
Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlog
Microsoft’s latest Patch Tuesday addresses 63 vulnerabilities, including two that are actively exploited, enhancing security for users and systems.

Learn how exposed ASP.NET keys can be exploited to deploy malware, compromising security and integrity in web applications.

Apple addresses a complex zero-day vulnerability, enhancing security and protecting users from potential threats in its software ecosystem.

Apple has released an emergency update to address the actively exploited iOS zero-day vulnerability CVE-2025-24200, enhancing device security.

Discover the latest Progress Software update addressing critical LoadMaster vulnerabilities, enhancing security and performance for users.

Explore NIST SP 800-39, a vital guide for effective information security risk management, providing frameworks and strategies for organizations.

Google Mandiant uncovers a critical MSI vulnerability in Lakeside Software, highlighting security risks and the need for immediate patching.

We are aware that some of the links to the source articles are not accurate and apologize for the inconvenience. We are working to resolve the issue and expect it…

Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlog
XE Hacker Group exploits VeraCore zero-day vulnerabilities to deploy persistent web shells, enhancing their control over compromised systems.

Zimbra releases critical security patches addressing SQL injection, stored XSS, and SSRF vulnerabilities to enhance user data protection.

CISA adds a new known exploited vulnerability to its catalog, highlighting the importance of cybersecurity awareness and proactive defense measures.

Orthanc Server is an open-source DICOM server for medical imaging, enabling efficient storage, retrieval, and sharing of medical data.

Discover how malicious ML models exploit flawed Pickle formats on Hugging Face, enabling them to bypass detection and pose security risks.

Microsoft kicks off 2025 with 161 security updates, enhancing protection and addressing vulnerabilities to ensure user safety and system integrity.

UK Cyber Monitoring Centre introduces ‘Richter Scale’ to evaluate cyber-attacks, enhancing response strategies and national cybersecurity resilience.

Critical vulnerability in WordPress ASE Plugin exposes websites to security risks, urging immediate updates to protect against potential attacks.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Cisco has released updates to address critical ISE vulnerabilities that could allow root command execution and privilege escalation, enhancing security.

Explore key trends shaping the future of Privileged Access Management (PAM) in cybersecurity leadership by 2025, enhancing security and governance.

Hackers exploit SimpleHelp RMM vulnerabilities to gain persistent access, leading to increased ransomware attacks and security risks for businesses.

Microsoft uncovers 3,000 exposed ASP.NET keys, highlighting vulnerabilities to code injection attacks and urging developers to enhance security measures.

CISA warns of ongoing exploitation of a Trimble Cityworks vulnerability leading to IIS remote code execution. Stay informed and secure your systems.

Veeam vulnerability allows arbitrary code execution via a man-in-the-middle attack, posing significant security risks for affected systems.

Discover essential trends in vulnerability management to future-proof your IT strategy and safeguard against evolving cyber threats.

CISA alerts on four critical vulnerabilities in the KEV Catalog, urging organizations to implement fixes by February 25 to enhance cybersecurity.