Featured Posts
All Posts

EOL Software
Aug 28, 2026
Running Node.js 20 on AWS: What Deprecation Actually Means and What Your Options Are
Navigating AWS Deprecation Policies and Securing Legacy Runtimes Beyond EOL
Javier Perez

Security
Aug 28, 2026
Apache Log4j Versions, EOL Dates, and Latest Releases (August 2026)
A complete reference for every Log4j release line, the Log4Shell retrospective, and the seven CVEs disclosed since December 2025 that stop at Log4j 2.25.x.
Greg Allen

Compliance
Aug 28, 2026
Does Running EOL Software Violate PCI DSS, HIPAA, or SOC 2?
EOL software is not an automatic violation, but it lands on the wrong side of the controls these frameworks enforce.
Rob Nalen

Compliance
Aug 27, 2026
Six Reasons Why Low-Severity CVEs Become High Risk
AI-driven vulnerability landscape rewrites triage math, especially for end-of-life (EOL) software.
Javier Perez

Security
Aug 27, 2026
91 Spring CVEs in a Single Day: Inside the August 2026 Batch
Understanding the shift in Spring project security disclosures and what this record-breaking batch means for your Java dependency tree.
Mark Szymanski

Security
Aug 26, 2026
Apache Tomcat 9.0.121 Fixes 11 CVEs, 8 Affect EOL Tomcat 8.5
How the August 2026 Tomcat security release leaves eight unpatched vulnerabilities, four rated Important, on end-of-life Tomcat 8.5.
Greg Allen

Security
Aug 26, 2026
AryStinger Explained: How Decade-Old Router Bugs Became 2026 Attack Infrastructure
First seen in March 2026, AryStinger turns unpatched, end-of-life routers and NAS devices into a covert reconnaissance network.
Greg Allen
.webp)
Security
Aug 25, 2026
CVE-2026-59270: Spring Security Embedded LDAP Admin DN Exposure
How an embedded UnboundID test server binds to every network interface with a well-known admin credential, letting anyone who can reach the port read or rewrite the directory.
Greg Allen

Compliance
Aug 24, 2026
Cyber Insurance and End-of-Life Software: What's Excluded in 2026
Navigating the Shift from Record-Keeping to Underwriting: How EOL Software Impacts Your Policy Coverage in 2026SEO Meta Description
Greg Allen

Security
Aug 21, 2026
CVE-2026-27601 & CVE-2021-23358: Underscore.js DoS and Template Code Injection
How two unguarded inputs to Underscore.js internals, an unbounded recursion depth, and an unvalidated template variable name, let remote data crash a Node.js process or run attacker-chosen code.
Ryan Jasinski
.png)
Security
Aug 21, 2026
CVE-2026-56848: Node.js HTTP/2 RST_STREAM Heap Use-After-Free
How a stream reset submitted inside an active nghttp2 receive callback re-enters the send path and frees the session state the receive loop is still reading, crashing the server process.
Ryan Jasinski

Security
Aug 21, 2026
The Real Risks of Running Unsupported Open Source Software
Three concrete exposures come with unsupported open source: unpatchable CVEs, compliance findings, and operational drag.
Maria Spano

Security
Aug 18, 2026
CVE-2026-58043: Node.js Permission Model Filesystem Allowlist Bypass
How a radix tree split node in the Node.js Permission Model grants read and write access to files that were never on the allowlist
Ryan Jasinski

Security
Aug 17, 2026
CVE-2026-73635 & CVE-2026-73633: Apache Struts Unauthenticated Denial of Service
How two unbounded memory reads in Struts, one in the core localized-text cache and one in the JSON plugin, let an unauthenticated client exhaust the Java heap and take the server down.
Greg Allen

EOL Software
Aug 17, 2026
NumPy 2.1 Reaches End of Life on August 19, 2026
The 2.1 branch leaves NumPy’s support window on August 19. If your project is pinned to Python 3.10, the only supported NumPy left to you expires four months later.
Hayden Barnes
.png)
.png)
.png)