Patching stories
A four-day shutdown at a UK energy site has intensified warnings that ageing infrastructure leaves critical national systems exposed to wider disruption.
Rising disclosure volumes are forcing security teams to predict which flaws attackers will exploit as FIRST broadens its vulnerability conference in Luxembourg.
As attackers use AI to speed up phishing and malware, companies are being told that multi-factor authentication and patching matter more than ever.
Patching is urgent for Cudy WR3000 rev 2.0 routers, as public code shows how two flaws can let attackers gain root command execution.
Security teams could cut exposure faster as the model helps rank exploitable flaws and apply temporary defences before vendor fixes arrive.
Basic security lapses are leaving web apps exposed, with Barracuda saying routine misconfigurations account for most of 20 flaws per site.
Owners of certain Cudy WR3000 routers face a root takeover risk unless they update firmware to patch two chained flaws.
Ransomware groups are keeping up pressure on smaller rivals, with mid-market firms still making up 73% of victims across North America and Europe.
Manufacturers face credential theft and engineering-data loss after a tailored Windchill web shell tied to Clop exploited CVE-2026-12569.
Defenders face a shrinking window to act, after Rapid7 found 62% of newly exploited flaws could be attacked without authentication or user interaction.
Unauthorised access could let attackers send arbitrary commands to spacecraft and instruments via NASA's AIT-GUI console, now fixed in version 2.5.2.
Fast-moving exploits are shrinking patch windows to hours, making network segmentation vital for protecting cameras, medical devices and other connected assets.
Patch backlogs are leaving organisations exposed, with 85 high-impact flaws flagged across Australia and New Zealand, up 44% in July.
Stolen credentials and AI-generated phishing are accelerating attacks, as Flashpoint tracked 22 million illicit discussions and 7.4 million infected hosts.
Security teams could gain more useful risk signals as NIST weighs changes to the National Vulnerability Database amid surging flaw volumes and AI use.
Support teams can now handle device context and remediation in one place as PDQ widens its Windows and macOS management tools.
Mid-market customers in Australia could see faster fixes and fewer tickets as blueAPACHE folds ControlUp ONE into its managed services.
Hidden endpoint blind spots are leaving Southeast Asian firms exposed to downtime, data leaks and losses above USD $1 million.
IT teams can now issue endpoint tasks from AI assistants, with PDQ keeping permissions, authentication and audit trails intact.
Supermarkets and hospitals could face spoiled stock and medicines after flaws in two widely used refrigeration controller platforms were disclosed.