< ciso
brief />
Tag Banner

All news with #patch management tag

142 articles

FBI removes contractor after PeopleSoft breach

🔒 The FBI removed an Accenture contractor after a data breach exposed personal details of employees tied to an unpatched third-party platform. FBI Cyber Division Assistant Director Brett Leatherman said the incident resulted from a security failure when a contractor did not apply a required patch. Reuters sources identified the platform as Oracle PeopleSoft, and said the contractor worked for Accenture on the system.
read more →

Enterprises face uncertainty after PeopleSoft breach claims

🛡️ The theft of FBI employee data tied to ShinyHunters and the shutdown of the FBI’s PeopleSoft jobs portal has raised alarm among enterprise users of PeopleSoft. Law enforcement has made arrests, but neither the FBI nor Oracle has clarified whether a new PeopleSoft zero-day caused the breach. Analysts urge immediate mitigations—patches, removing exposed management interfaces, and hunting for web shells—while warning that vendor silence and unconfirmed claims leave many organizations exposed.
read more →

EU Cyber Resilience Act reshapes vendor security baseline

🔒 The EU Cyber Resilience Act mandates 24-hour reporting for actively exploited vulnerabilities and severe incidents affecting products with digital elements, creating an EU-wide product-security law that applies even to non-EU companies. Experts warn the requirement effectively ends manual vulnerability triage, forcing vendors to automate linkage between SIEMs, SBOMs, KEV alerts, asset inventories, and other telemetry. The regulation is expected to elevate secure-by-design practices, test operational resilience, and reshape global technology markets much like GDPR did for data protection.
read more →

CISA Alerts: Active Exploits in WSO2, Adobe, SharePoint

⚠️ CISA warns that multiple critical and high-severity vulnerabilities in WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS are being actively exploited. Two critical flaws—CVE-2026-5430 in WSO2 and CVE-2026-71362 in Adobe Commerce—were added to the Known Exploited Vulnerabilities catalog with federal mitigation deadlines. Agencies must patch or mitigate by the specified dates, and organizations are urged to prioritize these fixes.
read more →

Microsoft to deprecate Windows Deployment Services

🖥️ Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. WDS, a successor to RIS, enabled network-based OS installs at scale but has seen partial deprecation steps since 2021, including removed features and reduced support for desktop OS deployment. Microsoft recommends migrating to alternatives such as Configuration Manager and notes current supported Server releases remain unaffected until removal.
read more →

Amazon RDS MySQL extended support for minors

🔔 Amazon RDS for MySQL announces Extended Support minor releases 5.7.44-rds.20260902 and 8.0.46-rds.20260908. RDS Extended Support offers up to three extra years of fixes for critical CVEs and bugs beyond standard support end dates. Customers can upgrade using Blue/Green Deployments, in-place upgrades, or restore from snapshots, and migrate with AWS Database Migration Service.
read more →

Microsoft fixes File History backup issue in September patch

🛠️ Microsoft addressed a known issue that caused the built-in File History backup to fail after installing September 2026 security updates. Affected systems experienced FileHistory.exe crashes, "Reconnect your drive" alerts despite attached drives, and missing previous file versions. The vendor says the fix is included in the September preview update for Windows 11, with broader availability on Patch Tuesday (October 13) for users who defer optional updates. Microsoft previously also issued out-of-band fixes for other September update regressions.
read more →

CISA ends weekly vulnerability bulletin amid shift

🔒 CISA will discontinue its weekly vulnerability bulletin effective September 28, citing the new Binding Operational Directive (BOD 26-04) that requires prioritizing patches based on real-world exploitation rather than severity scores. The agency points to rising AI-driven threats and urges CISOs to rely more on vendors' security bulletins and updates. CISA will continue other channels like KEV, Cybersecurity Alerts and CVE catalogs to share critical information.
read more →

Securing Unpatchable Systems Amid AI-Driven Finding

🔒 AI-assisted analysis is exposing decades of unpatched technical debt, leaving operational technology and legacy systems with known vulnerabilities that cannot easily be fixed. Inventory and visibility enable identification of at-risk devices, while network controls such as micro-segmentation, VLANs, ACLs, and NGFW/IPS provide compensating protections. Full air-gapping or data diodes can help but are often bypassed in practice, so defenders must assume imperfect isolation and apply layered controls and monitoring.
read more →

Windows Server 2022 to leave mainstream support

🔔 Microsoft confirmed that Windows Server 2022 will reach end of mainstream support on October 13, 2026, and then transition into extended support through October 14, 2031. The October 2026 security update will be the last release under mainstream support. Hotpatching for Datacenter: Azure Edition is extended until October 2027. Administrators are advised to plan upgrades to Windows Server 2025 to remain fully supported.
read more →

When the patch tsunami meets maintenance windows

🔧 AI-driven vulnerability discovery has collapsed discovery timelines from months to hours, but operational technology (OT) remediation still moves at plant speed. OT systems face physical, economic and contractual constraints that make rapid patching impractical, so defenders must prioritize containment, compensating controls and documented retirement plans. Preparation, vendor engagement and exercised surge plans are essential.
read more →

Microsoft: Patch Window Is Collapsing, Adopt Network Controls

🛡️ Microsoft warns that the interval between vulnerability disclosure and exploitation is rapidly shrinking, outpacing many organizations' ability to safely deploy patches. Igor Sakhnov, Azure Networking GM, urges a shift to network-level controls as a temporary control plane to limit exposure while patches are tested and rolled out. Analysts note the model suits mature cloud environments but faces practical challenges such as poor asset visibility and risks that temporary measures become permanent liabilities.
read more →

The patch window is collapsing: a new control plane

🔒 Modern vulnerability timelines are compressing as disclosures, exploit research, and AI-assisted workflows accelerate attacks while enterprise remediation remains slow due to operational constraints. Visibility and prioritization improve awareness but don’t reduce exposure quickly enough. Network-enforced, context-aware controls can provide rapid, targeted protections to limit exploitability during the interval between disclosure and patching.
read more →

Amazon RDS for PostgreSQL adds latest minor versions

🔔 Amazon RDS for PostgreSQL now supports minor releases 18.6, 17.11, 16.15, 15.19, and 14.24. We recommend upgrading to these versions to address prior CVEs and to benefit from community bug fixes and improvements. You can apply upgrades during scheduled maintenance with automatic minor version upgrades, and orchestrate phased rollouts using AWS Organizations Upgrade Rollout Policy. Use Blue/Green deployments to minimize downtime for upgrades.
read more →

Windows 11 24H2 Home and Pro reach end of support

🛡️ Microsoft warned that Windows 11 version 24H2 Home and Pro editions will stop receiving security and preview updates on October 13, 2026. Enterprise and Education editions of 24H2 remain supported until October 2027, and Microsoft recommends upgrading to Windows 11 25H2, widely available since September 2024. unmanaged Home and Pro devices will auto-upgrade to 25H2, though users can postpone restarts; administrators should use Settings > Windows Update to check availability.
read more →

Windows Server 2022 Approaches Mainstream End Date

📢 Microsoft reminded administrators that Windows Server 2022 will reach end of mainstream support on October 13, 2026, and will transition to extended support with monthly security updates through October 14, 2031. The company urged customers to plan upgrades to Windows Server 2025, available since November 2024, and to begin deployment testing early. Microsoft also extended hotpatching for Datacenter: Azure Edition until October 2027 and noted related lifecycle dates for other products.
read more →

ICO reprimands ACRO after significant data breach

🔒 The UK's Information Commissioner’s Office (ICO) has issued a reprimand to the Criminal Records Office (ACRO) after a 2023 breach affected 10,920 people. A hacker accessed ACRO’s website and Kentico CMS between August 2022 and March 2023, exposing highly sensitive personal and criminal data. The ICO found failings in patch management and security monitoring, noting unreviewed malware alerts and unclear patch responsibilities. ACRO has taken remedial steps including decommissioning compromised infrastructure and improving monitoring.
read more →

Microsoft patches 400 vulnerabilities in August update

🔒 Microsoft released its August Patch Tuesday addressing 400 CVEs, including one actively exploited zero-day and two publicly disclosed zero-days. The exploited flaw, CVE-2026-68820, is a use-after-free issue in the Windows Ancillary Function Driver for WinSock that can allow local low-privileged attackers to gain system privileges. Other notable fixes include EoP issues in the User Profile Service (CVE-2026-62832) and a Windows Container Isolation FS Filter Driver tampering flaw (CVE-2026-72971). Organizations without automated, risk-based patching will face challenges prioritizing these updates.
read more →

Legacy software bugs that lingered for decades

📰 This article reviews a series of long-dormant vulnerabilities—some more than 30 years old—unearthed and finally patched in recent years. It highlights how AI-powered analysis and deep inspections have accelerated the discovery of latent flaws across widely used projects such as libpng, PostgreSQL, Nginx, and the Linux KVM module. The piece explains the origins, exploitation risk, and remediation status of each bug, emphasizing supply-chain and infrastructure impacts and urging administrators to apply available patches.
read more →

Human oversight critical as AI patching tools miss risks

🔍 Researchers from 1Password evaluated AI-generated patches from ChatGPT-5.5 and Claude Opus 4.8 and found many fixes syntactically correct but operationally flawed. The study examined 6 recent CVEs and 6,080 generated patches, revealing only ~26% fully remediated issues without altering behavior. The team found numerous cases where patches left attack paths open, introduced new vulnerabilities, or merely blocked the proof-of-concept without fixing root causes.
read more →