SevenTnewS

Vulnerabilities & CVEs

Zero-day flaws, CVEs, patches and security advisories.

4 published articles

3 min read

Known Exploited Vulnerabilities

Active exploits push Progress LoadMaster flaw onto CISA's must-patch list

CISA's KEV catalog now includes CVE-2026-8037, an actively exploited command injection flaw in Progress LoadMaster. Under BOD 26-04, the entry turns a one-line advisory into a federal patch priority, and CISA urges every organization to treat the list the same way.

2026-08-10

3 min read

CISA KEV

Cisco flaw on CISA's KEV list: patching is not enough anymore

CISA adds a Cisco firewall password flaw to its KEV catalog. Under BOD 26-04, federal agencies must now investigate for pre-patch exploitation, not just apply the patch. The same expectation applies to recent Check Point and Microsoft SharePoint vulnerabilities.

2026-08-02

3 min read

Side-Channel Attack Steals Cloud AI Models

Model Stealing Attacks on Cloud-Based AI: A New Zero-Query Trojan Method Emerges

A new zero-query attack method called 'Zero-Query Model Stealing' allows adversaries to steal proprietary AI models from cloud APIs without sending any queries, using side-channel information from timing and memory patterns. This raises serious cybersecurity concerns for AI-as-a-service providers.

2026-07-27

2 min read

Data privacy

Grok Build was uploading entire codebases to the cloud. Musk says the data is safe now.

SpaceXAI's Grok Build CLI was uploading entire codebases to cloud storage. Elon Musk says all previously uploaded data will be deleted, but the incident exposes just how much AI coding tools can quietly collect.

2026-07-17