#vulnerability management
86 stories taggedvulnerability management · page 3 of 6.

Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs
Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products
The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

The US Government's Software Flaw Database Is Drowning. Can AI Be the Lifeguard?
The agency that tracks every known software weakness in the world is asking the public whether artificial intelligence can help it cope with a 72% surge in reported flaws.

Oracle Releases Free Database Security Tool Amid Growing Pressure From AI-Powered Bug Hunters
Oracle Database Security Central gives organisations a single place to spot risky database settings and unusual access patterns. It's free until February 2027, though the window that prompted its creation is already closing.

Your security team's growing backlog is not their fault
When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

Intel and AMD Quietly Patched Over 80 Security Flaws. Here Is What That Means For You.
Two of the biggest names in computer chips fixed a pile of serious vulnerabilities this Patch Tuesday. Some could let attackers take full control of an affected machine.

Adobe Patches Over 50 Flaws, Tells ColdFusion and Campaign Classic Users to Act Now
Several of Adobe's most widely used business tools carried perfect-ten severity scores this week. Two products have been flagged as likely targets, and Adobe is telling administrators to patch immediately.

AI Found Thousands of Flaws in Days. Humans Can't Patch Them Fast Enough.
Anthropic's Claude Mythos model discovered more security holes in major software than years of human review had caught. That's good news for defenders in theory, but the gap between finding a flaw and fixing it was already brutal before AI joined the hunt.

When Developers Ship 50x More Code, Security Becomes the Traffic Jam
AI coding assistants are pumping out software at a pace human security teams were never built to match. Nobody's quite sure what got shipped.

CISA Flags Kemp LoadMaster Flaw After Nearly 800 Exploit Attempts
A critical command-injection bug in Progress Kemp LoadMaster is being actively abused. Federal agencies have three weeks to patch.

The Security Metric That Lies: Why Knowing Your Vulnerabilities Is Not the Same as Reducing Your Risk
Security teams are drowning in vulnerability reports yet still can't answer the one question that matters: are we actually harder to attack today than we were last year? The old way of measuring risk is the problem.

Most companies understand CTEM. Almost none of them can run it.
Knowing the five phases of Continuous Threat Exposure Management is the easy part. Building a system that actually proves your defences are improving is where programmes fall apart.

What 300,000 Real-World Security Tests Taught One Company About AI Hacking Tools
Autonomous penetration testing has reached genuine scale. The hard lesson from running 300,000 tests isn't about finding weaknesses. It's about knowing which ones actually matter.

Patched Doesn't Mean Safe: Why Security Teams Need to Test After They Fix
A new survey of 750 security leaders finds that fewer than one in three organisations check whether a fix actually stopped an attacker. The gap between completing work and reducing risk is where breaches still happen.

Fixing One Hole at a Time Is No Longer Enough: Why Security Must Follow the Full Attack Path
Criminals no longer stop at the front door. They chain weaknesses across apps, accounts, and cloud systems, and security teams testing each piece in isolation are missing the bigger picture.