Security News

Curated cybersecurity news and emerging threats relevant to startups, SMBs, and growing teams.

Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.

Each item includes our perspective on why it matters to your security posture.

Cloudflare Turns a Security-Review Skill Into an Autonomous Agent Pipeline

Tools Vulnerability Threat Intelligence

Cloudflare evolved a single code-review skill into a two-stage multi-agent pipeline that found and triaged over 20,000 findings across 100+ repos.

Why it matters: If you're scaling AI-assisted code review, Cloudflare's split between a discovery pipeline and a separate validation/fix pipeline (using a different model to check findings) is worth copying — it's what keeps signal-to-noise manageable as scope grows past a handful of repos.
Read source →

AWS IAM Identity Center Updates Session Duration Limits

AWS Identity & Access

AWS now enforces stricter session duration controls for IAM Identity Center, reducing default session timeout from 12 hours to 8 hours.

Why it matters: If your team uses IAM Identity Center for federated access, review your session timeout policies. Shorter sessions improve security posture but may impact developer workflows. This is an opportunity to consolidate your identity baseline.
Read source →

Critical Kubernetes Vulnerability CVE-2026-28394 Disclosed

Kubernetes Vulnerability

A privilege escalation vulnerability in Kubernetes allows authenticated users to escalate to cluster admin. Patches available for v1.28+ immediately.

Why it matters: If you run self-managed Kubernetes clusters, this is a priority patch. Cloud-managed services (EKS, GKE, AKS) are patched automatically. Verify your cluster version and update within 48 hours if you're managing the control plane yourself.
Read source →

EU NIS2 Directive: Incident Reporting Deadline Extended

Compliance EU Regulation

The European Commission extends the critical incident reporting window from 24 to 72 hours for operators across finance, healthcare, energy, and digital services.

Why it matters: This affects any team serving EU customers or operating in the EU. The extended window gives more time to investigate, but your logging and detection infrastructure must be ready to correlate events across all systems within hours. Audit your incident response timelines now.
Read source →