Latest Cybersecurity News and IT Security Insights
Stay informed about emerging threats, practical protection strategies and innovations in vulnerability management. Benefit from the expertise of the Greenbone specialists and strengthen your IT security.
Subscribe to the Newsletter Now



CRA Implementation at Greenbone: How We Made the Reporting Obligation Operational
BlogWe already explained what requirements the Cyber Resilience Act imposes as of September 11, 2026, in a separate post on the implementation status of the CRA reporting obligation. This post answers the other half of the question: how the implementation was carried out at Greenbone itself. One clarification up front, because it is decisive for […]
CVE-2026-64849: SSRF Flaw in MLflow Actively Exploited
BlogCVE-2026-64849 (CVSS 9.3, EPSS ≥ 95th pctl) is a critical-severity unauthenticated full-read server-side request forgery (SSRF) flaw [CWE-918] in MLflow webhook delivery. The CVE affects all versions prior to 3.15.0. The root cause is flawed redirect handling and DNS rebinding. The flaw is exploited by bypassing the _validate_webhook_url protections in the default MLflow Tracking Server […]
The Cyber Resilience Act at Two Weeks: What’s Actually Ready, and What Isn’t
BlogTwo weeks before Article 14 reporting becomes mandatory, the infrastructure behind it is still under construction. The Commission’s guidance is approved but not yet formally in force. The reporting platform is in testing, not live. Not one harmonised standard has a citation in the Official Journal. Each of those gaps puts more weight on the […]