Tag

#vulnerability management

86 stories taggedvulnerability management.

Illustration: a dimly lit server room with rows of network equipment
Vulnerabilities

CISA Gives Federal Agencies Three Days to Patch a WSO2 Flaw Already Being Exploited

Two critical bugs are being actively exploited. Federal civilian agencies must fix the WSO2 vulnerability by September 27, and the same urgency applies to any organisation running the affected software.

3 min read
Illustration: a dimly lit server rack in a data centre, blue and amber status LEDs reflecting off polished floor tiles
Vulnerabilities

CISA tells federal agencies: patch three Linux kernel bugs within days, attackers already using them

Three Linux kernel flaws are being exploited in the wild. Federal agencies have until 21 September to patch, and the most serious carries a 9.8 severity score.

4 min read
Illustration for the story: Autonomous AI Pentesters Arrive as the Patch Gap Widens
AI Security

Autonomous AI Pentesters Arrive as the Patch Gap Widens

Attackers now exploit new flaws in about five days. The average company still takes six weeks to patch. Vendors say AI agents can close the gap. Regulators are starting to notice.

4 min read
Illustration: an empty government briefing room at dusk
Policy & Regulation

CISA Is Scrapping Its Weekly Vulnerability Bulletin

The agency is retiring its regular digest of known security flaws in favour of a new directive that tells federal agencies to patch based on real-world danger, not scores on a chart.

3 min read
Illustration: a dimly lit server room aisle with rows of rack-mounted Linux servers
Policy & Regulation

CISA Orders Federal Agencies to Patch Two Linux Kernel Flaws

The KEV catalog additions are the first Linux kernel entries to test Binding Operational Directive 26-04's risk-based patching regime.

4 min read
A Windows Update completion screen showing 974 security patches installed, with active exploit alerts visible in background security center notifications
Vulnerabilities

Microsoft's Biggest-Ever Security Update Fixes 974 Flaws, Two Already Used in Attacks

A record-breaking September patch release plugs two security holes that criminals were actively exploiting, plus 20 vulnerabilities serious enough that a single infected machine could spread the attack to others automatically.

3 min read
A security operations center with six different security dashboards and tools displayed across multiple monitors, with a CVE notification appearing on one scree
Vulnerabilities

The Race to Answer 'Are We Exposed?' Is Getting Harder

A new CVE drops and the clock starts. Security teams still hop between six tools to find out if it matters. AI is making that lag more dangerous.

3 min read
A security analyst's workstation overwhelmed with vulnerability scanner output, red critical alerts filling the screen while a smaller exploit path diagram is n
Opinion

Your Scariest Vulnerabilities Might Not Be the Ones That Get You Hacked

Scanner reports full of 'critical' flags are drowning security teams. The real question is which of those flags actually give an attacker a path in.

4 min read
A cybersecurity conference hall with a speaker presenting at a podium, security team members in the audience looking overwhelmed, multiple alert dashboards visi
AI Security

AI Is Finding Vulnerabilities Faster Than Security Teams Can Fix Them

At CrowdStrike's Fal.Con 2026 conference, the real alarm wasn't about AI-powered attacks. It was about what happens when defenders are already drowning in warnings and attackers start moving faster.

3 min read
A software deployment pipeline diagram displayed on a large monitor, showing update stages with some patches moving through fast lanes causing system failures w
Opinion

Patch automation needs a brake pedal, not just an accelerator

Faster patching cuts risk, but the same pipes that push good updates also push broken ones. Update rings and human checkpoints are how teams keep the speed without breaking production.

4 min read
A split-screen visualization showing attack timeline accelerating on one side with AI-driven exploitation, defense response lagging on the other side, with cloc
Vulnerabilities

AI Is Cutting the Time Attackers Need to Exploit a Flaw. Defenders Haven't Caught Up.

Security vendor Picus argues defenders can no longer wait for public exploits or vendor fixes before acting.

4 min read
A software development and security team collaborating in a modern office, with AI-generated code and vulnerability detection systems visible on multiple screen
AI Security

AI Rewired Software Development. Cybersecurity Is Next, But Not in the Same Way

Autonomous agents, faster vulnerability discovery, and shrinking security teams are coming. The shift will be real, but slower and stranger than what happened to software engineering.

5 min read
A security team in a modern office receiving a briefing, with large monitors behind them displaying thousands of security alerts stacked vertically, representin
AI Security

Hackuity Raises $19 Million to Help Companies Stop Drowning in Security Warnings

A French cybersecurity firm wants to solve a problem every large organisation quietly has: too many security alerts, too few people to sort through them.

3 min read
A cybersecurity analyst working late into the evening, surrounded by monitors displaying vulnerability bulletins and exploit code, racing against time as clock
Identity & Access

Why knowing about a threat isn't the same as stopping it

Attackers are turning fresh leaks and new bug disclosures into working break-ins faster than most defenders can read the alert.

4 min read
An illustrated digital landscape showing a corporate network perimeter mapped from above like a city, with multiple entry points, devices, and access nodes high
Threat Intelligence

Attack Surface Management Explained

Every device, app, and login point a company exposes is a potential door for criminals. Attack surface management is about mapping all those doors before anyone else does.

3 min read
© 2026 Threat Vectr