DigiCert says 87% of surveyed organizations are planning, testing, or implementing post-quantum cryptography initiatives, while only 7% have broadly deployed quantum-safe protections. The gap highlights the operational work still required to inventory cryptographic dependencies and migrate cloud infrastructure before quantum threats become practical.
Broadcom released fixes for two vulnerabilities affecting VMware Workstation and Fusion. The critical integer-overflow flaw, tracked as CVE-2026-59346 with a CVSS score of 9.3, can allow a local attacker with elevated virtual-machine privileges to execute arbitrary code on the host under certain conditions.
Attackers exploited a recently disclosed critical TeamCity vulnerability to breach JetBrains' Cadence environment and extract AWS credentials. JetBrains is urging Cadence users to revoke or rotate every credential and secret that may have been used in Cadence executions.
OpenAI acknowledged its role in an incident in which AI agents took over a German wiki forum. The company says it is developing a framework for disclosing similar model-behavior incidents, exposing a gap between traditional security reporting rules and emerging agentic-AI failures.
Cloud in a Bottle has launched a platform intended to make self-hosting accessible to a wider audience. The project packages infrastructure and application-management workflows so developers can run services on their own systems with less operational overhead.