home.social

#vulnerability-management — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vulnerability-management, aggregated by home.social.

fetched live
  1. GitLab Flaw Draws Widespread Probes Ahead of Patch

    GitLab has rushed out emergency patches for two severe flaws in its platform, warning users to upgrade ASAP to avoid potential exploitation. A particularly critical defect, CVE-2026-85706, has been assigned a maximum CVSS score of 10.0, sparking widespread concern.

    osintsights.com/gitlab-flaw-dr

    #Gitlab #Cve202685706 #VulnerabilityManagement #SupplyChain #EmergingThreats

  2. Autonomous Penetration Testing Gains Traction in Continuous Security Validation

    Autonomous penetration testing is revolutionizing continuous security validation, with Breach360 by BreachLock leading the charge, leveraging intel from over 40,000 real-world engagements to simulate real-life attacks. Traditional severity scores have limitations, and it's…

    osintsights.com/autonomous-pen

    #AutonomousPenetrationTesting #ContinuousSecurityValidation #PenetrationTesting #VulnerabilityManagement #Breach360

  3. GitLab Warns Users to Patch Path Traversal Flaw

    GitLab is urging users to upgrade immediately to patch a critical path traversal flaw, CVE-2026-85706, that could expose sensitive files to unauthenticated attackers. This maximum-severity vulnerability requires prompt action to protect self-managed GitLab installations.

    osintsights.com/gitlab-warns-u

    #Gitlab #PathTraversal #Cve202685706 #VulnerabilityManagement #EmergingThreats

  4. AIs Accelerate Exploit Discovery

    Meet the AI super sleuths that can uncover software vulnerabilities with just a whisper of a rumor. With minimal input, these agents can sniff out working exploits, potentially beating the patch cycle and leaving security teams scrambling to keep up.

    osintsights.com/ais-accelerate

    #ExploitDiscovery #ArtificialIntelligence #VulnerabilityManagement #EmergingThreats #AipoweredAttacks

  5. 📣 Help shape the VulnCon 2027 program!

    The Call for the VulnCon 2027 Program Committee is now live, and we’re looking for individuals ready to help shape the conversations and content driving the vulnerability management ecosystem.

    🗓️ Interest due: October 6, 2026
    📅 Term duration: October 2026–April 2027
    👥 Committee seats: 15

    Interested? Apply here:
    firstdotorg.wufoo.com/forms/cv

    Join us in helping build the program for VulnCon 2027, taking place March 30–April 2 in Scottsdale, Arizona.

    #VULNCON27 #VulnerabilityManagement #Cybersecurity #CVE #FIRST

  6. Microsoft Floods Patch Pipeline with 974 Security Fixes

    Microsoft just dropped a massive patch bundle, fixing a record-breaking 974 security holes in one fell swoop - more than doubling its previous year's total with three months still to go. This huge update eclipses the company's previous record of 570 vulnerabilities set just two months ago.

    osintsights.com/microsoft-floo

    #PatchManagement #VulnerabilityManagement #Microsoft #EmergingThreats #ZeroDay

  7. Microsoft Unveils Record 974 CVE Fixes in September Patch Tuesday Release

    This September Patch Tuesday release is a doozy, with a record 974 CVEs fixed - a staggering number that more than doubles the previous record and demands immediate attention from IT and security teams. The challenge is clear: prioritize and patch with lightning speed to stay ahead of potential threats.

    osintsights.com/microsoft-unve

    #PatchTuesday #Cve20261234 #VulnerabilityManagement #Microsoft #EmergingThreats

  8. Google Patches Actively Exploited Chrome Zero-Day Bug

    Google just patched a whopping 230 vulnerabilities, including a Chrome zero-day bug that's already being exploited by hackers - the seventh such vulnerability fixed this year! This massive update is a critical reminder to keep your browser up to date to stay safe online.

    osintsights.com/google-patches

    #ZeroDay #GoogleChrome #EmergingThreats #VulnerabilityManagement #BrowserSecurity

  9. EU Cyber Resilience Act Spurs Rush to Track Software Vulnerabilities

    Get ready for a new era of cyber transparency: by September 11, 2026, EU manufacturers with digital products must report vulnerabilities to ENISA within 24 hours of discovery, and provide a detailed report within 72 hours. This mandate is just the beginning, with stricter engineering requirements kicking in on…

    osintsights.com/eu-cyber-resil

    #EuCyberResilienceAct #Enisa #VulnerabilityManagement #SoftwareSecurity #SupplyChain

  10. Microsoft Patch Tuesday Disables Record 966 Flaws, Zero-Day Exploits

    Microsoft just dropped a massive Patch Tuesday update, fixing a record-shattering 966 vulnerabilities, including two zero-day exploits that hackers are actively using to cause trouble. This September 2026 update is a big deal, with the most flaws patched in a single update ever.

    osintsights.com/microsoft-patc

    #PatchTuesday #ZeroDay #Microsoft #EmergingThreats #VulnerabilityManagement

  11. NVD's April policy did not remove the enrichment work. It moved it. This chart is how you find out how much of it moved to you.

    The rule, published April 15: NVD enriches CVEs on CISA's KEV list, CVEs in software the federal government uses, and critical software under Executive Order 14028. Everything else is marked "not scheduled for immediate enrichment," which arrives in the API as Deferred and means no CPE. The CNA's own score usually still shows. The record does not look empty.

    Of the 51,219 CVEs published in 2026 that NVD has settled, 20,076 are Deferred. That is 39%. The useful part is that it is predictable.

    The rule is written about products. The result sorts by publisher. Patchstack, Wordfence and WPScan: 99% of their records Deferred. VulDB 70%, VulnCheck 52%, MITRE 47%, GitHub 27%. Microsoft, Chrome, Apple, Adobe and Mozilla: 0.0%. Take the three WordPress CNAs out and 12,608 Deferred CVEs remain. Severity does not change the answer: by the CNA's own score, Critical is Deferred at 46% and Low at 42%.

    So find the CNAs that publish most of your CVEs and read your own number off the chart. If you live on WordPress plugins or open-source packages, most of your CPE matching is now yours to do, and that is a staffing question before it is a tooling one. Run a Microsoft and Chrome estate and almost nothing changed. The KEV half of the rule is holding either way: 140 of the 141 KEV-listed CVEs from 2026 are enriched and none is Deferred.

    When NVD says Deferred, where does your CPE come from?

    #vulnerabilitymanagement #cybersecurity #CVE #NVD

  12. 🚨 The VulnCon 2027 website is live!🚨

    The 2027 Vulnerability Management Ecosystem Collaboration, Ideation, and Action Conference (VulnCon27), co-hosted by FIRST and the CVE Program, will take place March 30–April 2, 2027, at the DoubleTree Resort by Hilton Paradise Valley in Scottsdale, Arizona, USA.

    🔗 The website is live — head over for the latest updates and be sure to bookmark the page!
    🔗 first.org/conference/vulncon27/

    📣 The Call for the VulnCon 2027 Program Committee is also live!

    Help shape the 2027 program and contribute to the conversations driving the vulnerability management ecosystem.

    🗓️ Interest due: October 6, 2026
    📅 Term duration: October 2026–April 2027
    👥 Committee seats: 15

    Apply here:
    firstdotorg.wufoo.com/forms/cv

    More updates are on the way — bookmark the site and stay tuned! #VULNCON27 #VulnerabilityManagement #Cybersecurity #CVE #FIRST

  13. I had a chat with Jaya Baloo from AISLE about why they seem to be finding vulnerabilities even when the new fancy tools aren't finding anything

    The answer is unsurprisingly "engineering"

    Jaya has a ton of interesting insight, including how to work with open source projects and what's coming next in this space. I learned a ton

    opensourcesecurity.io/2026/202

    #OpenSourceSecurity #vulnerability #vulnerabilitymanagement
    #security

  14. ConnectWise Discloses New ScreenConnect Flaw, Offers Mitigations

    ConnectWise has uncovered a new vulnerability in its ScreenConnect platform that affects file transfer behavior in Remote Access Support and Access sessions, and is providing temporary mitigations until a patch is released later this week. To protect your systems, apply these manual workarounds now.

    osintsights.com/connectwise-di

    #RemoteAccess #Screenconnect #VulnerabilityManagement #ManagedServiceProviders #EmergingThreats

  15. 📊 Vulnerability Report – August 2026 is out.

    +25.5% CVEs over July and a new monthly record. 103 vulnerabilities entered a KEV catalog, up from 65 in July.

    The story of the month is the AI stack: Langflow, Ray and MLflow in CISA KEV within three weeks, and honeypots hammering MLflow and SGLang.

    vulnerability-lookup.org/2026/

    #KEV #GCVE #CTI #VulnerabilityReport #VLAI #CVE #CyberSecurity #Vulnerabilitymanagement

  16. 🚨 The VulnCon 2027 website just dropped! 🚨

    Head over to find the latest updates for the 2027 Vulnerability Management Ecosystem Collaboration, Ideation, and Action Conference, co-hosted by FIRST and the CVE Program.

    Learn how to apply to the Program Committee, about sponsorship opportunities, registration, and more!

    🗓️ March 30–April 2, 2027
    📍 Scottsdale, Arizona, USA

    Be sure to bookmark the page — there’s more to come!

    🔗 first.org/conference/vulncon27/

    #VULNCON27 #Cybersecurity #VulnerabilityManagement #CVE #FIRST

  17. Plex Issues Urgent Patch for Multiple Undisclosed Flaws

    Plex has just released a critical security update to patch multiple undisclosed flaws, urging users to upgrade to Plex Media Server 1.43.3 and Plex Desktop 1.115.0 ASAP to safeguard their devices. With over 360,000 devices exposed to the internet, swift action is crucial.

    osintsights.com/plex-issues-ur

    #Plex #MediaServer #SupplyChain #EmergingThreats #VulnerabilityManagement

  18. Cisco Discloses IOS XR Flaws, Urges Immediate Software Updates

    Cisco is urging immediate action to protect against two critical vulnerabilities in its IOS XR operating system, with CVSS scores of 9.8 that could allow hackers to wreak havoc on your network. Update your software now to prevent potential security breaches!

    osintsights.com/cisco-disclose

    #CiscoIosXr #Cve202620274 #Cve202620279 #VulnerabilityManagement #NetworkSecurity