#patch management
112 stories taggedpatch management · page 7 of 8.

U.S. Government Gives Agencies Two Weeks to Patch Four Actively Exploited Flaws
Critical security holes in Adobe ColdFusion, Langflow, and Joomla extensions are already being used by attackers. Federal agencies have until July 10 to fix them.

BeyondTrust Rushes Fixes for Two Critical Flaws That Let Attackers Walk Into Remote Support Tools
The company's Remote Support and Privileged Remote Access products carry pre-authentication bugs rated 9.2 on the severity scale, meaning attackers need no password to break in.

A New Citrix NetScaler Flaw Is Already Being Exploited, And It Looks Familiar
A security hole in widely used Citrix network equipment is leaking corporate secrets from memory. Attackers moved within 24 hours of the patch dropping.

Five Eyes spy chiefs warn AI is shrinking the window to stop cyberattacks — and boards need to act now
The heads of five Western cybersecurity agencies say artificial intelligence is already changing how fast criminals can strike, and the warning is aimed squarely at company boards, not IT teams.

Three Quick Hits: Canadian Hacker Jailed, Open-Source Flaws Dropped, ATM Jackpotters Sentenced
A week's worth of security stories that deserve a second look, from an Anonymous-linked arrest in Canada to cash-machine criminals facing US prison time.

Adobe Is Doubling Its Patch Releases — Here's Why That Matters
Starting in July, Adobe will push security fixes twice a month instead of once. Faster vulnerability discovery, AI-assisted research, and a threat pace that monthly updates can no longer keep up with are all driving the change.

CISA: Attackers Are Actively Exploiting a Dangerous Flaw in Microsoft SharePoint
A vulnerability in SharePoint, Microsoft's widely used workplace collaboration platform, lets criminals run malicious code on company servers. Patches have been available since late May. Many organisations haven't applied them.

Cisco Phone System Flaw Now Being Actively Exploited — Patch Immediately
A security hole in Cisco's business phone software is being used in real attacks. Millions of offices run this software. The fix has existed since June.

Twenty Years of Getting It Wrong: The Breaches and Blunders That Defined Modern Cybersecurity
From MGM's identity disaster to MOVEit's patch pile-up, the same failure modes keep appearing in postmortems. That's the problem.

Citrix Ships Fixes for Six NetScaler Bugs, Including a File-Read Flaw Scoring 8.8
The patch batch covers NetScaler ADC and Gateway, with input-validation and DoS issues that admins should not sit on.

Oracle E-Business Suite Payments Bug Hits CVSS 9.8, Already Being Hit
CVE-2026-46817 lets unauthenticated attackers take over Oracle Payments. Exploitation is confirmed now.

The Patch Cycle Won't Survive Machine-Speed Adversaries
Defenders measured dwell time in days. Agentic attack pipelines are about to measure it in minutes.

Cisco Unified CM SSRF Flaw Hits Active Exploitation Three Weeks After Patch Drop
A file-write chain rooted in CVE-2026-20230 is now being probed in the wild. PoC was already public when Cisco shipped the fix.

Five Eyes to CSOs: AI Has Already Changed Your Threat Model — Act Now
A joint advisory from CISA and four allied agencies demands strategic action on AI-amplified threats. Experts say the advice is late, vague, and misses the real risk sitting inside your own network.

June Patch Tuesday Breaks OLE Automation, Leaves Word and Excel Silent on Failure
A Windows update shipped June 9 quietly severed the OLE bridge between Office apps and dozens of third-party tools. No error message. Just nothing.