home.social

#patchnow — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #patchnow, aggregated by home.social.

  1. 📰 Critical 18-Year-Old 'NGINX Rift' Vulnerability (CVE-2026-42945) Under Active Attack

    🚨 CRITICAL NGINX FLAW! An 18-year-old bug 'NGINX Rift' (CVE-2026-42945) is actively exploited for DoS & RCE. Affects millions of web servers. Patch immediately! #NGINX #CVE #Infosec #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ng

  2. 📰 CISA Adds Seven New Vulnerabilities to 'Must-Patch' KEV Catalog

    📢 CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies are required to patch under BOD 22-01. All orgs are urged to prioritize these fixes to defend against active threats. #CISA #KEV #PatchNow ...

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  3. «Attackierte MS-Defender-Lücken und BitLocker-Schutzmaßnahmen:
    Die CISA warnt vor Angriffen auf teils 18 Jahre alte Microsoft-Lücken. Patches schützen den Defender und Gegenmaßnahmen vor BitLocker-Lücke.»

    Hach ja, Microsoft und ihre Sicherheit. Abgesehen davon, System- so wie Softwareupdates IMMER so schnell wie möglich einspielen aber zu viele glauben Updates sind nicht wirklich wichtig.

    🔓 heise.de/news/Attackierte-MS-D

    #microsift #bitlocker #MSDefender #cisa #patch #PatchNOW #itsicherheit #update

  4. «Attackierte MS-Defender-Lücken und BitLocker-Schutzmaßnahmen:
    Die CISA warnt vor Angriffen auf teils 18 Jahre alte Microsoft-Lücken. Patches schützen den Defender und Gegenmaßnahmen vor BitLocker-Lücke.»

    Hach ja, Microsoft und ihre Sicherheit. Abgesehen davon, System- so wie Softwareupdates IMMER so schnell wie möglich einspielen aber zu viele glauben Updates sind nicht wirklich wichtig.

    🔓 heise.de/news/Attackierte-MS-D

    #microsift #bitlocker #MSDefender #cisa #patch #PatchNOW #itsicherheit #update

  5. «Attackierte MS-Defender-Lücken und BitLocker-Schutzmaßnahmen:
    Die CISA warnt vor Angriffen auf teils 18 Jahre alte Microsoft-Lücken. Patches schützen den Defender und Gegenmaßnahmen vor BitLocker-Lücke.»

    Hach ja, Microsoft und ihre Sicherheit. Abgesehen davon, System- so wie Softwareupdates IMMER so schnell wie möglich einspielen aber zu viele glauben Updates sind nicht wirklich wichtig.

    🔓 heise.de/news/Attackierte-MS-D

    #microsift #bitlocker #MSDefender #cisa #patch #PatchNOW #itsicherheit #update

  6. «Attackierte MS-Defender-Lücken und BitLocker-Schutzmaßnahmen:
    Die CISA warnt vor Angriffen auf teils 18 Jahre alte Microsoft-Lücken. Patches schützen den Defender und Gegenmaßnahmen vor BitLocker-Lücke.»

    Hach ja, Microsoft und ihre Sicherheit. Abgesehen davon, System- so wie Softwareupdates IMMER so schnell wie möglich einspielen aber zu viele glauben Updates sind nicht wirklich wichtig.

    🔓 heise.de/news/Attackierte-MS-D

    #microsift #bitlocker #MSDefender #cisa #patch #PatchNOW #itsicherheit #update

  7. «Attackierte MS-Defender-Lücken und BitLocker-Schutzmaßnahmen:
    Die CISA warnt vor Angriffen auf teils 18 Jahre alte Microsoft-Lücken. Patches schützen den Defender und Gegenmaßnahmen vor BitLocker-Lücke.»

    Hach ja, Microsoft und ihre Sicherheit. Abgesehen davon, System- so wie Softwareupdates IMMER so schnell wie möglich einspielen aber zu viele glauben Updates sind nicht wirklich wichtig.

    🔓 heise.de/news/Attackierte-MS-D

    #microsift #bitlocker #MSDefender #cisa #patch #PatchNOW #itsicherheit #update

  8. 🔴 New security advisory:

    CVE-2026-20182 affects multiple systems.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #InfoSec #PatchNow #InfoSecCommunity

  9. 🔴 New security advisory:

    CVE-2026-20182 affects multiple systems.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #InfoSec #PatchNow #InfoSecCommunity

  10. 🔴 New security advisory:

    CVE-2026-42945 affects multiple systems.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #InfoSec #PatchNow #InfoSecCommunity

  11. 🔴 New security advisory:

    CVE-2026-42945 affects multiple systems.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #InfoSec #PatchNow #InfoSecCommunity

  12. "🚨 Critical Vulnerability in Cisco IOS XE Software Web UI! 🚨"

    Cisco has identified a critical privilege escalation vulnerability in the web UI feature of Cisco IOS XE Software. If exposed to the internet or untrusted networks, this flaw allows remote, unauthenticated attackers to create an account with privilege level 15 access, potentially gaining control of the affected system. 🕸️💻

    Cisco is actively aware of the exploitation of this vulnerability. The issue was discovered during the resolution of multiple Cisco TAC support cases. There are currently no workarounds available. However, Cisco recommends disabling the HTTP Server feature on all internet-facing systems as a precautionary measure. 🚫🌐

    For more details and to check if your system might be affected, visit the official advisory: Cisco Security Advisory

    Tags: #Cisco #IOSXE #WebUI #Vulnerability #PrivilegeEscalation #CyberSecurity #InfoSec #PatchNow 🛡️🔐

  13. GitLab admins: Get patchin'. Now. cku.gt/D4bjM
    This 0day is exploited ITW as we speak, I have multiple reports of successful admin account takeovers.
    #0day #gitlab #privesc #patchnow #cvss10

  14. Grafana patched a CVSS 10.0 SCIM flaw (CVE-2025-41115) after discovering that numeric externalId values could override internal user IDs - enabling impersonation or privilege escalation when SCIM + user sync were active.

    Fixes are available in the latest enterprise versions. Immediate updates recommended.

    💬 Share your thoughts and follow TechNadu for more technical updates.

    #Infosec #Grafana #IAM #SCIM #CVE #SecurityUpdate #VulnerabilityManagement #ThreatIntel #IdentitySecurity #PatchNow #CyberAwareness

  15. Grafana patched a CVSS 10.0 SCIM flaw (CVE-2025-41115) after discovering that numeric externalId values could override internal user IDs - enabling impersonation or privilege escalation when SCIM + user sync were active.

    Fixes are available in the latest enterprise versions. Immediate updates recommended.

    💬 Share your thoughts and follow TechNadu for more technical updates.

    #Infosec #Grafana #IAM #SCIM #CVE #SecurityUpdate #VulnerabilityManagement #ThreatIntel #IdentitySecurity #PatchNow #CyberAwareness

  16. Grafana patched a CVSS 10.0 SCIM flaw (CVE-2025-41115) after discovering that numeric externalId values could override internal user IDs - enabling impersonation or privilege escalation when SCIM + user sync were active.

    Fixes are available in the latest enterprise versions. Immediate updates recommended.

    💬 Share your thoughts and follow TechNadu for more technical updates.

    #Infosec #Grafana #IAM #SCIM #CVE #SecurityUpdate #VulnerabilityManagement #ThreatIntel #IdentitySecurity #PatchNow #CyberAwareness

  17. Hundreds of Brother printer models are affected by a critical, unpatchable vulnerability (CVE-2024-51978) that allows attackers to generate the default admin password using the device’s serial number—information that’s easily discoverable via other flaws.

    748 total models across Brother, Fujifilm, Ricoh, Toshiba, and Konica Minolta are impacted, with millions of devices at risk globally.

    Attackers can:
    • Gain unauthenticated admin access
    • Pivot to full remote code execution
    • Exfiltrate credentials for LDAP, FTP, and more
    • Move laterally through your network

    Brother says the vulnerability cannot be fixed in firmware and requires a change in manufacturing. For now, mitigation = change the default admin password immediately.

    Our pentest team regularly highlights printer security as a critical path to system compromise—and today’s news is another example that underscores this risk. This is your reminder: Printers are not “set-and-forget” devices. Treat them like any other endpoint—monitor, patch, and lock them down.

    Need help testing your network for exploitable print devices? Contact us and our pentest team can help!

    Read the Dark Reading article for more details on the Brother Printers vulnerability: darkreading.com/endpoint-secur

    #CyberSecurity #PenetrationTesting #Pentest #Pentesting #PrinterSecurity #BrotherPrinters #CVE202451978 #Infosec #IT #SMB #CISO #Cyberaware #DFIR #ITSecurity #ZeroTrust #PatchNow #Pentest

  18. ⛔ New security advisory:

    CVE-2026-32985 affects multiple systems.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #Cybersecurity #PatchNow #InfoSecCommunity

  19. ⛔ New security advisory:

    CVE-2026-1435 affects Graylog Graylog.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #Cybersecurity #PatchNow #InfoSecCommunity

  20. "🔐 #KeyTrap DoS: The DNSSEC Dilemma - A 25-Year-Old Design Flaw Exposed 🚨"

    In a groundbreaking discovery, researchers from the National Research Center for Applied Cybersecurity ATHENE have unveiled #KeyTrap (CVE-2023-50387), a critical flaw in DNSSEC's design that could bring the internet to its knees. With a severity rating of 7.5/10, this flaw in DNSSEC has been lurking since 1999, and affects 31% of global DNSSEC-validating DNS resolvers, risking widespread internet service disruptions. KeyTrap, an Algorithmic Complexity Attack, can overload a DNS server with a single packet, stalling major DNS providers like Google and Cloudflare for up to 16 hours. This vulnerability not only jeopardizes internet access but could also cripple essential security mechanisms like anti-spam defenses and PKI. Despite patches being rolled out, a permanent fix may necessitate a DNSSEC standard overhaul. 🌍💻🛡️

    CVE Details: mitre & nvd

    Tags: #CyberSecurity #DNSSEC #Vulnerability #InternetSafety #PatchNow #TechNews #InfoSecExchange #SecurityFlaw #DigitalInfrastructure 🚀🔒💡

    Source: ATHENE Press Portal

  21. VMware has issued a security advisory advising customers of 4 critical vulnerabilities that allows users with local administrator privileges in a VM to perform VM escapes.

    www.vmware.com/security/advisories/VMSA-2024-0006.html

    #vmware #patchnow #vulnerability #VMEscape #VM

  22. "⚠️ Critical RCE Alert: 3,000 Apache ActiveMQ Servers at Risk! ⚠️"

    Over 3,000 Apache ActiveMQ servers are exposed online, vulnerable to a critical RCE flaw (CVE-2023-46604, CVSS v3: 10.0). Immediate patching is urged to prevent potential data theft and network compromise. Stay vigilant! 🛡️💻

    Apache ActiveMQ is an open-source message broker for secure communication between clients and servers, supporting Java and various cross-language clients and protocols like AMQP, MQTT, OpenWire, and STOMP.

    The flaw in question is CVE-2023-46604, a critical severity (CVSS v3 score: 10.0) RCE that allows attackers to execute arbitrary shell commands by exploiting class types in the OpenWire protocol.

    According to Apache's disclosure on October 27, 2023, this vulnerability affects the following Apache ActiveMQ and Legacy OpenWire Module versions:

    • Versions before 5.18.3 in the 5.18.x series
    • Versions before 5.17.6 in the 5.17.x series
    • Versions before 5.16.7 in the 5.16.x series
    • All versions before 5.15.16

    To address this issue, fixes have been released in versions 5.15.16, 5.16.7, 5.17.6, and 5.18.3. It's recommended to upgrade to one of these versions to enhance your IT security.

    Tags: #CyberSecurity #RCE #ApacheActiveMQ #Vulnerability #PatchNow #InfoSec #ServerSecurity #CVE202346604 🚨🔐

    Source: BleepingComputer

    Author: Bill Toulas

  23. 🚨​ [#PatchNow] New VM2 #SandboxEscape... Two critical vulns are out in the #VM2 #Sandbox Library. These flaws affect all versions prior to 3.9.17 and both carry a CVSS score of 9.8.

    If exploited, a threat actor could escape protection boundaries and execute arbitrary code. A patch has been released. so get it and update: bleepingcomputer.com/news/secu.

    These two CVEs (CVE-2023-29199 and CVE-2023-30547) were discovered by Seung Hyun Lee.

    nvd.nist.gov/vuln/detail/CVE-2

    nvd.nist.gov/vuln/detail/CVE-2

    #infosec #patchmanagement #riskmitigation

  24. [#PatchNow] A critical vulnerability in #VM2 Sandbox Library is a flaw affecting all versions with CVSS score of 9.8. If exploited, it could allow a threat actor to escape protection boundaries and execute arbitrary code on target systems. This is patched in version 3.9.15.

    github.com/patriksimek/vm2/sec

    thehackernews.com/2023/04/rese | #infosec #vuln #patchmanagement

  25. A third party report highlights a critical auth bypass in AdGuard Home that could grant admin control to attackers. Users are urged to patch immediately and review access controls. 🛡️🔧 Update to the latest release and rotate credentials. More: cyberinsider.com/adguard-home- #CyberSecurity #AdGuardHome #Vulnerability #PatchNow

  26. 📢⚠️🩹 #Cisco has patched 48 vulnerabilities in its Secure Firewall products, including 2 critical CVSS 10 flaws that could allow authentication bypass and remote code execution with root access - Patch NOW!

    Read: hackread.com/cisco-patches-fir

    #CyberSecurity #Vulnerability #PatchNow

  27. Microsoft warnt vor einer kritischen 0‑Day‑Lücke in Microsoft Office und ruft zur sofortigen Installation des Notfall‑Updates auf. um Unternehmen und Nutzer vor aktiven Angriffen zu schützen. 🛡️🧩 Mehr Infos: heise.de/news/Notfall-Update-g #Microsoft #Office #Security #ITSecurity #PatchNow

    #OnlyOffice ist auch sehr gut onlyoffice.com/de/download-des

  28. Microsoft has rushed out an emergency security update for Office (CVE‑2026‑21509) after confirming the flaw is already being exploited in the wild. 🔐

    The high‑severity security feature bypass lets attackers bypass OLE protections and run malicious code via specially crafted Office files. 📄⚠️

    👉 Microsoft issues emergency fix for actively exploited Office flaw:
    cyberinsider.com/microsoft-iss
    #Microsoft #Office #Security #CVE202621509 #PatchNow

    Threre is also #OnlyOffice

    onlyoffice.com/download-desktop

  29. CISA warnt vor aktiven Angriffen auf Apple-WebKit-Lücken und Gladinet-Dienste – Updates sind bereits verfügbar. 🚨🔐 Wer iOS, macOS & Co. nutzt, sollte jetzt patchen, bevor Angreifer nachziehen. 👉 heise.de/news/Updaten-Warnung- #CyberSecurity #Apple #PatchNow #Newz

  30. Cybersecurity Weekly Roundup (Nov 16–22)

    Chrome zero day; Oracle Identity Manager RCE (KEV); FortiWeb exploited; SonicWall SSLVPN flaw; Cloudflare outage; WhatsApp enumeration. Plus: Logitech breach, 7-Zip PoC, Salesforce/Gainsight ripple, Dutch takedown.

    Actions: Patch edge first, push Chrome, rotate keys and OAuth, rehearse failover.

    Read: kylereddoch.me/blog/cybersecur

    #Cybersecurity #Infosec #MSP #BlueTeam #PatchNow

  31. 🚨 Fortinet has released patches for two actively exploited vulnerabilities in its #FortiWeb web-application firewalls. One allows full takeover, the other enables command injection.

    Update now: hackread.com/fortinet-fixes-fo

    #Cybersecurity #InfoSec #Vulnerability #Fortinet #PatchNow

  32. 🚨 Urgent patch alert: a 9.9/10 severity flaw (CVE-2025-42887) in #SAP Solution Manager allows code injection and full system takeover. Act now.

    Read: hackread.com/sap-patch-cve-202

    #CyberSecurity #Vulnerability #ZeroDay #InfoSec #PatchNow

  33. CISA just confirmed a nasty Windows SMB bug (CVE-2025-33073) is being actively exploited.

    It lets an attacker gain SYSTEM privileges by tricking a machine into connecting to a bad SMB server.

    All Windows Server versions, Win10, and Win11 are affected. A patch was released in June 2025.

    CISA has officially added it to their must-patch (KEV) list.

    #CyberSecurity #Windows #CVE #PatchNow

    bleepingcomputer.com/news/secu

    #CyberSecurity #InfoSec #CVE #Windows #SMB #CISA #Vulnerability

  34. 🚨 CISA warns of active attacks on Linux, Android & Sitecore! 🐧📱🖥️ High & critical risks: privilege escalation & code injection. Updates available—patch now! More on CVEs & risks👇 #Cybersecurity #InfoSec #PatchNow #newz

    heise.de/en/news/Attacks-on-vu

  35. FortiWeb-Admins aufgepasst! 🚨 Für die kritische #Sicherheitslücke (CVE-2025-25257, CVSS 9.6) steht jetzt ein Exploit bereit – Angreifer können ohne Login SQL-Injection & Codeausführung erreichen. Jetzt dringend patchen! 🔒 Mehr Infos: heise.de/news/Exploit-verfuegb #Cybersecurity #Fortinet #PatchNow
    #newz

    Kurzlink: heise.de/-10485654

  36. 🚨 Major zero-day alert: A vulnerability is being actively exploited in AMI’s MegaRAC BMC software, potentially impacting thousands of servers across AMD, ARM, Supermicro, and more.
    🧠 Redfish interface flaw enables full root access
    🔓 Attackers can bypass authentication entirely
    🖥️ Supply chain vendors affected
    🌐 BMCs exposed to the internet = catastrophic risk
    📆 CISA deadline for mitigation: July 16

    This isn’t theoretical. Exploitation is happening now. If you haven’t patched and locked down your out-of-band server management, you’re leaving the door wide open.

    💬 Is your team treating BMCs as a core part of your threat surface?

    #CyberSecurity #ZeroDay #VulnerabilityManagement #CISO #PatchNow
    arstechnica.com/security/2025/

  37. Critical security flaws discovered in VMware core products including vCenter Server and ESXi. Vulnerabilities could allow command execution and service disruption. Updates available now to protect your infrastructure.

    #SecurityLand #CyberWatch #Broadcom #VMware #Vulnerability #PatchNow #SecurityVulnerability #Technology

    Read More: security.land/multiple-securit

  38. 🚨 Firefox just patched 2 critical zero-days exploited at #Pwn2Own Berlin! 🦊💻 Hackers earned $100K for finding flaws that could expose sensitive data or enable code execution. Users are urged to update ASAP for protection! 🔒 Read more: thehackernews.com/2025/05/fire #CyberSecurity #ZeroDay #Firefox #PatchNow #newz

  39. 🚨✨ Critical Alert: SSH ProxyCommand Vulnerability! Dive into the details of CVE-2023-51385, a severe code execution flaw, exposing servers to shell injection. Discover insights, mitigation strategies, and stay ahead of potential threats. 🔐💻

    relianoid.com/blog/ssh-proxyco

  40. 📰 Foxit PDF Reader Flaw (CVE-2026-5942) Could Lead to Information Disclosure

    📄 Foxit PDF Reader users: A use-after-free flaw (CVE-2026-5942) has been disclosed. It can leak sensitive info and requires opening a malicious file. A patch is available. #Foxit #Vulnerability #CyberSecurity #PatchNow

    🔗 cyber.netsecops.io

  41. [#FYSA] [Vuln] Critical Vulnerabilities in #VMware Aria Operations for Logs: VMware released software to remediate four security vulnerabilities affecting #vRealize Log Insight (aka #AriaOperations for Logs) that could expose users to remote code execution attacks.

    Tracked as CVE-2022-31706 and CVE-2022-31704, the directory traversal and broken access control issues could be exploited by a threat actor to achieve remote code execution irrespective of the difference in the attack pathway.

    thehackernews.com/2023/01/vmwa | #infosec #patchmanagement #patchnow #vulnerabilitymanagement

  42. ❗️#CERTWarnung❗️
    Die #Schwachstelle CVE-2023-46604 in Apache #ActiveMQ wird aktiv ausgenutzt. Entfernte Angreifende können ActiveMQ Server kompromittieren und Ransomware-Angriffe durchführen.
    Mehr dazu hier: 👉 bsi.bund.de/dok/1099178

    #PatchNow