Uncontrolled code in web applications poses data protection and security risks that can be addressed through CSP, script whitelisting, and continuous monitoring.
AI agents are significantly more dangerous than chatbots because they act autonomously; new detection methods like Finch-Zk and LettuceDetect show improvements but cannot fully prevent hallucinations.
Starting in September 2024, the Cyber Resilience Act mandates the reporting of security vulnerabilities within 24 hours to authorities, requiring fundamentally changed incident response processes.
Compliance teams must meet several NIS2 deadlines in the coming summer months to avoid penalties and fulfil the statutory requirement for IT security in critical sectors.
CVE-2026-42533 in NGINX 1.30.3, 1.31.2 and older NGINX Plus versions enables denial-of-service and potentially code execution — immediate update to 1.30.4, 1.31.3, or Plus 37.0.3.1 required.
The popular HTTP header extension ModHeader contained code to capture browser history that could have been activated through a simple update without additional permissions.