Browsing Tag
Vulnerability Management
37 posts
Prioritizing, patching, and reducing exposure to software vulnerabilities.
Gunra Ransomware Puts VPN Gateways and Backups on the Same Incident List
A new FBI, CISA, NSA, Secret Service, DC3, and South Korean police advisory says Gunra ransomware affiliates are abusing exposed VPN and firewall paths, stealing cloud data, dumping credentials, and deleting backups before encryption. The useful response starts with edge-device patching, identity triage, immutable backups, and log review before recovery begins.
Microsoft’s August Patch Tuesday Makes AFD.sys the Patch Priority
Microsoft’s August 2026 Patch Tuesday fixes roughly 400 vulnerabilities, including an actively exploited AFD.sys privilege-escalation flaw. Windows teams should patch the exploited kernel bug first, then move quickly through exposed server roles, Office, SharePoint, and other high-risk systems.
N-able N-central Hotfix Turns RMM Servers Into an Incident Response Drill
N-able has released a second required hotfix for an actively exploited N-central authentication-bypass flaw. For MSPs and enterprise IT teams, the work is not only upgrading to 2026.3.1.10, but also checking Take Control sessions, Cloudflare Tunnel persistence, and downstream endpoints before treating the RMM platform as trusted again.
Rails Active Storage Flaw Turns Image Uploads Into a Secret-Rotation Drill
Rails maintainers patched CVE-2026-66066, a critical Active Storage flaw that can let attackers turn image uploads into arbitrary file reads and possible remote code execution. For affected teams, the job is not only upgrading Rails and libvips, but checking exposure windows and rotating secrets that may have been readable by the Rails process.
Chrome’s AI Bug Surge Makes Browser Restarts a Security Deadline
Google says Chrome 149 and 150 fixed 1,072 security bugs, more than the prior 23 milestones combined, as AI-assisted vulnerability discovery accelerates. The result is a push toward twice-weekly security releases, dynamic patching, and stricter enterprise browser-restart policies.
Water Utility Hacks Put Internet-Exposed PLCs on the Emergency List
Federal agencies say water and wastewater utilities in at least seven states reported attacks on internet-exposed PLCs, with some operations degraded. The Minnesota response shows why utilities need to remove controllers from public access, verify cellular modem exposure, and preserve manual operating capability.
Microsoft Project Perception Puts AI Agents on the Security Patch Path
Microsoft’s Project Perception enters public preview August 3 with MAI-Cyber-1-Flash inside MDASH, promising lower-cost vulnerability discovery and agentic security workflows. The important question is how much action enterprises should let AI security agents take.
Check Point SmartConsole Zero-Day Puts Firewall Management on Patch Deadline
Check Point has patched CVE-2026-16232, an actively exploited SmartConsole authentication bypass that can give attackers full administrator access to exposed Security Management servers. The urgent work is not only installing the Jumbo Hotfix, but also restricting Trusted Clients and checking management logs for signs of compromise.
Zoom’s Windows Account-Takeover Bug Makes Client Updates an Admin Priority
Zoom has patched CVE-2026-53412, a critical Windows client flaw that could let an unauthenticated attacker take over accounts over the network. The practical response is to verify Zoom Workplace and VDI client versions, not just assume auto-update has reached every endpoint.
Russian Router Campaign Turns SNMP Into a Critical Infrastructure Risk
NSA, CISA, the FBI, and 15 allied agencies warn that Russian FSB Center 16 actors are still compromising poorly configured routers across critical infrastructure. The practical fix starts with SNMPv3, blocked management protocols, patched firmware, and a hard look at exposed network devices.