#vulnerability management
77 stories taggedvulnerability management.

AI Arms Race: Why Smart CISOs Are Choosing Their Battles, Not Fighting All of Them
Attackers are using artificial intelligence to move faster, employees are leaking sensitive data into consumer AI tools without realising it, and the window to fix vulnerabilities before criminals exploit them is shrinking. Here is what security leaders should actually prioritise.

Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs
Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products
The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

The US Government's Software Flaw Database Is Drowning. Can AI Be the Lifeguard?
The agency that tracks every known software weakness in the world is asking the public whether artificial intelligence can help it cope with a 72% surge in reported flaws.

Oracle Releases Free Database Security Tool Amid Growing Pressure From AI-Powered Bug Hunters
Oracle Database Security Central gives organisations a single place to spot risky database settings and unusual access patterns. It is free until February 2027, though the window that prompted its creation is already closing.

Your security team's growing backlog is not their fault
When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

Intel and AMD Quietly Patched Over 80 Security Flaws. Here Is What That Means For You.
Two of the biggest names in computer chips fixed a pile of serious vulnerabilities this Patch Tuesday. Some could let attackers take full control of an affected machine.

Adobe Patches Over 50 Flaws, Tells ColdFusion and Campaign Classic Users to Act Now
Several of Adobe's most widely used business tools carried perfect-ten severity scores this week. Two products have been flagged as likely targets, and Adobe is telling administrators to patch immediately.

AI Found Thousands of Flaws in Days. Humans Can't Patch Them Fast Enough.
Anthropic's Claude Mythos model discovered more security holes in major software than years of human review had caught. That's exciting for defenders and terrifying for everyone else, because the gap between finding a flaw and fixing it is already dangerously wide.

When Developers Ship 50x More Code, Security Becomes the Traffic Jam
AI coding assistants are pumping out software at a pace human security teams were never built to match. The real question is not whether bugs slip through, but whether anyone still knows what got shipped.

CISA Flags Kemp LoadMaster Flaw After Nearly 800 Exploit Attempts
A critical command-injection bug in Progress Kemp LoadMaster is being actively abused. Federal agencies have three weeks to patch.

The Security Metric That Lies: Why Knowing Your Vulnerabilities Is Not the Same as Reducing Your Risk
Security teams are drowning in vulnerability reports yet still cannot answer the one question that matters: are we actually harder to attack today than we were last year? A growing number of experts say the old way of measuring risk is the problem.

Most companies understand CTEM. Almost none of them can run it.
Knowing the five phases of Continuous Threat Exposure Management is the easy part. Building a system that actually proves your defences are improving is where programmes fall apart.

What 300,000 Real-World Security Tests Taught One Company About AI Hacking Tools
Autonomous penetration testing has reached genuine scale. The hard lesson from running 300,000 tests is not about finding weaknesses. It is about knowing which ones actually matter.

Patched Doesn't Mean Safe: Why Security Teams Need to Test After They Fix
A new survey of 750 security leaders finds that fewer than one in three organisations check whether a fix actually stopped an attacker. The gap between completing work and reducing risk is where breaches still happen.