#vulnerability management
86 stories taggedvulnerability management.

CISA Gives Federal Agencies Three Days to Patch a WSO2 Flaw Already Being Exploited
Two critical bugs are being actively exploited. Federal civilian agencies must fix the WSO2 vulnerability by September 27, and the same urgency applies to any organisation running the affected software.

CISA tells federal agencies: patch three Linux kernel bugs within days, attackers already using them
Three Linux kernel flaws are being exploited in the wild. Federal agencies have until 21 September to patch, and the most serious carries a 9.8 severity score.

Autonomous AI Pentesters Arrive as the Patch Gap Widens
Attackers now exploit new flaws in about five days. The average company still takes six weeks to patch. Vendors say AI agents can close the gap. Regulators are starting to notice.

CISA Is Scrapping Its Weekly Vulnerability Bulletin
The agency is retiring its regular digest of known security flaws in favour of a new directive that tells federal agencies to patch based on real-world danger, not scores on a chart.

CISA Orders Federal Agencies to Patch Two Linux Kernel Flaws
The KEV catalog additions are the first Linux kernel entries to test Binding Operational Directive 26-04's risk-based patching regime.

Microsoft's Biggest-Ever Security Update Fixes 974 Flaws, Two Already Used in Attacks
A record-breaking September patch release plugs two security holes that criminals were actively exploiting, plus 20 vulnerabilities serious enough that a single infected machine could spread the attack to others automatically.

The Race to Answer 'Are We Exposed?' Is Getting Harder
A new CVE drops and the clock starts. Security teams still hop between six tools to find out if it matters. AI is making that lag more dangerous.

Your Scariest Vulnerabilities Might Not Be the Ones That Get You Hacked
Scanner reports full of 'critical' flags are drowning security teams. The real question is which of those flags actually give an attacker a path in.

AI Is Finding Vulnerabilities Faster Than Security Teams Can Fix Them
At CrowdStrike's Fal.Con 2026 conference, the real alarm wasn't about AI-powered attacks. It was about what happens when defenders are already drowning in warnings and attackers start moving faster.

Patch automation needs a brake pedal, not just an accelerator
Faster patching cuts risk, but the same pipes that push good updates also push broken ones. Update rings and human checkpoints are how teams keep the speed without breaking production.

AI Is Cutting the Time Attackers Need to Exploit a Flaw. Defenders Haven't Caught Up.
Security vendor Picus argues defenders can no longer wait for public exploits or vendor fixes before acting.

AI Rewired Software Development. Cybersecurity Is Next, But Not in the Same Way
Autonomous agents, faster vulnerability discovery, and shrinking security teams are coming. The shift will be real, but slower and stranger than what happened to software engineering.

Hackuity Raises $19 Million to Help Companies Stop Drowning in Security Warnings
A French cybersecurity firm wants to solve a problem every large organisation quietly has: too many security alerts, too few people to sort through them.

Why knowing about a threat isn't the same as stopping it
Attackers are turning fresh leaks and new bug disclosures into working break-ins faster than most defenders can read the alert.

Attack Surface Management Explained
Every device, app, and login point a company exposes is a potential door for criminals. Attack surface management is about mapping all those doors before anyone else does.