A threat-hunting report puts the gap between a public proof-of-concept and active exploitation at about 48 hours. Here is what that does to patch scheduling, why severity scores are the wrong primary signal, and a few adjustments worth making.
Cisco compromised Claude Code’s persistent memory to deliver insecure guidance across projects, sessions, and reboots. What engineering teams should do.