerabilities Disclosed to Open-Source Maintainers Were Patched

1,596 disclosed, 97 patched. Discovery is now a capital expenditure; fixing is still one person in their own time.

Research consortiumDisclosure volumeCloudVulnerabilities
Sev 4TargetOpen-source maintainersActorResearch consortium
26-0405
File

Federal Audit Found National Vulnerability Database Backlog Past 27,000 Entries

27,000 entries with no analysis attached. Your scanner matches on metadata that, for these, does not exist.

UnattributedProcess capacityMultipleVulnerabilities
Sev 4TargetNational Vulnerability DatabaseActorUnattributed
26-0404
File

Autonomous Vulnerability Research Reported 10,000 Critical Findings in Open Source

Ten thousand critical findings in a month across operating systems, browsers and core libraries. Discovery funded at twenty-five times remediation.

Research consortiumAutonomous discoveryCloudVulnerabilities
Sev 4TargetOpen-source software estateActorResearch consortium
26-0329
File

Around 29,000 CVEs Reclassified as Never to Be Analysed

The backlog was reclassified, not cleared. Your dashboard will improve because 29,000 entries left the denominator.

UnattributedData classificationMultipleVulnerabilities
Sev 4TargetVulnerability toolingActorUnattributed
26-0328
File

27-year-old OpenBSD Flaw and 16-year-old FFmpeg Bug Found by Automated Research

“Battle-tested” is used as a security argument. A defect that survived 27 years of review in OpenBSD undercuts it.

Research consortiumAutonomous discoveryCloudVulnerabilities
Sev 4TargetLong-lived open-source codeActorResearch consortium
25-1216
File

Newly Disclosed Vulnerabilities Weaponised Within Hours Through 2025

The head start was the entire point of coordinated disclosure. At an interval measured in hours, publication is a starting gun heard equally by both sides.

MultipleVariousCloudAnalysis
Sev 4TargetEnterprise software estatesActorMultiple
24-1031
File

Sophos Published Five Years of Attacks on Its Own Firewalls and Its Use of an Implant

A private company placed monitoring code on machines it did not own, and published that it had.

China-based groups, per the vendorEdge-device vulnerabilitiesTechnologyInfrastructure
Sev 5TargetSophos perimeter devicesActorChina-based groups, per the vendorUnited Kingdom
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging