ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

A TantoSec proof-of-concept chains an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution, but only against apps in a specific non-default configuration. Progress patched the chain in July. No confirmed in-the-wild exploitation exists.
Tap to vote and see what everyone thinks.
Summary by ByteBrief