Skip to main content

Vulnerability Management

Rows of computer servers in a brightly-lit data center or network operations center.

Microsoft Patches 138 Vulnerabilities, Including Critical DNS and Netlogon Flaws

Microsoft just patched a critical DNS flaw that could let hackers execute code on your network, along with 137 other vulnerabilities - so make sure to update ASAP! The update also includes a mandatory rollout of updated Secure Boot certificates to keep your system secure.

Analyst 207
Disarrayed computer network operations center with analysts at work amidst scattered papers and idle equipment.

Remediation Programs Often Fail to Validate Fixes

The alarming truth is that remediation programs often fall short, with a staggering mismatch between the speed of exploits and fixes - Mandiant's report reveals a mean time to exploit of just -7 days, while Verizon's data shows a median remediation time of 32 days.

Analyst 207
Global agency representatives meet to discuss AI supply chain risks, surrounded by laptops and documents.

Global Agencies Unveil AI Supply Chain Risk Guidance with SBOMs

Global agencies have joined forces to release groundbreaking guidance on AI supply chain risk, outlining minimum elements for Software Bill of Materials (SBOMs) to enhance security and transparency. This crucial step forward aims to tackle the complex challenges of measuring and defining AI risks across organizations.

Analyst 207
Software engineer working on laptop with code on screen in modern office with large window.

Microsoft Patch Tuesday Disrupts 120 Vulnerabilities with AI-Driven Insights

Microsoft's May Patch Tuesday update tackles a whopping 120 vulnerabilities, including 17 critical flaws that could leave your systems exposed to remote code execution, elevation of privilege, and information disclosure attacks. Prioritize patching now to safeguard your domain controllers and prevent potentially disastrous breaches.

Analyst 207
Generic server setup with multiple monitors and equipment racks in a brightly-lit tech environment.

Microsoft Patch Tuesday Exposes 137 Vulnerabilities, Including 30 Critical Flaws

Microsoft just dropped a massive Patch Tuesday update, fixing 137 vulnerabilities - including 30 critical flaws and 14 high-severity bugs scoring 9.0 or higher on the CVSS scale. This surge in patches, partly driven by AI-powered bug detection, is expected to continue, making it crucial to stay on top of updates.

Analyst 207
Rows of computer servers and networking equipment in a bright, clean server room setting.

Microsoft Patch Tuesday Discloses 137 Vulnerabilities, Warns of Critical Flaws

Microsoft's May Patch Tuesday update is a must-address, with 137 vulnerabilities patched, including 13 critical flaws that could leave your systems exposed. The good news? None are known to be under active attack - yet.

Analyst 207
Brightly-lit laboratory with rows of computer workstations and technical equipment.

AI-Powered Bug Hunts Disrupt Software Giants' Patch Cycles

Microsoft just dropped a massive batch of software updates to fix 118 security vulnerabilities, including 16 critical flaws that could let hackers take control of your system. For the first time in nearly two years, none of these patches are for emergency zero-day flaws that were already being exploited.

Analyst 207
Rows of computer servers in a brightly-lit data center with a subtly highlighted component indicating a potential…

Linux Vulnerability Exposes Widespread Risk of Local Privilege Escalation

A critical Linux vulnerability, dubbed copy.fail, poses a severe risk of local privilege escalation, allowing unprivileged processes to rapidly escalate to root access. This shocking flaw, considered one of the worst in years, can be exploited with alarming ease.

Analyst 207
Linux developer in dimly lit workspace looks concerned amidst computer screens and notes.

Linux Defenders Scramble to Outpace Exploit Cycle

Linux defenders are racing against the clock to outmaneuver exploiters, with one maintainer proposing a temporary "kill switch" to disable vulnerable kernel functions until a proper patch can be developed. This stopgap solution aims to buy crucial time between vulnerability discovery and patch release.

Analyst 207
Windows 10 laptop on a clean surface with open screen displaying a blurred image.

Microsoft Releases Urgent Windows 10 Update to Fix Security Flaws

Microsoft just dropped a critical Windows 10 update, KB5087544, to squash 120 security flaws and fix frustrating Remote Desktop issues - and it's a must-install to keep your system safe and running smoothly. This urgent patch also tackles Secure Boot state and certificate changes to give you added peace of mind.

Analyst 207
Rows of computer workstations and a large screen in a brightly-lit tech facility.

Microsoft Patch Tuesday Addresses 120 Vulnerabilities

Microsoft's May 2026 Patch Tuesday rollout is a doozy, tackling a whopping 120 vulnerabilities in one fell swoop - and thankfully, there are no zero-day threats to worry about this time around. This massive update means admins have their work cut out for them, but it's a big win for security.

Analyst 207
Windows 11 laptop on a desk showing a Windows Update screen with a progress bar and security symbols.

Microsoft Releases Mandatory Windows 11 Updates to Fix 120 Vulnerabilities

Microsoft just dropped some essential updates for Windows 11, tackling a whopping 120 vulnerabilities in one go! These mandatory patches, available as KB5089549 and KB5087420, are now live and ready to boost your system's security.

Analyst 207
European cybersecurity officials gather around a sleek computer workstation.

OpenAI Bolsters Europe's Cybersecurity With Model Access

OpenAI is ramping up Europe's cybersecurity game by granting restricted access to its cutting-edge vulnerability-finding model, GPT-5.5-Cyber, to dozens of European organizations through its new Trusted Access for Cyber program. This move will empower defenders to swiftly protect systems and respond to threats, while also addressing security concerns with greater transparency.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit mail server room.

Exim BDAT Flaw Exposes GnuTLS Builds to Code Execution Risk

A newly discovered vulnerability, dubbed Dead.Letter, threatens Exim builds that use GnuTLS, allowing attackers to exploit a use-after-free flaw in BDAT handling and potentially execute malicious code. This critical flaw can be triggered when a specific sequence of BDAT and TLS commands is sent, leading to heap corruption and a heightened risk of code execution.

Analyst 207
Secure facility with a computer terminal on a desk and blurred server racks in the background.

Fortinet Disrupts Critical RCE Flaws in FortiSandbox, FortiAuthenticator

Fortinet has patched a critical remote code execution vulnerability in its FortiAuthenticator and FortiSandbox products, which could have allowed unauthenticated attackers to run unauthorized code or commands. The company has released fixed builds to address the flaw, tracked as CVE-2026-44277, and urges users to update to versions 6.5.7, 6.6.9, or 8.0.3 to stay secure.

Analyst 207
Rows of computer servers and network equipment in a brightly-lit server room with neatly organized cables and wires.

AI Adoption Exposes New Vulnerabilities in APAC Cybersecurity

As AI systems increasingly become integral to business operations, they're also emerging as a major insider threat, with 7 in 10 APAC organisations now identifying AI as their top data security risk. This new breed of threat is forcing companies to rethink their cybersecurity strategies and take a closer look at the vulnerabilities AI can introduce.

Analyst 207
Developer workstation with laptop and coding tools in a clean room with natural daylight and abstract software diagram on…

OpenAI Launches Daybreak to Bolster Secure Software Development

OpenAI has launched Daybreak, an innovative initiative that helps developers build secure software from the ground up, accelerating cyber defenders and continuously securing software. By integrating cutting-edge models like GPT-5.5, Daybreak shifts security to the forefront of the software development lifecycle.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center setting.

SAP Patches Critical Flaws in Commerce Cloud and S/4HANA

SAP has patched a critical vulnerability in its Commerce Cloud and S/4HANA systems, warning that hackers could exploit the flaw to upload malicious code and take control of the application. This security gap, caused by a misconfigured Spring Security setup, put sensitive data and system integrity at risk.

Analyst 207
Researcher interacts with computer workstation surrounded by screens displaying code and vulnerability analysis in a…

OpenAI Unveils Daybreak to Automate Vulnerability Detection and Patching

Meet Daybreak, a game-changing cybersecurity tool from OpenAI that supercharges vulnerability detection and patching with cutting-edge AI, helping organizations stay one step ahead of attackers and making the world a safer place. By combining AI intelligence with advanced code analysis, Daybreak identifies and fixes vulnerabilities faster than ever before.

Analyst 207
Laptop screen displays Jenkins plugin interface with code environment, beside blurred smartphone and sticky notes.

TeamPCP Breaches Checkmarx Jenkins Plugin Again

If you're using the Checkmarx Jenkins AST plugin, make sure you're on a safe footing by using version 2.0.13-829.vc72453fa_1c16 or earlier, published on December 17, 2025, as newer versions may be vulnerable. Checkmarx has since released a patched version, 2.0.13-848.v76e89de8a_053, available on GitHub and the Jenkins Marketplace.

Analyst 207
Cluttered workstation with researcher in background looking at laptop.

Linux Distributions Scramble to Patch Dirty Frag Kernel Vulnerabilities

A critical vulnerability known as Dirty Frag has been discovered in the Linux kernel, allowing attackers with local access to gain root privileges across major distributions. Linux distributions are now racing against the clock to patch this chained local privilege escalation flaw.

Analyst 207
Security operations center with analysts at workstations and multiple screens displaying data, set against an urban backdrop.

Autonomous Teaming Closes Defenders' Speed Gap

The alarmingly rapid pace of cyber threats has left defenders scrambling to keep up, with the time from vulnerability disclosure to working exploit dwindling from 56 days in 2024 to a staggering 10 hours in 2026. Meanwhile, defenders are still stuck on human time, struggling to match the lightning-fast speed of attackers who now operate in seconds.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit data center.

cPanel Discloses Fixes for High-Severity Vulnerabilities

cPanel has patched three high-severity vulnerabilities, including a critical flaw that allows hackers to execute arbitrary Perl code, putting your online data at risk. The fixes address weaknesses that could be exploited to read sensitive files, disrupt service, or execute malicious code.

Analyst 207
Medical devices and equipment in a hospital setting with autonomous AI agent terminals in the foreground displaying…

Autonomous AI Agents Expose Hidden Vulnerabilities in Real-World Deployments

Researchers uncovered a shocking 91% of autonomous AI agent deployments are vulnerable to tool-chaining attacks, revealing a critical weakness in current governance approaches. This startling finding highlights the urgent need for updated security measures to protect AI systems in healthcare, finance, customer service, and software development.

Analyst 207