#vulnerability management
77 stories taggedvulnerability management · page 2 of 6.

Fixing One Hole at a Time Is No Longer Enough: Why Security Must Follow the Full Attack Path
Criminals no longer stop at the front door. They chain together weaknesses across your apps, accounts, and cloud systems, and security teams testing each piece in isolation are missing the bigger picture.

Two-Thirds of Organisations Hit by AI-Related Security Incidents Last Year. The Weak Link Is the API.
A surge in AI adoption has quietly created a new kind of back door into company systems. Experts say most businesses are focused on the wrong part of the problem.

CISA flags N-able N-central bug as actively exploited, orders federal fix
The remote monitoring platform used by thousands of IT providers carries an authentication bypass that attackers are already using in the wild.

CISA Rewrites the Rules for Software Ingredients Lists. Critics Say It's Not Enough.
A 17-nation coalition has updated the global standard for tracking what goes into software. The framework is broader than its 2021 predecessor, but security experts argue it sidesteps the hardest questions.

Black Hat 2025: Five things worth your time, and the traps to avoid
The Las Vegas conference still produces genuinely useful research. Getting to it means ignoring a lot of expensive noise.

Cantina Raises $8 Million to Let AI Agents Hunt and Fix Security Flaws Automatically
A New York startup wants to replace slow, manual vulnerability management with software agents that find problems, investigate them, and patch them without waiting for a human to file a ticket.

AI Is Shrinking the Time Between Bug and Break-In. Playbooks Haven't Caught Up.
Vendors are pitching AI-driven vulnerability tools like Mythos as the answer. The harder question is what defenders have been doing wrong for years.

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.
A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.

Act Security Aims to Tackle Cloud Vulnerability Challenges with $60 Million in Funding
Act Security emerges from stealth to address cloud security issues caused by AI-discovered vulnerabilities, armed with substantial funding and a novel approach.

Nvidia Leads 40-Company Coalition to Build Open Security Tools for AI Systems
The Open Secure AI Alliance wants shared, openly inspectable tools to become the standard defence against attacks on artificial intelligence systems, and it is warning regulators that locking down open AI could leave defenders blind.

Can You Still Patch Your Way to Safety? Why the Old Playbook Is Breaking Down
Artificial intelligence can now turn a published vulnerability description into a working attack in under a day. That changes the math for every organisation relying on traditional patch schedules.

Microsoft Wants You to Patch in Three Days. Security Teams Say That's Not How It Works.
Microsoft is telling IT administrators to apply security fixes within 72 hours, citing AI tools that find and exploit software flaws faster than ever. Experts agree on the threat. They disagree, sharply, on whether three days is workable.

Eclypsium launches InfraTrust to flag the infrastructure flaws no one is patching
A new knowledge base and monthly report from firmware security firm Eclypsium aims to tell defenders which router, firewall and server bugs to fix first.

AI Is Compressing the Cybersecurity Timeline. Security Teams Are Racing to Keep Up.
Artificial intelligence is speeding up both attack and defence at the same time. The organisations that survive the shift may not be the best-defended. They may simply be the fastest to act.

AI Security Scanners Are Drowning Teams in False Alarms, and the Fix Isn't More AI
More than 60% of flagged security flaws are noise. A researcher testing a dozen tools says AI models make the problem worse, not better, because they lack the context to tell a real threat from a ghost.