Tag

Patch Management

All articles tagged with #patch management

OpenAI incident exposes patched Linux IPv6 flaw and urgent patch steps
security1 month ago

OpenAI incident exposes patched Linux IPv6 flaw and urgent patch steps

A patched Linux kernel vulnerability, CVE-2026-53362 (IPv6 Frag Gap), played a role in OpenAI’s Hugging Face incident, showing how a local foothold can escalate to root via an IPv6 UDP path; patches exist in recent kernels but many systems remain unpatched. Security guidance: apply vendor kernel updates, reboot to load the new kernel, prioritize patching for high-risk workloads, verify container-host boundaries, and consider temporary mitigations (e.g., disabling IPv6) if needed. Monitor for signs of compromise and expect more AI-enabled exploits as attackers leverage kernel bugs to gain control.

PaperCut Flaw Chain Enables Unauthenticated Remote Code Execution, Prompting Emergency Patch
security1 month ago

PaperCut Flaw Chain Enables Unauthenticated Remote Code Execution, Prompting Emergency Patch

Hackers chained two PaperCut NG/MF flaws—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe dynamic class loading)—to trigger unauthenticated remote code execution and alter server configuration; after an emergency patch with further hardening, exploitation appears limited but active, with attackers using Base64-encoded commands to identify the victim and a Java class to enumerate processes and files. Organizations should remove public exposure, apply the latest patches, and restrict access to trusted networks while monitoring logs for compromise indicators.

CISA imposes 3-day patch window for critical Oracle vulnerability
security1 month ago

CISA imposes 3-day patch window for critical Oracle vulnerability

CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog, giving federal agencies a three‑day deadline to patch a critical Oracle flaw in Oracle HTTP Server and WebLogic Proxy Plug‑in on Windows VMs that can grant full data access. Oracle released patches in January 2026 for affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0); private-sector researchers reported active exploitation attempts, underscoring the urgency of patching.

Active Windows zero-day drives urgent August patch Tuesday across core services
security1 month ago

Active Windows zero-day drives urgent August patch Tuesday across core services

Microsoft’s August Patch Tuesday closes 398 CVEs, including CVE-2026-68820—a use‑after‑free in afd.sys that can escalate from code execution to SYSTEM and is under active exploitation—making it the top priority; four other high‑severity flaws (CVE-2026-62878 in Windows DNS Server, CVE-2026-62893 in Windows Deployment Services, CVE-2026-62815 in Microsoft QUIC, and CVE-2026-59124 in HPC Pack) are unauthenticated RCEs whose exploitation depends on service exposure. The update also finishes a two‑part SharePoint chain (CVE-2026-55040 and CVE-2026-63520) first disclosed by Rapid7. Prioritize systems with exposed DNS/WDS/QUIC/HPC services and ensure on‑prem SharePoint farms apply both July and August fixes to close the chain.

Actively Exploited SharePoint Flaws Prompt Urgent Patch Alert
technology2 months ago

Actively Exploited SharePoint Flaws Prompt Urgent Patch Alert

CISA warns that three on‑premises SharePoint Server flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) are being actively exploited to bypass authentication and run remote code, with attackers targeting unpatched systems. Microsoft also patched CVE-2026-55040 and CVE-2026-58644. Shadowserver reports thousands of exposed SharePoint servers, prompting urgent patching, hardened logging, AMSI/Defender integration, and limiting internet exposure. Federal agencies have a July 17 deadline under BOD 26-04 to patch CVE-2026-56164. Since 2021, CISA has flagged 11 exploited Microsoft SharePoint vulnerabilities (7 linked to ransomware).

security2 months ago

CISA Warns of Active SharePoint Exploits, Urges Immediate Hardening

CISA warns of active exploitation of three on-premises SharePoint vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) that enable remote code execution and post-exploitation activity such as stealing IIS machine keys; two additional CVEs (CVE-2026-55040 and CVE-2026-58644) are also identified as potential risks if not patched. To mitigate, organizations should apply the latest Microsoft patches, verify installation completion, and shorten patching cycles where possible; ensure AMSI integration is enabled for all SharePoint web apps and follow Microsoft guidance for AMSI configuration. Use the provided AMSI and MDAV detections as part of incident response and hardening: hunt for intrusion artifacts before rotating IIS keys, implement enhanced logging and telemetry to detect anomalies, and limit internet exposure by placing SharePoint behind a Layer 7 proxy and restricting Central Administration access. Review Microsoft’s security guidance and report incidents to CISA as needed. These CVEs have been added to the Known Exploited Vulnerabilities (KEV) catalog.

CISA Tightens Patch Timelines for Federal Agencies, Pushing Critical Flaws to Three‑Day Fixes
technology4 months ago

CISA Tightens Patch Timelines for Federal Agencies, Pushing Critical Flaws to Three‑Day Fixes

The Cybersecurity and Infrastructure Security Agency issued Binding Operational Directive 26-04, requiring U.S. Federal Civilian Executive Branch agencies to remediate high‑risk vulnerabilities with accelerated timelines—down to three days for publicly exposed, known‑exploited flaws and up to two weeks for less urgent cases. The directive supersedes older BODs and mandates updates to vulnerability management policies, asset inventories, and automated KEV/CVE reporting, with full adherence within 180 days and policy changes within 60 days. It covers on‑premises, third‑party hosted, and cloud environments while excluding certain military, intelligence, and contractor systems, signaling a broader industry patch‑priority shift.

CISA orders patch for Windows zero-click flaw tied to NTLM hash leaks
technology5 months ago

CISA orders patch for Windows zero-click flaw tied to NTLM hash leaks

CISA has added CVE-2026-32202 to the Known Exploited Vulnerabilities list and ordered U.S. federal agencies to patch Windows endpoints and servers by May 12 under Binding Operational Directive (BOD) 22-01. The flaw is described as a zero-click NTLM hash-leak vulnerability that can be exploited in pass-the-hash attacks and may stem from an incomplete fix for CVE-2026-21510, which APT28-linked actors used in attacks against Ukraine and EU targets. Microsoft also flagged the vulnerability as exploited in the wild, and security teams are urged to apply vendor mitigations or discontinue the product if mitigations aren’t available. The alert comes as three other Windows flaws (BlueHammer, RedSun, UnDefend) are also being actively exploited to gain SYSTEM or higher privileges.

Mythos AI Triggers Cross-Sector Push to Guard Infrastructure
technology5 months ago

Mythos AI Triggers Cross-Sector Push to Guard Infrastructure

Anthropic’s Mythos AI, rolled out to a select group of firms, accelerates vulnerability detection and patching, raising alarms that rapid, cross‑sector coordination between governments and business is needed to defend critical infrastructure like hospitals, banks and utilities from new threats and potential autonomous attack agents while managing patch downtime.

Microsoft patches critical ASP.NET Core data-protection flaw to curb cookie forgery
security5 months ago

Microsoft patches critical ASP.NET Core data-protection flaw to curb cookie forgery

Microsoft released out-of-band security updates for a critical ASP.NET Core Data Protection vulnerability (CVE-2026-40372) that could let unauthenticated attackers forge authentication cookies and gain SYSTEM privileges. The flaw comes from a regression in the 10.0.0–10.0.6 NuGet packages, which could cause forged payloads to bypass authenticity checks; upgrading to 10.0.7 and redeploying with a rotated DataProtection key ring fixes the issue. This follows April’s Patch Tuesday and includes additional out-of-band Windows Server fixes. No service disruption is reported, but applications using DataProtection should update promptly to prevent token forgery and data exposure.

CISA Flags Exploited Windows Task Host Flaw Elevating Privileges
security5 months ago

CISA Flags Exploited Windows Task Host Flaw Elevating Privileges

CISA has labeled CVE-2025-60710 a actively exploited Windows Task Host privilege-escalation flaw, urging all organizations to patch within two weeks under Binding Operational Directive 22-01. The link-following vulnerability affects Windows 11 and Windows Server 2025 and can be exploited by users with basic permissions to gain SYSTEM-level control; Microsoft patched the issue in November 2025, but Microsoft’s advisory has not yet confirmed active exploitation, so defenders should apply vendor mitigations or discontinue the affected component per CISA guidance.

Feds told to patch BeyondTrust flaw within 3 days after active exploitation
technology7 months ago

Feds told to patch BeyondTrust flaw within 3 days after active exploitation

CISA ordered Federal civilian agencies to patch BeyondTrust Remote Support and Privileged Remote Access within three days after CVE-2026-1731, a remote code execution flaw that’s been actively exploited. SaaS instances were patched by BeyondTrust on Feb 2, 2026, but on-premise deployments require manual updates. Exploitation can allow unauthenticated remote code execution, risking system compromise, data exfiltration, and service disruption. Threat intel reports active exploitation and about 11,000 exposed instances (roughly 8,500 on‑premises). The agency added the CVE to its Known Exploited Vulnerabilities catalog and urged mitigations or discontinuation per vendor guidance under BOD 22-01.

CISA orders urgent patch for actively exploited SCCM flaw
security7 months ago

CISA orders urgent patch for actively exploited SCCM flaw

CISA directed federal agencies to patch CVE-2024-43468, a SQL injection flaw in Microsoft Configuration Manager (SCCM) that is now being actively exploited in attacks. The vulnerability was patched by Microsoft in October 2024, but exploitation was later shown in PoC code, and CISA warns that unpatched systems pose significant risk. Agencies must apply mitigations by March 5 under BOD 22-01, and CISA recommends that organizations outside federal use vendor guidance to secure affected systems as soon as possible.

Critical pre-auth RCE in BeyondTrust remote-support tools prompts urgent patch
technology8 months ago

Critical pre-auth RCE in BeyondTrust remote-support tools prompts urgent patch

BeyondTrust warns of CVE-2026-1731, a pre-auth remote code execution flaw in Remote Support (RS) 25.3.1 and Privileged Remote Access (PRA) 24.3.4 and earlier, allowing unauthenticated attackers to run OS commands; patches are available by upgrading to RS 25.3.2+ and PRA 25.1.1+ (or enabling automatic updates). Cloud systems have been secured; about 11,000 instances are exposed online, with roughly 8,500 on-premises potentially vulnerable if not patched; no active exploitation is reported yet.

Ivanti EPMM hit by two critical zero-days, with patches and risk guidance issued
security8 months ago

Ivanti EPMM hit by two critical zero-days, with patches and risk guidance issued

Ivanti disclosed two critical RCE zero-day flaws in Endpoint Manager Mobile (CVE-2026-1281 and CVE-2026-1340) exploited in the wild at a limited number of customers. Both flaws score 9.8 and can run arbitrary code remotely without authentication. Ivanti released RPM-based mitigations for affected EPMM versions, noting no downtime is required but hotfixes must be reapplied after any version upgrade; a permanent fix arrives with EPMM 12.8.0.0 in Q1 2026. Exploitation can reveal administrator and user data, device details, and location (if enabled), and attackers could alter configurations via the API or web console. Defenders can detect activity via a specific Apache access-log regex, though logs can be altered by attackers. Recovery guidance includes restoring from a known-good backup or rebuilding, resetting local and service accounts' passwords, rotating certificates, and reviewing Sentry logs. CISA has added CVE-2026-1281 to KEV; federal agencies must patch or decommission affected systems by Feb 1, 2026.