security bulletin

May 7, 2026

THE GLASWING ERA: AI-POWERED VULNERABILITY DISCOVERY AND WHAT IT MEANS FOR CYBER UNDERWRITING

Anthropic’s Mythos Preview and Project Glasswing have redrawn the cyber threat landscape. This brief explains what changed, what it means for risk selection and pricing, and […]
December 10, 2025

Critical Unauthenticated RCE in React Server Components (React2Shell, CVE-2025-55182)

Executive summary CVE-2025-55182 (“React2Shell”) is a CVSS 10.0 unauthenticated remote code execution vulnerability in React Server Components (RSC) that enables arbitrary code execution on affected servers […]
July 22, 2025

Critical SharePoint Vulnerability (CVE-2025-53770)

We are issuing an urgent alert regarding a critical and actively exploited vulnerability, identified as CVE-2025-53770, affecting on-premises Microsoft SharePoint Servers. Download Bulletin Why This Matters […]