{"date_iso":"2026-09-05","date_human":"Saturday, September 5, 2026","generated_utc":"2026-09-05 15:55 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Microsoft Teams Desktop Client Fails to Load on Windows System \u2013 Microsoft Investigating","link":"https://cybersecuritynews.com/microsoft-teams-desktop-client-fails/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Dark Reading","SecurityWeek","The Hacker News","The Register Security"],"coverage":6,"cve_ids":[],"summary":"Microsoft is investigating an ongoing issue causing some Windows users to face significant delays or outright failures when launching the Microsoft Teams desktop client. The company acknowledged the problem, tracked\u2026","source":"Cyber Security News","date_rel":"6h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-Teams-Desktop-Client-Fails.webp","description":"Microsoft is investigating an ongoing issue causing some Windows users to face significant delays or outright failures when launching the Microsoft Teams desktop client. The company acknowledged the problem, tracked internally as TM1466820, and confirmed it remains unresolved as engineers continue digging through service logs to find a root cause. According to Microsoft\u2019s incident notice, affected users encounter trouble specifically during the first launch of Teams on a Windows device. Some cannot load the client at all, while others experience delays stretching up to two minutes before the\u2026","related":[{"title":"ASCII smuggling isn't just an AI security risk","link":"https://www.theregister.com/security/2026/09/04/ascii-smuggling-isnt-just-an-ai-security-risk/5294595","source":"The Register Security","date_rel":"20h ago"},{"title":"Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally","link":"https://cybersecuritynews.com/project-zenith-windows-pcs/","source":"Cyber Security News","date_rel":"23h ago"},{"title":"In Other News: Microsoft\u2019s Cloud Patches, Hacked Dropbox Accounts, Guardio\u2019s $1.1B Valuation","link":"https://www.securityweek.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/","source":"SecurityWeek","date_rel":"23h ago"},{"title":"Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters","link":"https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html","source":"The Hacker News","date_rel":"23h ago"},{"title":"Microsoft says some users can\u2019t open the Teams desktop client","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-says-some-users-cant-open-the-teams-desktop-client/","source":"Bleeping Computer","date_rel":"4 Sep"},{"title":"Microsoft: KB5120998 mouse reset bug affects only non-English PCs","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/","source":"Bleeping Computer","date_rel":"3 Sep"}]},{"title":"AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials","link":"https://cybersecuritynews.com/ai-agents-breach-company-network/","reason":"Teams","category":"News","sources":["Cyber Security News","CyberScoop","Dark Reading","Microsoft Security Blog"],"coverage":4,"cve_ids":[],"summary":"A human attacker armed with frontier artificial intelligence models breached an enterprise network and seized root credentials in under 10 hours, a timeline that would normally take human red teams roughly two weeks to\u2026","source":"Cyber Security News","date_rel":"8h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/AI-Agents-Breach-Company-Network.webp","description":"A human attacker armed with frontier artificial intelligence models breached an enterprise network and seized root credentials in under 10 hours, a timeline that would normally take human red teams roughly two weeks to complete, according to a new incident response report from Palo Alto Networks\u2019 Unit 42. The threat actor told Unit 42 investigators during ransom negotiations that they relied on frontier AI models paired with attack-specific agentic AI frameworks to automate the intrusion. Rather than manually executing each stage of the attack, the operator directed AI agents to monitor\u2026","related":[{"title":"Why judgment is emerging as cybersecurity\u2019s defining skill","link":"https://cyberscoop.com/ai-security-operations-human-context-ciso-op-ed/","source":"CyberScoop","date_rel":"4 Sep"},{"title":"Impersonating IT support: how threat actors turn a remote session into enterprise-wide access","link":"https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/","source":"Microsoft Security Blog","date_rel":"2 Sep"},{"title":"AI's Vulnerability Surge May Be More Manageable Than First Feared","link":"https://www.darkreading.com/application-security/ai-vulnerability-surge-manageable-than-first-feared","source":"Dark Reading","date_rel":"2 Sep"}]},{"title":"New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic","link":"https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html","reason":"Linux","category":"News","sources":["CCCS Alerts & Advisories","Rapid7 Blog","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to\u2026","source":"The Hacker News","date_rel":"4 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzLyhHupZwRy1pOQzT93Qhs5waZ8gqtlgDJUKgt1f37dz3KqIDDZY8uNo8QguZNccBHivdA_ecnY8cQUyhZQAvLH4APu3imxP-rwo2dYLZtKnJ92IkRPFmwepmJgRk9GrLrJiN_IbInwvNXaW7N5761YfEB1IIK4uDdNBTy6Koz8uXgOSXaQWixXM1Wts/s1600/HAProxy.jpg","description":"A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and","related":[{"title":"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors","link":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors","source":"Rapid7 Blog","date_rel":"4 Sep"},{"title":"SUSE Linux security advisory (AV26-882)","link":"https://cyber.gc.ca/en/alerts-advisories/suse-linux-security-advisory-av26-882","source":"CCCS Alerts & Advisories","date_rel":"3 Sep"}]},{"title":"Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC","link":"https://www.theregister.com/security/2026/09/03/prolific-microsoft-0-day-hunter-drops-crowdstrike-falcon-exploit-poc/5294318","reason":"Crowdstrike","category":"News","sources":["Bleeping Computer","CyberScoop","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On\u2026","source":"The Register Security","date_rel":"3 Sep","thumbnail":"https://image.theregister.com/?imageId=5294333&width=800","description":"The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike\u2019s Falcon endpoint security platform - albeit with a Windows link. According to the prolific zero-day hunter, FalconFlank is a privilege escalation vulnerability that abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. This is an automated security tool built into\u2026","related":[{"title":"New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges","link":"https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/","source":"Bleeping Computer","date_rel":"4 Sep"},{"title":"Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon","link":"https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html","source":"The Hacker News","date_rel":"3 Sep"},{"title":"Dogged Russia-based botnet dismantled after 23-year run","link":"https://cyberscoop.com/sality-botnet-dismantled/","source":"CyberScoop","date_rel":"2 Sep"}]},{"title":"Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs","link":"https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program\u2026","source":"The Hacker News","date_rel":"2 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu5sAuC-e7tUigtaAj0gicqzy_kWZTZRujpV3IxqGW1wr_VCuXbKXG7M-nNIac5QO2GY_KtEQ8HfnUENc6JZpS8haeGQIvOH4EddDvrQTJwXY2kkZcz41JbeT1_YhVuyrArJV4sUB3hrT9dFIazMbT-_8hLxg0jrQzHLPLv_h3bNb98puP5yVwgA1zoIsQ/s1600/aiai.jpg","description":"Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. \"The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them","related":[{"title":"Google security advisory (AV26-883) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-883","source":"CCCS Alerts & Advisories","date_rel":"22h ago"},{"title":"Outsider Phishing Kit Survives Takedown With 700 New Pages","link":"https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/","source":"Infosecurity Magazine","date_rel":"3 Sep"}]},{"title":"Hackers Use Popular Messaging Services to Control New Windows Backdoors","link":"https://cybersecuritynews.com/popular-messaging-services/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-50376"],"summary":"A financially motivated threat group known as Toy Ghouls has begun using two custom Windows backdoors that communicate through popular messaging and broker services. The tools give attackers a discreet way to run\u2026","source":"Cyber Security News","date_rel":"4 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Use-Popular-Messaging-Services-to-Control-New-Windows-Backdoors.webp","description":"A financially motivated threat group known as Toy Ghouls has begun using two custom Windows backdoors that communicate through popular messaging and broker services. The tools give attackers a discreet way to run commands, collect system details, and maintain control over compromised devices. The campaign marks a change for the group, which had previously relied heavily on public tools and leaked ransomware builders. Its move to custom malware suggests a broader effort to stay inside victim networks longer while making activity harder for security teams to spot. Analysts at Securelist\u2026","related":[{"title":"CVE-2026-50376 Windows Remote Desktop Client Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50376","source":"Microsoft Security","date_rel":"4 Sep"},{"title":"BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory","link":"https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html","source":"The Hacker News","date_rel":"3 Sep"}]},{"title":"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws","link":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html","reason":"Wordpress","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-14894","CVE-2026-32475"],"summary":"Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) \u2026","source":"The Hacker News","date_rel":"4 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9jQ8JSakEpnqxzsAZhwXnVvTMB0Lrbj7shOcXtSJzA30wcMTbkAIUGvSZPiBXOLeAW66Jpuysxn56W8YWD00hsCNB742oLqeyvgD8MXdIHHqwyeehyoyXx9G9c6XjxwN10Co_XVZuBkRjMquzgf9V17gh2Gw-xff0qJ9rh3sPO4tBq4OjjS0dxsl73WKT/s1600/wp-main.jpg","description":"Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms \u2013 Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including","related":[{"title":"Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites","link":"https://www.securityweek.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/","source":"SecurityWeek","date_rel":"2h ago"}]},{"title":"Cisco searched for IOS XR bugs and found so many it rolled them into an update release","link":"https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News","The Register Security"],"coverage":3,"cve_ids":["CVE-2026-20274"],"summary":"Cisco has warned its customers of three critical-rated flaws in its products. Two of them are present in the Cisco IOS XR operating system that powers the company\u2019s carrier-grade kit. CVE-2026-20274 scores 9.8 on the\u2026","source":"The Register Security","date_rel":"4 Sep","thumbnail":"https://image.theregister.com/?imageId=5294415&width=800","description":"Cisco has warned its customers of three critical-rated flaws in its products. Two of them are present in the Cisco IOS XR operating system that powers the company\u2019s carrier-grade kit. CVE-2026-20274 scores 9.8 on the ten-point CVSS scale and covers a buffet of buffering issues, the potential for out-of-bounds writes, and the chance to initialize resources with an insecure default. CVE-2026-20279 is another 9.8-rated flaw. Cisco says it\u2019s an improper access control problem that covers \u201cimproper certificate validation, missing authentication for critical function, missing authorization, and\u2026","related":[{"title":"Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root","link":"https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html","source":"The Hacker News","date_rel":"3 Sep"},{"title":"Cisco security advisory (AV26-876)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-876","source":"CCCS Alerts & Advisories","date_rel":"3 Sep"}]},{"title":"Critical Citrix NetScaler auth bypass now leveraged in attacks","link":"https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/","reason":"CVE-2026-19490","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories"],"coverage":2,"cve_ids":["CVE-2026-19489","CVE-2026-19490"],"summary":"Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.","source":"Bleeping Computer","date_rel":"4 Sep","thumbnail":"","description":"","related":[{"title":"AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489","link":"https://cyber.gc.ca/en/alerts-advisories/al26-019-vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-19490-cve-2026-19489","source":"CCCS Alerts & Advisories","date_rel":"20h ago"}]},{"title":"Your phone or computer may soon ask how old you are","link":"https://www.malwarebytes.com/blog/privacy/2026/09/your-phone-or-computer-may-soon-ask-how-old-you-are","reason":"Ios","category":"Threat Intel","sources":["Cisco Security Advisories","Malwarebytes Labs"],"coverage":2,"cve_ids":[],"summary":"First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be. California has passed a\u2026","source":"Malwarebytes Labs","date_rel":"3 Sep","thumbnail":"","description":"First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be. California has passed a law that requires a range of operating systems to start collecting your age when you first set them up. Under the state\u2019s Digital Age Assurance Act (DAAA), signed into law in October 2025, Windows, macOS, iOS, and Android will all have to do this from January 1, 2027. Operating systems set up before that date in California will need to do the same by July 1, 2027. Operating\u2026","related":[{"title":"Cisco IOS XR Software Security Hardening Release: September 2026","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XR%20Software%20Security%20Hardening%20Release:%20September%202026%26vs_k=1","source":"Cisco Security Advisories","date_rel":"20h ago"},{"title":"Cisco Advance Notification for Publication of September 2, 2026, Security Advisories","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-f2SiMFxl?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Advance%20Notification%20for%20Publication%20of%20September%202,%202026,%20Security%20Advisories%26vs_k=1","source":"Cisco Security Advisories","date_rel":"2 Sep"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-82923","vendor":"WordPress","product":"AI Website Builder (GitHub build)","severity":"CRITICAL","score":9.8,"description":"The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL \u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":0.0083,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82923"},{"id":"CVE-2026-85661","vendor":"Microsoft","product":"excel-mcp-server","severity":"CRITICAL","score":9.8,"description":"excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any fil\u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85661"},{"id":"CVE-2026-85663","vendor":"aimhubio","product":"aim","severity":"CRITICAL","score":9.8,"description":"Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85663"},{"id":"CVE-2026-85672","vendor":"getomni-ai","product":"zerox","severity":"CRITICAL","score":9.8,"description":"zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attacker\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85672"},{"id":"CVE-2026-85688","vendor":"TEN-framework","product":"ten-framework","severity":"CRITICAL","score":9.8,"description":"TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read \u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85688"},{"id":"CVE-2026-85696","vendor":"OpenTalker","product":"SadTalker","severity":"CRITICAL","score":9.8,"description":"SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85696"},{"id":"CVE-2026-18658","vendor":"IBM","product":"Operational Decision Manager","severity":"CRITICAL","score":9.8,"description":"IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to wr\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18658"},{"id":"CVE-2026-44402","vendor":"Voltronic Power","product":"SNMP Web Pro","severity":"CRITICAL","score":9.8,"description":"Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archiv\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-44402"},{"id":"CVE-2026-31020","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without in\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-31020"},{"id":"CVE-2026-75430","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75430"}],"vendor_spikes":[{"vendor":"Linux","count":147,"critical_count":0},{"vendor":"WordPress","count":65,"critical_count":4},{"vendor":"IBM","count":64,"critical_count":2},{"vendor":"Unknown","count":43,"critical_count":4},{"vendor":"undici","count":10,"critical_count":0},{"vendor":"YesWiki","count":10,"critical_count":1},{"vendor":"thorsten","count":8,"critical_count":0},{"vendor":"xmlsoft","count":8,"critical_count":0},{"vendor":"siyuan-note","count":7,"critical_count":0},{"vendor":"HashiCorp","count":7,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":18,"new_cve_count":563,"has_news_data":true,"has_cve_data":true}