Why the 'patchpocalypse' demands immediate isolation PARTNER CONTENT: Attackers automated, but your 30-day patch window didn't
PATCHES Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update One bug disabled the security service on restart, another blocked installation on hardened RHEL systems
OS PLATFORMS Microsoft extends extended updates for Windows 10 in the most muted way imaginable Tiny tweak to support page reveals consumers can purchase another year of patch protection
PATCHES Cisco SD-WAN make-me-root bug under attack Second Catalyst SD-WAN Manager flaw exploited as an 0-day this month
Patches Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 Remote, unauthenticated RCE with root privileges is about as bad as it gets
PATCHES AI is making Patch Tuesday (kinda) fun again Unless you're an admin or vulnerability manager – then you're totally screwed
Security Anthropic to release Mythos-class models to the public AI flaw-finder still under lock and key for now while company figures out guardrails, but extends access to more users including governments
Security Clear your calendar, Drupal user: You have a critically urgent patch to install The org’s staying mum on the details, but Wednesday’s fixes reach back to unsupported 8.9 branches
Patches Patch time for Cisco SD-WAN admins as vendor drops yet another make-me-admin zero-day CISA hands feds super-tight deadline for this perfect-10, actively exploited flaw
patches Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Palo Alto Networks found and fixed 75 flaws this month, up from its usual five
Security Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs The good news: no 0-days. The bad news: busy week ahead for Microsoft admins
Cyber-crime ShinyHunters claims dump puts 119K Vimeo emails in the wild Vimeo points finger at analytics supplier Anodot, says no logins or card data were touched
Patches Google's fix for critical Gemini CLI bug might break your CI/CD pipelines This CVSS 10.0 RCE vuln has been patched, automatically for some, so better check those workflows
Patches Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day Emergency patches out now for those managing the millions of domains assumed to be affected
Patches Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack Second try's a charm?
Patches Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP No reports of active exploitation (yet)
Patches Ancient Excel bug comes out of retirement for active attacks Vuln old enough to drive lands on CISA's exploited list
Patches Microsoft's massive Patch Tuesday: It's raining bugs One CVE under attack, one already disclosed by angry bug hunter, and 163 more
Patches Zombie Microsoft bugs rise from the dead, pave way for crims and ransomware scum One was patched almost 14 years ago
Patches Attackers exploited this critical FortiClient EMS bug as a 0-day CISA added the flaw to KEV after Fortinet confirmed exploitation in the wild
Patches Citrix NetScaler bug exploited in days, may be multiple flaws in a trench coat Researchers say attackers are already looting vulnerable boxes
Patches Google rushes Chrome update fixing two zero-days already under attack Skia graphics lib and V8 JavaScript engine brings browser's tally of actively exploited bugs to three in 2026
Patches Patch these 4 critical, make-me-root SolarWinds bugs ASAP SolarWinds + file transfer software = what attackers' dreams are made of
Patches CISA gives federal agencies three days to patch actively exploited Dell bug Hardcoded credential flaw in RecoverPoint already abused in espionage campaign
Patches Attackers finally get around to exploiting critical Microsoft bug from 2024 As if admins haven't had enough to do this week
Patches Microsoft's Valentine's gift to admins: 6 exploited zero-day fixes Roses are red, violets are blue ... now get patching
Patches Critical React Native Metro dev server bug under attack as researchers scream into the void Too slow react-ion time
Patches Patch or die: VMware vCenter Server bug fixed in 2024 under attack today If you skipped it back then, now’s a very good time
Patches Ancient telnet bug happily hands out root to attackers Critical vuln flew under the radar for a decade
Patches Cloudflare whacks WAF bypass bug that opened side door for attackers ACME validation had a challenge-request hole
Patches Anthropic quietly fixed flaws in its Git MCP server that allowed for remote code execution Prompt injection for the win
Patches Sorry Dave, I’m afraid I can’t do that! PCs refuse to shut down after Microsoft patch Microsoft claims it's a Secure Launch bug
Patches Cisco finally fixes max-severity bug under active attack for weeks This is a threat to security - and to the weekend for some unlucky netadmins
Patches Popular Python libraries used in Hugging Face models subject to poisoned metadata attack The open-source libraries were created by Salesforce, Nvidia, and Apple with a Swiss group
Patches Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit No reports of active exploitation … yet
Patches Maximum-severity n8n flaw lets randos run your automation server Unauthenticated RCE means anyone on the network can seize full control
Patches Logitech macOS mouse mayhem traced to expired dev certificate Company says it dropped the ball, apologizes for wasting people's time
Patches An early end to the holidays: 'Heartbleed of MongoDB' is now under active exploit You didn't think you'd get to enjoy your time off without a major cybersecurity incident, did you?
Patches Microsoft rushes an out-of-band update for Message Queuing bug Redmond gets in early for the twelve whoopsies of Christmas
Patches HPE tells customers to patch fast as OneView RCE bug scores a perfect 10 Maximum-severity vuln lets unauthenticated attackers execute code on trusted infra management platform
Patches Apple, Google forced to issue emergency 0-day patches Both admit attackers were already exploiting the bugs, with scant detail and hints of spyware-grade abuse
Patches Microsoft RasMan DoS 0-day gets unofficial patch - and a working exploit Exploit hasn't been picked up by any malware detection engines, CEO tells The Reg
Patches New React vulns leak secrets, invite DoS attacks And the earlier React2Shell patch is vulnerable
Patches Microsoft quietly shuts down Windows shortcut flaw after years of espionage abuse Silent Patch Tuesday mitigation ends ability to hide malicious commands in .lnk files
Patches Two Android 0-day bugs disclosed and fixed, plus 105 more to patch Christmas comes early for attackers this year
Patches Fortinet finally cops to critical make-me-admin bug under active exploitation More than a month after PoC made public
Patches Cisco warns of 'new attack variant' battering firewalls under exploit for 6 months Plus 2 new critical vulns - patch now
Patches Docker Compose vulnerability opens door to host-level writes – patch pronto Windows Desktop installer also fixed after DLL hijack flaw rated 8.8 severity
Patches Microsoft drops surprise Windows Server patch before weekend downtime You didn't have plans, did you?
Patches Forking confusing: Vulnerable Rust crate exposes uv Python packager Forks of forks of forks, but which ones are patched?
Patches Oracle rushes out another emergency E-Business Suite patch as Clop fallout widens Latest in a long line of EBS flaws leta miscreants remotely compromise enterprise systems to pinch sensitive data
Patches Warnings about Cisco vulns under active exploit are falling on deaf ears 50,000 firewall devices still exposed
Patches ‘An attacker's playground:’ Crims exploit GoAnywhere perfect-10 bug Researchers say tens of thousands of instances remain publicly reachable
Patches UK and US security agencies order urgent fixes as Cisco firewall bugs exploited in wild CISA gives feds 24 hours to patch, NCSC urges rapid action as flaws linked to ArcaneDoor spies
Patches SonicWall releases rootkit-busting firmware update following wave of attacks Security vendor's no good, very bad week year
Patches Third time's the charm? SolarWinds (again) patches critical Web Help Desk RCE Or maybe 3 strikes, you're out?
Patches Ding ding: Fortra rings the perfect-10 bell over latest GoAnywhere MFT bug Outside experts say the vulnerability has probably already been exploited
Patches OpenAI plugs ShadowLeak bug in ChatGPT that let miscreants raid inboxes Radware says flaw enabled hidden email prompts to trick Deep Research agent into exfiltrating sensitive data
Patches Google pushes emergency patch for Chrome 0-day – check your browser version now Sixth such Chrome flaw this year spotted by the Chocolate Factory, already in play
Patches Apple 0-day likely used in spy attacks affected devices as old as iPhone 8 May have been used in 'extremely sophisticated' attacks against 'specific targeted individuals'
Patches Samsung fixes Android 0-day that may have been used to spy on WhatsApp messages A similar vuln on Apple devices was used against 'specific targeted users'
Patches Critical, make-me-super-user SAP S/4HANA bug under active exploitation 9.9-rated flaw on the loose, so patch now
Patches Android drops mega patch bomb - 120 fixes, two already exploited September bundle the largest this year, and possibly the most serious
Patches Frostbyte10 bugs put thousands of refrigerators at major grocery chains at risk Major flaws uncovered in Copeland controllers: Patch now
Patches Thousands of Citrix NetScaler boxes still sitting ducks despite patches Shadowserver counts more than 13,000 appliances still wide open – including thousands in US, Germany, and UK
Patches Apple rushes out fix for active zero-day in iOS and macOS Another 'extremely sophisticated' exploit chewing at Cupertino's walled garden
Patches Amazon quietly fixed Q Developer flaws that made AI agent vulnerable to prompt injection, RCE Move along, nothing to see here
Patches Commvault releases patches for two nasty bug chains after exploits proven Researchers disclosing their findings said 'it's as bad as it sounds'
Patches Don't want drive-by Ollama attackers snooping on your local chats? Patch now Reconfigure local app settings via a 'simple' POST request
Patches Cisco's Secure Firewall Management Center now not-so secure, springs a CVSS 10 RCE hole Switchzilla's summer of perfect 10s
Patches Fortinet discloses critical bug with working exploit code amid surge in brute-force attempts If there's smoke?
Patches Microsoft, CISA warn yet another Exchange server bug can lead to 'total domain compromise' No reported in-the-wild exploits…yet
Patches Patch now: Millions of Dell PCs with Broadcom chips vulnerable to attack Psst, wanna steal someone's biometrics?
Patches Chained bugs in Nvidia's Triton Inference Server lead to full system compromise Wiz Research details flaws in Python backend that expose AI models and enable remote code execution
Patches Microsoft spotlights Apple bug patched in March as SharePoint exploits continue Look over there!
Patches Microsoft patches critical SharePoint 2016 zero-days amid active exploits Admins urged to rotate machine keys, restart IIS after emergency fix
Patches Another massive security snafu hits Microsoft, but don't expect it to stick Move along, nothing to see here
Patches Watch out, another max-severity, make-me-root Cisco bug on the loose Three perfect 10s in the last month - ISE, ISE, baby
Patches Microsoft offers vintage Exchange and Skype server users six more months of security updates It looks like enough of you are struggling to migrate that Redmond is willing to help out – for a price that might buy nothing
Patches CVSS 10 RCE in Wing FTP exploited within 24 hours, security researchers warn Intruders looked up how to use curl mid-attack - rookie errors kept damage minimal
Patches Microsoft enjoys first Patch Tuesday of 2025 with no active exploits Sure, 130 fixes were sent out, but bask in the security goodness
Patches CitrixBleed 2 exploits are on the loose as security researchers yell and wave their hands NetScaler vendor issued a patch but otherwise, stony silence
Patches Cisco scores a perfect 10 - sadly for a critical flaw in its comms platform The second max score this week for Netzilla - not a good look
Patches CISA warns the Signal clone used by natsec staffers is being attacked, so patch now Two flaws in TeleMessage are 'frequent attack vectors for malicious cyber actors'
Patches Microsoft admits to Intune forgetfulness Customizations not saved with security baseline policy update
Patches Citrix bleeds again: This time a zero-day exploited - patch now Two emergency patches issued in two weeks
Patches Don't panic, but it's only a matter of time before critical 'CitrixBleed 2' is under attack Why are you even reading this story? Patch now!
Patches Choose your own Patch Tuesday adventure: Start with six zero-day fixes, or six critical flaws