< ciso
brief />
Tag Banner

All news with #patch management tag

142 articles · page 2 of 8

Amazon OpenSearch Service extends upgrade runway

🔔 Amazon OpenSearch Service is extending security and OS patch coverage for several legacy Elasticsearch and OpenSearch engine versions through November 7, 2027, with an updated Extended Support surcharge schedule. Coverage includes Elasticsearch 1.5–7.8 (excluding 5.6 which remains covered through 2028), OpenSearch 1.0–1.2, and OpenSearch 2.3–2.9; domains on these versions will remain operational. New Standard and Extended Support windows and pricing for additional versions (Elasticsearch 6.8, 7.9, 7.10; OpenSearch 1.3, 2.11–2.19) are announced, with an Extended Support charge of $0.0065 per NIH in US East (N. Virginia). AWS recommends upgrading to the latest OpenSearch release for performance and security improvements.
read more →

Verification Closes the Loop on Risk Reduction

🔍 Organizations often equate remediation with reduced risk, but scanning and closed tickets don’t prove attackers can no longer achieve their objectives. A survey of 750 security leaders found only 30% validate that patches actually eliminate risk, while many rely on rescans. Real verification requires testing attack paths and outcomes, as shown by a firm whose retest reduced impacts from 251 to zero. Continuous verification, not just remediation, is the emerging standard.
read more →

Sysadmin AI Expectations Fall Short by 2026

🔍 Action1 surveyed over 1,000 sysadmins worldwide to compare 2024 expectations of AI and automation against the state of adoption in 2026. The report finds substantial shortfalls in areas such as patch management, monitoring, vulnerability prioritization and incident remediation, with predicted full automation far exceeding current implementation. Adoption is, however, growing selectively: many admins use AI for analysis and recommendations under supervised models while retaining authority over critical decisions. Concerns remain around privacy, accuracy, cost and job impact.
read more →

Risk‑Based Patching: Rethinking Vulnerability Prioritization

🛡️ CISA’s Binding Operational Directive (BOD) 26-04 shifts federal vulnerability management from uniform deadlines to risk-based remediation, prioritizing exposures most likely to be exploited. The directive recognizes that CVSS scores alone don’t capture exploitability, reachability or operational context. With AI accelerating attack lifecycles and expanding the attack surface via copilots and integrations, defenders must adopt continuous exposure mapping and validation. The article argues defenders need adversary-aware testing, business-aligned prioritization and a move from patch counts to exposure-centric strategies.
read more →

Microsoft’s three-day patching guidance raises risks

🛡️ Microsoft advises Windows administrators to apply security patches within three days, arguing that AI has accelerated vulnerability discovery and exploitation. Many enterprise teams, however, say the blanket three-day window is unrealistic given heavy testing, change control, and compatibility constraints. Experts recommend focusing rapid remediation on vulnerabilities with verified exploitation or credible proof-of-concept while using compensating controls and automation to manage broader exposure.
read more →

Eclypsium InfraTrust highlights top infrastructure fixes

🛡️ Eclypsium launched InfraTrust and a monthly InfraTrust Pulse to aggregate vendor infrastructure advisories and guide administrators on which flaws to patch first. The inaugural July 2026 Pulse tracked 61 advisories from 14 vendors, flagging six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities. The report emphasizes prioritizing flaws by exploitability, exposure, and real-world risk rather than CVSS alone.
read more →

Microsoft Ends Exchange 2016/2019 ESU Support in October

📢 Microsoft confirmed it will stop shipping security updates for Exchange Server 2016 and Exchange Server 2019 under the Extended Security Update (ESU) program in October 2026. The announcement follows a six-month extension granted in April 2026 and reiterates there will be no further extensions. Administrators are urged to upgrade to Exchange Server Subscription Edition or migrate to Exchange Online.
read more →

Ransomware Landscape Expands with New Groups Weekly

🛡️ The Black Kite Ransomware Report 2026 finds 146 active ransomware groups as of June 2026, up from 105 a year earlier, with 61 new groups emerging in 2026 alone. The study highlights a fragmented ecosystem where groups often have short lifespans—averaging 4.9 months—and a small number of operators still account for a large share of disclosed victims. Black Kite urges organizations to prioritize rapid patching of critical vulnerabilities and strengthen identity and vendor controls to mitigate attacks.
read more →

Weekly cyber recap: critical bugs, active exploits

⚠️ This week saw small inputs produce severe outcomes: unauthenticated RCEs in WordPress Core, SonicWall SMA zero-days exploited in the wild, OpenSSL DoS via an 11-byte payload, and a SharePoint RCE added to CISA's KEV catalog. Other notable items include the OkoBot malware framework targeting crypto wallets, the NadMesh botnet harvesting cloud keys, and a long list of high-priority CVEs that require immediate patching and investigation.
read more →

Microsoft works to resolve WSUS sync delays

🛠️ Microsoft is addressing a known issue that has caused Windows Server Update Services (WSUS) servers to experience prolonged synchronization times and timeouts, impacting the delivery of updates. The problem, with heightened impact since July 13, 2026, affects client and server platforms and prevents admins from deploying updates through WSUS or Configuration Manager. Mitigations have been deployed for new or rebuilt WSUS installations, and Microsoft is developing additional steps to remediate previously affected servers.
read more →

Windows Server 2022 to leave mainstream support in 2026

📰 Microsoft has announced that Windows Server 2022 will reach the end of mainstream support on October 13, 2026, and will transition to extended support with security updates through October 14, 2031. Customers are advised to plan upgrades to Windows Server 2025, the latest LTSC release available since November 2024. Microsoft also extended hotpatching for Datacenter: Azure Edition until October 2027 and highlighted lifecycle resources for planning migrations.
read more →

US launches Gold Eagle to accelerate vulnerability response

🛡️ The US government has launched Gold Eagle, a program led by CISA, the Treasury and the Department of Defense to speed detection and remediation of software vulnerabilities. The initiative, previewed in Executive Order 14409, aims to centralize reporting and reduce duplicate scans, likely using the VINCE platform with public-private participation. Experts warn the plan may not address the core remediation capacity and coordination issues that limit patch deployment.
read more →

CISOs Must Rethink Vulnerability Management Now

🔍 Security experts urge enterprises to shift from scheduled patch cycles to risk-based, continuous approaches such as just-in-time patching, citing AI-driven vulnerability discovery and exploitation that outpace traditional models. Vendors warn that AI tools can rapidly surface and validate flaws, widening the gap between discovery and remediation and overwhelming teams. Compensating controls like virtual patching can help, but they are stopgaps; organizations need continuous asset visibility, real-time exploitation intelligence, and prioritization based on exposure and exploitability.
read more →

Microsoft July 2026 Patch Tuesday: 570+ Vulnerabilities

🔒 July’s Patch Tuesday from Microsoft addressed an unprecedented number of vulnerabilities, with reports of 570–622 CVEs (620 if platform-level fixes are counted), plus hundreds in Chromium. The release includes many high-severity flaws — notably elevation of privilege and remote code execution bugs — with only three zero-days and 59 critical issues. Microsoft’s new summary-style advisories and its AI-powered MDASH scanning explain the surge, forcing organizations to reassess patch management and prioritization.
read more →

Microsoft issues unprecedented July Patch Tuesday updates

🛡️ Microsoft released updates for 570 CVEs on the July 14 Patch Tuesday, prompted by its use of agentic AI to discover flaws. The update batch includes three zero-days (two exploited in the wild) and a large number of elevation-of-privilege, remote code execution and information disclosure bugs. Experts warn this surge is becoming the new normal and urge organizations to adopt risk-based patching, attack-surface reduction and scalable processes.
read more →

Microsoft blocks update for Dell devices after shutdowns

🛠️ Microsoft is blocking the June Windows 11 update on some Dell systems after the KB5095093 preview update introduced an incompatibility with the Intel Innovation Platform Framework Processor Participant driver. Affected devices may show a yellow exclamation in Device Manager and experience unexpected shutdowns, poor performance, overheating, and battery drain. Microsoft is working with Dell and will pause KB5101650 distribution until a fix is released in the coming days.
read more →

Building the Business Case to Reduce Security Debt

🔍 Security leaders have improved visibility into vulnerabilities across applications and pipelines, yet many organizations face growing security debt as findings outpace remediation. Treat security debt like financial debt by measuring total and critical debt, setting reduction targets, and distinguishing acceptable versus unacceptable risk. Focus remediation capacity on exploitable vulnerabilities in crown-jewel systems, establish risk-focused metrics, and increase investment in remediation and automation to align security outcomes with business priorities.
read more →

Why clearinghouses aren’t the core solution

🛠️ Athena joins a crowded set of recently announced clearinghouses, but the author argues the clearinghouse itself is the least important part of the equation. Clearinghouses are simply pools of vulnerability data; the real value is in actuation — rebuilding, testing, signing, and delivering fixes where users will actually consume them. The rise of private pre-disclosure findings is a byproduct of models tested against running applications, and scale plus fast throughput matters more than the mere existence of another database.
read more →

SMB Cyber Readiness: Prioritize the Fundamentals

🔒 AI is reshaping attacker toolkits, but familiar failures—phishing, unpatched vulnerabilities, poor monitoring and weak passwords—remain the primary causes of incidents for SMBs. ESET telemetry and research show AI mainly amplifies these risks rather than replacing them with pervasive, real-time AI malware. Practical mitigations like patch management, identity protection, MFA, password managers and MDR services remain the most effective ways to improve readiness and resilience.
read more →

SageMaker HyperPod adds AMI versioning and auto-patch

🛠️ Amazon SageMaker HyperPod now reports AMI versions across clusters and can automatically apply backward-compatible security patches without disrupting workloads. Administrators can view AMI semantic versions (major.minor.patch), detect drift, and roll back to prior versions — preserving NVIDIA drivers, CUDA, and other bundled software — via the UpdateClusterSoftware API. Auto-patching is opt-in per instance group, applies only when nodes are idle, and avoids major/minor upgrades; it can be enabled through CreateCluster or UpdateCluster APIs. A new AMI support policy defines patch support timelines; both features are available for EKS-orchestrated HyperPod clusters in supported Regions.
read more →