#patch now
9 stories taggedpatch now.

Cisco's Network Gatekeeper Has a Perfect-10 Flaw and Hackers Are Already Inside
A zero-day in Cisco Identity Services Engine lets anyone on the internet walk past the login screen entirely. Federal agencies have three days to patch. There is no workaround.

Hackers Are Taking Over MikroTik Routers Through a Chained Attack Called MikroTrick
Two critical flaws in MikroTik's RouterOS software are being actively exploited together to seize full control of internet-facing routers. More than 120,000 devices are exposed. Patches are available now.

Working Exploit Published for Cleo Harmony Flaw That Ransomware Gangs Already Love
A newly discovered flaw in the Cleo Harmony file-transfer application lets attackers break in and take control without a password. A working exploit is already public, and Cl0p used a different Cleo bug to hit major organisations just months ago.

Hackers Are Actively Exploiting a Critical Flaw in the AI Builder Langflow
A software vulnerability scored at near-maximum severity is being used right now to break into Langflow servers and steal credentials. Over 360 attacks hit tracking sensors in the UK in a single day.

A Hidden Linux Flaw Lets Any Local User Seize Full Control of a Machine
A race condition buried in the Linux XFS filesystem since 2017 can hand a regular user complete administrative control. Patches are out. Reboots are required.

A Hidden Door in RabbitMQ Left Company Systems Wide Open for Two Years
A flaw in the popular messaging software handed anyone on the network a master key to company data. Patches are out. Use them now.

Apple Pushes Emergency Fixes for Two Flaws Already Being Used to Attack iPhones and Macs
Two previously unknown security holes, one in the heart of Apple's operating system and one in its browser engine, are being actively exploited. Every iPhone, iPad, and Mac owner should update today.

CISA Orders Federal Agencies to Patch Palo Alto Firewall Flaw Being Exploited Now
A misconfigured URL filtering setting in Palo Alto Networks firewall software is letting attackers weaponise the firewalls themselves, turning them into unwitting cannons pointed at other targets.

CitrixBleed Redux: PoC Drop Triggers Immediate NetScaler Memory-Scrape Campaign
Attackers wasted no time after proof-of-concept code surfaced for a new Citrix NetScaler memory-disclosure bug. The gap between publish and exploit measured in hours, not days.