#vulnerability management
79 stories taggedvulnerability management · page 4 of 6.

569 Patches in One Month: Microsoft Just Broke Every Record on the Books
AI tools are finding software flaws faster than any human team ever could. The result is a single monthly update that dwarfs every full year of fixes from the past two decades.

Microsoft's July 2026 Patch Tuesday Is the Biggest Ever, 622 Fixes at Once
AI tools are finding software flaws faster than companies can fix them. This month's update from Microsoft shows exactly what that looks like in practice.

You Don't Need to Fire the Exploit to Know You're Exposed
A quieter way to test whether a vulnerability actually threatens your network: check the steps an attacker would need, not the payload itself.

The Engineers Building Both Sides of the AI Security War
A new breed of security team is quietly writing the rules for how artificial intelligence gets used in cyberattacks and defenses. Most companies have never heard of them.

Security Debt Is Growing Faster Than Companies Can Fix It. Here Is What That Means.
Eight in ten organisations are sitting on a backlog of unresolved security flaws that stretch back more than a year. A practical framework, first outlined in CSO Online, explains how to turn that problem into a board-level conversation.

CISA Flags Four Live-Exploited Bugs in Adobe, Joomla and Langflow
The US cyber agency gave federal agencies until early December to patch a critical Adobe ColdFusion flaw and three others already being abused in the wild.

Five Eyes spy agencies warn AI will outpace cybersecurity defences within months
The intelligence alliance that links the US, UK, Australia, Canada and New Zealand says AI-powered attacks are arriving faster than most organisations can adapt — and breaches are now a question of when, not if.

A Year of Testing Has Cooled Security Teams' Enthusiasm for AI-Run Hacking Drills
Companies that hoped AI could fully replace human security testers have pulled back sharply. New data shows only 9% still trust fully automated systems — down from nearly a third just twelve months ago.

CISA Flags Actively Exploited SimpleHelp Flaw, Orders Federal Agencies to Patch Fast
A newly listed authentication bypass in SimpleHelp remote-support software is being used in real attacks, and federal agencies now face a hard deadline to fix it.

CISA orders federal agencies to patch SharePoint flaw by Saturday as attacks begin
A newly exploited Microsoft SharePoint bug lands in CISA's Known Exploited Vulnerabilities Catalog, triggering a three-day patching clock under Binding Operational Directive 26-04.

Adobe Rushes Out Fixes for a Dozen Flaws in ColdFusion and Campaign Classic — Six Are as Bad as It Gets
Twelve security holes, six of them rated the highest possible severity, were quietly sitting in two widely used Adobe products. Patches are out. The clock is ticking.

Frontier AI Is a Pressure Test, Not a New Threat Model
The arrival of capable AI models like Mythos changes attacker economics. It doesn't change which controls actually matter — and most organizations are still failing the old ones.

The Patch Cycle Won't Survive Machine-Speed Adversaries
Defenders measured dwell time in days. Agentic attack pipelines are about to measure it in minutes.

AWS Continuum Wants to Close the Gap Between AI-Generated Code and AI-Fixed Vulnerabilities
Amazon's new agentic security service promises continuous discovery, triage, and remediation. In practice, it's a bet that the same AI acceleration creating your backlog can also drain it.

AI Breaks the Assumption Cybersecurity Was Built On
Modern security programs were engineered around deterministic systems. Agentic AI isn't one.