#vulnmanagement — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vulnmanagement, aggregated by home.social.
-
Fortinet patched 10 flaws, including critical auth-bypass in FortiMonitorOnSight and improper authentication in Privileged Access Agent Chrome extension. Both allow unauthenticated remote exploitation. High-severity issues in FortiSandbox and FortiOS ZTNA also fixed. #Fortinet #VulnManagement #PatchManagement
https://cyberworldops.eu/en/fortinet-fixes-critical-authentication-flaws-in-fortimonitoronsight
-
Fortinet patched 10 flaws, including critical auth-bypass in FortiMonitorOnSight and improper authentication in Privileged Access Agent Chrome extension. Both allow unauthenticated remote exploitation. High-severity issues in FortiSandbox and FortiOS ZTNA also fixed. #Fortinet #VulnManagement #PatchManagement
https://cyberworldops.eu/en/fortinet-fixes-critical-authentication-flaws-in-fortimonitoronsight
-
Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement
https://cyberworldops.eu/en/tycon-tpdin-monitor-web2-two-flaws-expose-relays-and-configurations-to
-
Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement
https://cyberworldops.eu/en/tycon-tpdin-monitor-web2-two-flaws-expose-relays-and-configurations-to
-
Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement
https://cyberworldops.eu/en/tycon-tpdin-monitor-web2-two-flaws-expose-relays-and-configurations-to
-
A critical vulnerability in the Cosmos EVM shared module was silently patched on August 19 but exploitation continued across six blockchains. Cosmos Labs published a post-mortem on August 28 with no CVE assigned, no CWE, and no CVSS score — leaving the ecosystem to fend for itself.
#CosmosEVM #SilentPatch #BlockChainCVE #VulnManagement
https://cyberworldops.eu/en/cosmos-evm-critical-flaw-without-cve-six-blockchains-affected-silent
-
Google partage ses retours sur l'usage de l'IA dans la gestion des vulnérabilités. Intéressant — mais à lire en gardant en tête que Google est aussi fournisseur d'outils IA pour la sécurité. Ce qui compte : quels types de vulnérabilités sont mieux détectés, et lesquels passent encore entre les mailles ? Le diable est dans les métriques. #infosec #AI #vulnmanagement
https://dcod.ch/2026/07/21/gestion-des-vulnerabilites-avec-ia/ -
After the early-2026 wave of max-severity issues like CVE-2026-21858 “Ni8mare” and new KEV entries, have you adjusted your 2026 vulnerability management strategy yet? Explore the CVEs on https://www.cvedatabase.com/cve/CVE-2026-21858 and https://www.cvedatabase.com/cve/CVE-2026-20045
#VulnManagement #CyberSecurity #CVE #Risk -
New by me: Cybersecurity Weekly Roundup (Jan 17–24, 2026)
This week’s theme is basically: the edge is lava. Cisco UC gets patched under active exploitation, Fortinet SSO abuse turns into rogue admins, GitLab fixes a 2FA bypass, Zoom patches a critical RCE path, and telnetd reminds us why legacy services deserve the void.
I also added a quick Reality Check section at the end so you can sanity-check patching, logging, and “patched vs. clean” in one glance.
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-17-24-2026/
#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #BlueTeam #Ransomware
-
New by me: Cybersecurity Weekly Roundup (Jan 17–24, 2026)
This week’s theme is basically: the edge is lava. Cisco UC gets patched under active exploitation, Fortinet SSO abuse turns into rogue admins, GitLab fixes a 2FA bypass, Zoom patches a critical RCE path, and telnetd reminds us why legacy services deserve the void.
I also added a quick Reality Check section at the end so you can sanity-check patching, logging, and “patched vs. clean” in one glance.
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-17-24-2026/
#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #BlueTeam #Ransomware
-
New by me: Cybersecurity Weekly Roundup (Jan 17–24, 2026)
This week’s theme is basically: the edge is lava. Cisco UC gets patched under active exploitation, Fortinet SSO abuse turns into rogue admins, GitLab fixes a 2FA bypass, Zoom patches a critical RCE path, and telnetd reminds us why legacy services deserve the void.
I also added a quick Reality Check section at the end so you can sanity-check patching, logging, and “patched vs. clean” in one glance.
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-17-24-2026/
#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #BlueTeam #Ransomware
-
New by me: Cybersecurity Weekly Roundup (Jan 17–24, 2026)
This week’s theme is basically: the edge is lava. Cisco UC gets patched under active exploitation, Fortinet SSO abuse turns into rogue admins, GitLab fixes a 2FA bypass, Zoom patches a critical RCE path, and telnetd reminds us why legacy services deserve the void.
I also added a quick Reality Check section at the end so you can sanity-check patching, logging, and “patched vs. clean” in one glance.
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-17-24-2026/
#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #BlueTeam #Ransomware
-
New by me: Cybersecurity Weekly Roundup (Jan 17–24, 2026)
This week’s theme is basically: the edge is lava. Cisco UC gets patched under active exploitation, Fortinet SSO abuse turns into rogue admins, GitLab fixes a 2FA bypass, Zoom patches a critical RCE path, and telnetd reminds us why legacy services deserve the void.
I also added a quick Reality Check section at the end so you can sanity-check patching, logging, and “patched vs. clean” in one glance.
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-17-24-2026/
#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #BlueTeam #Ransomware
-
Back in the saddle with my Cybersecurity Weekly Roundup for 2026.
This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.
15 stories, quick briefs, and my practitioner take:
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-2-9-2026/#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle
-
Back in the saddle with my Cybersecurity Weekly Roundup for 2026.
This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.
15 stories, quick briefs, and my practitioner take:
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-2-9-2026/#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle
-
Back in the saddle with my Cybersecurity Weekly Roundup for 2026.
This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.
15 stories, quick briefs, and my practitioner take:
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-2-9-2026/#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle
-
Back in the saddle with my Cybersecurity Weekly Roundup for 2026.
This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.
15 stories, quick briefs, and my practitioner take:
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-2-9-2026/#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle
-
Back in the saddle with my Cybersecurity Weekly Roundup for 2026.
This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.
15 stories, quick briefs, and my practitioner take:
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-2-9-2026/#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle
-
Ever wish your vulnerability scanner could tell you what's really exploitable? Grype now includes CISA KEV & EPSS data, plus powerful vuln-db search! Prioritize smarter. 🎯 #Grype #Cybersecurity #VulnManagement
https://anchore.com/blog/time-to-take-another-look-at-grype-a-year-of-major-improvements/ -
Ever wish your vulnerability scanner could tell you what's really exploitable? Grype now includes CISA KEV & EPSS data, plus powerful vuln-db search! Prioritize smarter. 🎯 #Grype #Cybersecurity #VulnManagement
https://anchore.com/blog/time-to-take-another-look-at-grype-a-year-of-major-improvements/ -
Ever wish your vulnerability scanner could tell you what's really exploitable? Grype now includes CISA KEV & EPSS data, plus powerful vuln-db search! Prioritize smarter. 🎯 #Grype #Cybersecurity #VulnManagement
https://anchore.com/blog/time-to-take-another-look-at-grype-a-year-of-major-improvements/ -
Ever wish your vulnerability scanner could tell you what's really exploitable? Grype now includes CISA KEV & EPSS data, plus powerful vuln-db search! Prioritize smarter. 🎯 #Grype #Cybersecurity #VulnManagement
https://anchore.com/blog/time-to-take-another-look-at-grype-a-year-of-major-improvements/ -
Ever wish your vulnerability scanner could tell you what's really exploitable? Grype now includes CISA KEV & EPSS data, plus powerful vuln-db search! Prioritize smarter. 🎯 #Grype #Cybersecurity #VulnManagement
https://anchore.com/blog/time-to-take-another-look-at-grype-a-year-of-major-improvements/ -
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://go.first.org/xjTt6 #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://www.first.org/conference/vulncon2025/cfp #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://www.first.org/conference/vulncon2025/cfp #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://www.first.org/conference/vulncon2025/cfp #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://www.first.org/conference/vulncon2025/cfp #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
Want to speak at #VulnCon2025 ? Apply today! The #CFP closes January 15, 2025. Learn more at: https://www.first.org/conference/vulncon2025/cfp #vulnmanagement #CVEProgram #VulnerabilityMetadata #ManagingRisk #PSIRT #VEX #SupplyChainSecurity #VulnIdentifiers
-
CISA BOD 23-01 released new compliance requirements regarding asset inventory and vulnerability management. Federal agencies must comply with this directive by April 2023, but all organizations are encouraged to incorporate the guidelines to strengthen the foundations of their security posture.
How can you achieve compliance? Check out our blog for an overview of the new directive, and steps to meet (or even exceed!) the requirements:
#networksecurity #vulnmanagement #assetinventory #itcompliance
-
CISA BOD 23-01 released new compliance requirements regarding asset inventory and vulnerability management. Federal agencies must comply with this directive by April 2023, but all organizations are encouraged to incorporate the guidelines to strengthen the foundations of their security posture.
How can you achieve compliance? Check out our blog for an overview of the new directive, and steps to meet (or even exceed!) the requirements:
#networksecurity #vulnmanagement #assetinventory #itcompliance
-
CISA BOD 23-01 released new compliance requirements regarding asset inventory and vulnerability management. Federal agencies must comply with this directive by April 2023, but all organizations are encouraged to incorporate the guidelines to strengthen the foundations of their security posture.
How can you achieve compliance? Check out our blog for an overview of the new directive, and steps to meet (or even exceed!) the requirements:
#networksecurity #vulnmanagement #assetinventory #itcompliance