#patch management
114 stories taggedpatch management · page 3 of 8.

Researcher Drops 'HardBreacher' Exploit for Kaspersky Security Software
A bug-hunter who has repeatedly embarrassed Microsoft now has Kaspersky in the crosshairs, releasing a proof-of-concept exploit that can hand an attacker near-total control of a Windows machine running Kaspersky Endpoint Security.

Hackers Are Actively Exploiting a Near-Perfect-Score Flaw in Ruby on Rails
A critical vulnerability in the popular web framework lets criminals read files off a server and run their own code on it, and the official patch only closes half the door.

Microsoft: Ignore the 'Antivirus Is Off' Warnings in Defender, It's a False Alarm
A bad notification, not a broken product. Microsoft says Defender is running normally despite pop-ups claiming otherwise, and a fix is on the way.

PaperCut Rushes Out Second Fix as Attackers Chain Bugs to Run Code
A newly patched flaw in the widely used print management software is being actively exploited, and PaperCut has shipped emergency hardening on top of the original patch.

ServiceNow patches three top-severity flaws in its AI platform
Three of the four bugs score a maximum 10.0 on the industry severity scale, and one can be triggered by an attacker who has not logged in.

CISA Flags Six Actively Exploited Bugs, Including a Citrix NetScaler Flaw
The U.S. cyber agency ordered federal agencies to patch fast, after evidence hackers are already breaking into Citrix, Linux and Microsoft SQL Server systems.

CISA: Hackers Are Actively Exploiting a Patched Gitea Flaw That Lets Them Run Malicious Commands
A security hole in Gitea, a widely used code-hosting platform, is being exploited in the wild. A patch has existed since late July, but federal agencies have until August 28 to apply it.

AI Finds the Bugs in Hours. Fixing Them Still Takes Months.
Artificial intelligence is now fast enough to discover serious security flaws in widely used software within hours. The human systems needed to patch those flaws haven't come close to keeping pace, and the gap is growing.

Nucleus Security says its new tools can spot a vulnerability before your scanner even knows it exists
A new early-warning feature aims to cut the days-long gap between a software flaw going public and security teams being able to scan for it.

Vulnerability management is drowning, and AI is being sold as the lifeboat
Security teams face more software flaws than they can patch, and vendors are pitching frontier AI as the fix. Lucy Green looks at what that actually means for the people running these programmes.

Silent Software Patches Protect Hackers, Not Users
When companies fix security flaws without telling anyone, the people paid to defend your data are flying blind. A new Broadcom programme for its Spring software framework shows exactly how that plays out.

91 Security Flaws Fixed in Spring, the Java Framework Powering Hundreds of Thousands of Apps
One critical flaw lets attackers silently alter user records. Over 200 vulnerabilities have already been patched in Spring this year, a sharp rise tied to Broadcom's push into AI.

Ransomware crews jump on a Windows Task Host bug that hands over full control of the PC
CISA says criminals are now using CVE-2025-60710, a Windows privilege escalation flaw Microsoft patched in November, to seize SYSTEM-level access on unpatched Windows 11 and Server 2025 machines.

Critical GitLab Flaw Lets Attackers Wipe Public Projects Without Logging In
GitLab has patched a flaw rated 9.4 out of 10 that let unauthenticated attackers alter or delete public projects and user data through the platform's GraphQL interface.

Oracle Releases Free Database Security Tool Amid Growing Pressure From AI-Powered Bug Hunters
Oracle Database Security Central gives organisations a single place to spot risky database settings and unusual access patterns. It's free until February 2027, though the window that prompted its creation is already closing.