home.social

#vulnmanagement — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vulnmanagement, aggregated by home.social.

fetched live
  1. Fortinet patched 10 flaws, including critical auth-bypass in FortiMonitorOnSight and improper authentication in Privileged Access Agent Chrome extension. Both allow unauthenticated remote exploitation. High-severity issues in FortiSandbox and FortiOS ZTNA also fixed. #Fortinet #VulnManagement #PatchManagement

    cyberworldops.eu/en/fortinet-f

  2. Fortinet patched 10 flaws, including critical auth-bypass in FortiMonitorOnSight and improper authentication in Privileged Access Agent Chrome extension. Both allow unauthenticated remote exploitation. High-severity issues in FortiSandbox and FortiOS ZTNA also fixed. #Fortinet #VulnManagement #PatchManagement

    cyberworldops.eu/en/fortinet-f

  3. Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement

    cyberworldops.eu/en/tycon-tpdi

  4. Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement

    cyberworldops.eu/en/tycon-tpdi

  5. Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement

    cyberworldops.eu/en/tycon-tpdi

  6. A critical vulnerability in the Cosmos EVM shared module was silently patched on August 19 but exploitation continued across six blockchains. Cosmos Labs published a post-mortem on August 28 with no CVE assigned, no CWE, and no CVSS score — leaving the ecosystem to fend for itself.

    #CosmosEVM #SilentPatch #BlockChainCVE #VulnManagement

    cyberworldops.eu/en/cosmos-evm

  7. Google partage ses retours sur l'usage de l'IA dans la gestion des vulnérabilités. Intéressant — mais à lire en gardant en tête que Google est aussi fournisseur d'outils IA pour la sécurité. Ce qui compte : quels types de vulnérabilités sont mieux détectés, et lesquels passent encore entre les mailles ? Le diable est dans les métriques. #infosec #AI #vulnmanagement
    dcod.ch/2026/07/21/gestion-des

  8. After the early-2026 wave of max-severity issues like CVE-2026-21858 “Ni8mare” and new KEV entries, have you adjusted your 2026 vulnerability management strategy yet? Explore the CVEs on cvedatabase.com/cve/CVE-2026-2 and cvedatabase.com/cve/CVE-2026-2

  9. New by me: Cybersecurity Weekly Roundup (Jan 17–24, 2026)

    This week’s theme is basically: the edge is lava. Cisco UC gets patched under active exploitation, Fortinet SSO abuse turns into rogue admins, GitLab fixes a 2FA bypass, Zoom patches a critical RCE path, and telnetd reminds us why legacy services deserve the void.

    I also added a quick Reality Check section at the end so you can sanity-check patching, logging, and “patched vs. clean” in one glance.

    kylereddoch.me/blog/cybersecur

    #Cybersecurity #InfoSec #VulnManagement #ThreatIntel #BlueTeam #Ransomware

  10. New by me: Cybersecurity Weekly Roundup (Jan 17–24, 2026)

    This week’s theme is basically: the edge is lava. Cisco UC gets patched under active exploitation, Fortinet SSO abuse turns into rogue admins, GitLab fixes a 2FA bypass, Zoom patches a critical RCE path, and telnetd reminds us why legacy services deserve the void.

    I also added a quick Reality Check section at the end so you can sanity-check patching, logging, and “patched vs. clean” in one glance.

    kylereddoch.me/blog/cybersecur

    #Cybersecurity #InfoSec #VulnManagement #ThreatIntel #BlueTeam #Ransomware

  11. New by me: Cybersecurity Weekly Roundup (Jan 17–24, 2026)

    This week’s theme is basically: the edge is lava. Cisco UC gets patched under active exploitation, Fortinet SSO abuse turns into rogue admins, GitLab fixes a 2FA bypass, Zoom patches a critical RCE path, and telnetd reminds us why legacy services deserve the void.

    I also added a quick Reality Check section at the end so you can sanity-check patching, logging, and “patched vs. clean” in one glance.

    kylereddoch.me/blog/cybersecur

    #Cybersecurity #InfoSec #VulnManagement #ThreatIntel #BlueTeam #Ransomware

  12. New by me: Cybersecurity Weekly Roundup (Jan 17–24, 2026)

    This week’s theme is basically: the edge is lava. Cisco UC gets patched under active exploitation, Fortinet SSO abuse turns into rogue admins, GitLab fixes a 2FA bypass, Zoom patches a critical RCE path, and telnetd reminds us why legacy services deserve the void.

    I also added a quick Reality Check section at the end so you can sanity-check patching, logging, and “patched vs. clean” in one glance.

    kylereddoch.me/blog/cybersecur

    #Cybersecurity #InfoSec #VulnManagement #ThreatIntel #BlueTeam #Ransomware

  13. New by me: Cybersecurity Weekly Roundup (Jan 17–24, 2026)

    This week’s theme is basically: the edge is lava. Cisco UC gets patched under active exploitation, Fortinet SSO abuse turns into rogue admins, GitLab fixes a 2FA bypass, Zoom patches a critical RCE path, and telnetd reminds us why legacy services deserve the void.

    I also added a quick Reality Check section at the end so you can sanity-check patching, logging, and “patched vs. clean” in one glance.

    kylereddoch.me/blog/cybersecur

    #Cybersecurity #InfoSec #VulnManagement #ThreatIntel #BlueTeam #Ransomware

  14. Back in the saddle with my Cybersecurity Weekly Roundup for 2026.

    This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.

    15 stories, quick briefs, and my practitioner take:
    kylereddoch.me/blog/cybersecur

    #Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle

  15. Back in the saddle with my Cybersecurity Weekly Roundup for 2026.

    This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.

    15 stories, quick briefs, and my practitioner take:
    kylereddoch.me/blog/cybersecur

    #Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle

  16. Back in the saddle with my Cybersecurity Weekly Roundup for 2026.

    This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.

    15 stories, quick briefs, and my practitioner take:
    kylereddoch.me/blog/cybersecur

    #Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle

  17. Back in the saddle with my Cybersecurity Weekly Roundup for 2026.

    This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.

    15 stories, quick briefs, and my practitioner take:
    kylereddoch.me/blog/cybersecur

    #Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle

  18. Back in the saddle with my Cybersecurity Weekly Roundup for 2026.

    This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.

    15 stories, quick briefs, and my practitioner take:
    kylereddoch.me/blog/cybersecur

    #Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle

  19. Ever wish your vulnerability scanner could tell you what's really exploitable? Grype now includes CISA KEV & EPSS data, plus powerful vuln-db search! Prioritize smarter. 🎯 #Grype #Cybersecurity #VulnManagement
    anchore.com/blog/time-to-take-

  20. Ever wish your vulnerability scanner could tell you what's really exploitable? Grype now includes CISA KEV & EPSS data, plus powerful vuln-db search! Prioritize smarter. 🎯
    anchore.com/blog/time-to-take-

  21. Ever wish your vulnerability scanner could tell you what's really exploitable? Grype now includes CISA KEV & EPSS data, plus powerful vuln-db search! Prioritize smarter. 🎯 #Grype #Cybersecurity #VulnManagement
    anchore.com/blog/time-to-take-

  22. Ever wish your vulnerability scanner could tell you what's really exploitable? Grype now includes CISA KEV & EPSS data, plus powerful vuln-db search! Prioritize smarter. 🎯 #Grype #Cybersecurity #VulnManagement
    anchore.com/blog/time-to-take-

  23. Ever wish your vulnerability scanner could tell you what's really exploitable? Grype now includes CISA KEV & EPSS data, plus powerful vuln-db search! Prioritize smarter. 🎯 #Grype #Cybersecurity #VulnManagement
    anchore.com/blog/time-to-take-

  24. CISA BOD 23-01 released new compliance requirements regarding asset inventory and vulnerability management. Federal agencies must comply with this directive by April 2023, but all organizations are encouraged to incorporate the guidelines to strengthen the foundations of their security posture.

    How can you achieve compliance? Check out our blog for an overview of the new directive, and steps to meet (or even exceed!) the requirements:

    runzero.com/blog/cisa-bod-23-0

    #networksecurity #vulnmanagement #assetinventory #itcompliance

  25. CISA BOD 23-01 released new compliance requirements regarding asset inventory and vulnerability management. Federal agencies must comply with this directive by April 2023, but all organizations are encouraged to incorporate the guidelines to strengthen the foundations of their security posture.

    How can you achieve compliance? Check out our blog for an overview of the new directive, and steps to meet (or even exceed!) the requirements:

    runzero.com/blog/cisa-bod-23-0

    #networksecurity #vulnmanagement #assetinventory #itcompliance

  26. CISA BOD 23-01 released new compliance requirements regarding asset inventory and vulnerability management. Federal agencies must comply with this directive by April 2023, but all organizations are encouraged to incorporate the guidelines to strengthen the foundations of their security posture.

    How can you achieve compliance? Check out our blog for an overview of the new directive, and steps to meet (or even exceed!) the requirements:

    runzero.com/blog/cisa-bod-23-0

    #networksecurity #vulnmanagement #assetinventory #itcompliance