#vulnerability-management — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vulnerability-management, aggregated by home.social.
-
GitLab Flaw Draws Widespread Probes Ahead of Patch
GitLab has rushed out emergency patches for two severe flaws in its platform, warning users to upgrade ASAP to avoid potential exploitation. A particularly critical defect, CVE-2026-85706, has been assigned a maximum CVSS score of 10.0, sparking widespread concern.
#Gitlab #Cve202685706 #VulnerabilityManagement #SupplyChain #EmergingThreats
-
Autonomous Penetration Testing Gains Traction in Continuous Security Validation
Autonomous penetration testing is revolutionizing continuous security validation, with Breach360 by BreachLock leading the charge, leveraging intel from over 40,000 real-world engagements to simulate real-life attacks. Traditional severity scores have limitations, and it's…
#AutonomousPenetrationTesting #ContinuousSecurityValidation #PenetrationTesting #VulnerabilityManagement #Breach360
-
GitLab Warns Users to Patch Path Traversal Flaw
GitLab is urging users to upgrade immediately to patch a critical path traversal flaw, CVE-2026-85706, that could expose sensitive files to unauthenticated attackers. This maximum-severity vulnerability requires prompt action to protect self-managed GitLab installations.
#Gitlab #PathTraversal #Cve202685706 #VulnerabilityManagement #EmergingThreats
-
AIs Accelerate Exploit Discovery
Meet the AI super sleuths that can uncover software vulnerabilities with just a whisper of a rumor. With minimal input, these agents can sniff out working exploits, potentially beating the patch cycle and leaving security teams scrambling to keep up.
https://osintsights.com/ais-accelerate-exploit-discovery?utm_source=mastodon&utm_medium=social
#ExploitDiscovery #ArtificialIntelligence #VulnerabilityManagement #EmergingThreats #AipoweredAttacks
-
📣 Help shape the VulnCon 2027 program!
The Call for the VulnCon 2027 Program Committee is now live, and we’re looking for individuals ready to help shape the conversations and content driving the vulnerability management ecosystem.
🗓️ Interest due: October 6, 2026
📅 Term duration: October 2026–April 2027
👥 Committee seats: 15Interested? Apply here:
https://firstdotorg.wufoo.com/forms/cvefirst-vulncon27-program-committee-interest/Join us in helping build the program for VulnCon 2027, taking place March 30–April 2 in Scottsdale, Arizona.
#VULNCON27 #VulnerabilityManagement #Cybersecurity #CVE #FIRST
-
Microsoft Floods Patch Pipeline with 974 Security Fixes
Microsoft just dropped a massive patch bundle, fixing a record-breaking 974 security holes in one fell swoop - more than doubling its previous year's total with three months still to go. This huge update eclipses the company's previous record of 570 vulnerabilities set just two months ago.
#PatchManagement #VulnerabilityManagement #Microsoft #EmergingThreats #ZeroDay
-
The @gcve BCP-07 KEV format has been updated to allow the
WithdrawnandReassertedKEV Assertions.This allows to support case like CVE-2026-69836 .
🔗 https://gcve.eu/bcp/gcve-bcp-07/#withdrawn-and-reasserted-kev-assertions
#cve #gcve #kev #cybersecurity #vulnerabilitymanagement #vulnerability
-
Microsoft Unveils Record 974 CVE Fixes in September Patch Tuesday Release
This September Patch Tuesday release is a doozy, with a record 974 CVEs fixed - a staggering number that more than doubles the previous record and demands immediate attention from IT and security teams. The challenge is clear: prioritize and patch with lightning speed to stay ahead of potential threats.
#PatchTuesday #Cve20261234 #VulnerabilityManagement #Microsoft #EmergingThreats
-
Google Patches Actively Exploited Chrome Zero-Day Bug
Google just patched a whopping 230 vulnerabilities, including a Chrome zero-day bug that's already being exploited by hackers - the seventh such vulnerability fixed this year! This massive update is a critical reminder to keep your browser up to date to stay safe online.
#ZeroDay #GoogleChrome #EmergingThreats #VulnerabilityManagement #BrowserSecurity
-
EU Cyber Resilience Act Spurs Rush to Track Software Vulnerabilities
Get ready for a new era of cyber transparency: by September 11, 2026, EU manufacturers with digital products must report vulnerabilities to ENISA within 24 hours of discovery, and provide a detailed report within 72 hours. This mandate is just the beginning, with stricter engineering requirements kicking in on…
#EuCyberResilienceAct #Enisa #VulnerabilityManagement #SoftwareSecurity #SupplyChain
-
Microsoft Patch Tuesday Disables Record 966 Flaws, Zero-Day Exploits
Microsoft just dropped a massive Patch Tuesday update, fixing a record-shattering 966 vulnerabilities, including two zero-day exploits that hackers are actively using to cause trouble. This September 2026 update is a big deal, with the most flaws patched in a single update ever.
#PatchTuesday #ZeroDay #Microsoft #EmergingThreats #VulnerabilityManagement
-
Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.
#PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement
-
NVD's April policy did not remove the enrichment work. It moved it. This chart is how you find out how much of it moved to you.
The rule, published April 15: NVD enriches CVEs on CISA's KEV list, CVEs in software the federal government uses, and critical software under Executive Order 14028. Everything else is marked "not scheduled for immediate enrichment," which arrives in the API as Deferred and means no CPE. The CNA's own score usually still shows. The record does not look empty.
Of the 51,219 CVEs published in 2026 that NVD has settled, 20,076 are Deferred. That is 39%. The useful part is that it is predictable.
The rule is written about products. The result sorts by publisher. Patchstack, Wordfence and WPScan: 99% of their records Deferred. VulDB 70%, VulnCheck 52%, MITRE 47%, GitHub 27%. Microsoft, Chrome, Apple, Adobe and Mozilla: 0.0%. Take the three WordPress CNAs out and 12,608 Deferred CVEs remain. Severity does not change the answer: by the CNA's own score, Critical is Deferred at 46% and Low at 42%.
So find the CNAs that publish most of your CVEs and read your own number off the chart. If you live on WordPress plugins or open-source packages, most of your CPE matching is now yours to do, and that is a staffing question before it is a tooling one. Run a Microsoft and Chrome estate and almost nothing changed. The KEV half of the rule is holding either way: 140 of the 141 KEV-listed CVEs from 2026 are enriched and none is Deferred.
When NVD says Deferred, where does your CPE come from?
-
New by me: I Spent the Past Few Days With OpenAI’s GPT-6 Astra. Here’s What It Means for Cybersecurity
#OpenAI #GPT6Astra #Cybersecurity #InfoSec #AI #VulnerabilityManagement
-
🚨 The VulnCon 2027 website is live!🚨
The 2027 Vulnerability Management Ecosystem Collaboration, Ideation, and Action Conference (VulnCon27), co-hosted by FIRST and the CVE Program, will take place March 30–April 2, 2027, at the DoubleTree Resort by Hilton Paradise Valley in Scottsdale, Arizona, USA.
🔗 The website is live — head over for the latest updates and be sure to bookmark the page!
🔗 https://www.first.org/conference/vulncon27/📣 The Call for the VulnCon 2027 Program Committee is also live!
Help shape the 2027 program and contribute to the conversations driving the vulnerability management ecosystem.
🗓️ Interest due: October 6, 2026
📅 Term duration: October 2026–April 2027
👥 Committee seats: 15Apply here:
https://firstdotorg.wufoo.com/forms/cvefirst-vulncon27-program-committee-interest/More updates are on the way — bookmark the site and stay tuned! #VULNCON27 #VulnerabilityManagement #Cybersecurity #CVE #FIRST
-
I had a chat with Jaya Baloo from AISLE about why they seem to be finding vulnerabilities even when the new fancy tools aren't finding anything
The answer is unsurprisingly "engineering"
Jaya has a ton of interesting insight, including how to work with open source projects and what's coming next in this space. I learned a ton
https://opensourcesecurity.io/2026/2026-09-jaya-aisle/
#OpenSourceSecurity #vulnerability #vulnerabilitymanagement
#security -
ConnectWise Discloses New ScreenConnect Flaw, Offers Mitigations
ConnectWise has uncovered a new vulnerability in its ScreenConnect platform that affects file transfer behavior in Remote Access Support and Access sessions, and is providing temporary mitigations until a patch is released later this week. To protect your systems, apply these manual workarounds now.
#RemoteAccess #Screenconnect #VulnerabilityManagement #ManagedServiceProviders #EmergingThreats
-
This weekly CVE report covers 10 exploited vulnerabilities added to CISA KEV and 2,316 new CVEs from Aug 31 to Sep 6, 2026. Patch fast.
#CVE #CISAKEV #ExploitedVulnerabilities #SonicWall #InfoSec #PatchNow #VulnerabilityManagement
-
📊 Vulnerability Report – August 2026 is out.
+25.5% CVEs over July and a new monthly record. 103 vulnerabilities entered a KEV catalog, up from 65 in July.
The story of the month is the AI stack: Langflow, Ray and MLflow in CISA KEV within three weeks, and honeypots hammering MLflow and SGLang.
https://www.vulnerability-lookup.org/2026/09/06/vulnerability-report-august-2026/
#KEV #GCVE #CTI #VulnerabilityReport #VLAI #CVE #CyberSecurity #Vulnerabilitymanagement
-
🚨 The VulnCon 2027 website just dropped! 🚨
Head over to find the latest updates for the 2027 Vulnerability Management Ecosystem Collaboration, Ideation, and Action Conference, co-hosted by FIRST and the CVE Program.
Learn how to apply to the Program Committee, about sponsorship opportunities, registration, and more!
🗓️ March 30–April 2, 2027
📍 Scottsdale, Arizona, USABe sure to bookmark the page — there’s more to come!
🔗 https://www.first.org/conference/vulncon27/
#VULNCON27 #Cybersecurity #VulnerabilityManagement #CVE #FIRST
-
Plex Issues Urgent Patch for Multiple Undisclosed Flaws
Plex has just released a critical security update to patch multiple undisclosed flaws, urging users to upgrade to Plex Media Server 1.43.3 and Plex Desktop 1.115.0 ASAP to safeguard their devices. With over 360,000 devices exposed to the internet, swift action is crucial.
#Plex #MediaServer #SupplyChain #EmergingThreats #VulnerabilityManagement
-
Cisco Discloses IOS XR Flaws, Urges Immediate Software Updates
Cisco is urging immediate action to protect against two critical vulnerabilities in its IOS XR operating system, with CVSS scores of 9.8 that could allow hackers to wreak havoc on your network. Update your software now to prevent potential security breaches!
#CiscoIosXr #Cve202620274 #Cve202620279 #VulnerabilityManagement #NetworkSecurity