< ciso
brief />
Tag Banner

All news with #vulnerability management tag

290 articles · page 2 of 15

CISA Adds Three Linux Kernel Flaws to KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation. The flaws include high-severity issues in the TLS receive path, ebtables SNAT ARP rewrite, and an AF_ALG socket race condition, with CVSS scores of 9.8, 8.8, and 7.8 respectively. Red Hat updated advisories on September 19, 2026, urging immediate remediation, and FCEB agencies are recommended to patch by September 21, 2026 under BOD 26-04.
read more →

CISA ends weekly vulnerability bulletin amid shift

🔒 CISA will discontinue its weekly vulnerability bulletin effective September 28, citing the new Binding Operational Directive (BOD 26-04) that requires prioritizing patches based on real-world exploitation rather than severity scores. The agency points to rising AI-driven threats and urges CISOs to rely more on vendors' security bulletins and updates. CISA will continue other channels like KEV, Cybersecurity Alerts and CVE catalogs to share critical information.
read more →

CISO’s Guide to Agentic Pentesting and Governance

🔍 A new free guide explains how autonomous AI agents are accelerating exploit weaponization and why annual pentests are no longer sufficient. It highlights industry data showing attackers now exploit vulnerabilities within days while median patch times lag weeks, and outlines vendor criteria—provable coverage, independent validation, browser-native agents—and governance controls to safely adopt agentic testing. The guide also covers budget math, compliance benefits, and a 90-day adoption roadmap.
read more →

Securing Unpatchable Systems Amid AI-Driven Finding

🔒 AI-assisted analysis is exposing decades of unpatched technical debt, leaving operational technology and legacy systems with known vulnerabilities that cannot easily be fixed. Inventory and visibility enable identification of at-risk devices, while network controls such as micro-segmentation, VLANs, ACLs, and NGFW/IPS provide compensating protections. Full air-gapping or data diodes can help but are often bypassed in practice, so defenders must assume imperfect isolation and apply layered controls and monitoring.
read more →

Homebrew 7.0.0 adds GUI and stronger security

🛠️ Homebrew 7.0.0 introduces a native BrewUI graphical interface for macOS 14 “Tahoe” and later, a built-in vulnerability scanner (brew vulns), and a Homebrew-specific advisory database. The release also tightens sandboxing by blocking default access to users' home directories and separates network downloads from offline installs. Users will see faster installs through concurrent download and install operations.
read more →

WordPress Adds Automated Plugin Security Reviews

🛡️ WordPress has introduced an automated security review for every plugin release before distribution via the WordPress.org update API to detect potential vulnerabilities and malicious code. The system, part of the Protect The Shire initiative, uses AI models and Jetpack Scan during a cooldown period to produce a security score; high-risk releases are blocked automatically. Developers are notified by email only when a release is blocked and must address findings to republish.
read more →

Microsoft September Patch Breaks Vulnerability Records

🔒 Microsoft’s September patch is unusually large, addressing a record ~972 vulnerabilities with 112 rated high critical. This follows consecutive months of escalating patch counts and coincides with industry concern over AI-accelerated discovery and exploitation of flaws. Vendors and organizations have warned the window for patching is narrowing, prompting a surge in rapid remediation efforts. Microsoft emphasizes immediate updates as attackers can quickly weaponize fixes through AI-assisted analysis.
read more →

Cloudflare launches Vulnerability Discovery and Remediation

🔍 Cloudflare is offering early access to Vulnerability Discovery and Remediation, a managed service that scans authorized customer codebases using OpenAI Daybreak models (including GPT-5.6 Cyber) to find and prioritize vulnerabilities. The service correlates source findings with production traffic, WAF signals, and security events to produce prioritized fixes and scoped WAF mitigations. Customers review proposed patches and rules before any change is made.
read more →

Google Mantis harness for scalable AI-driven fixes

🐞 Google released Mantis, an open-source framework that automates discovery, triage, reproduction, and patching of software vulnerabilities using AI. It combines agentic techniques with sandboxed vulnerability reproduction to reduce hallucinations and improve true-positive rates. Mantis analyzes repository history to build architectural and threat-model documentation and constructs hierarchical security summaries to preserve context while reducing token overhead. The project and examples are available on GitHub and include guidance for sandboxing and using the mantis-advise skill.
read more →

When the patch tsunami meets maintenance windows

🔧 AI-driven vulnerability discovery has collapsed discovery timelines from months to hours, but operational technology (OT) remediation still moves at plant speed. OT systems face physical, economic and contractual constraints that make rapid patching impractical, so defenders must prioritize containment, compensating controls and documented retirement plans. Preparation, vendor engagement and exercised surge plans are essential.
read more →

FSB warns of frontier AI risks to financial stability

⚠️ The Financial Stability Board (FSB) has warned that frontier AI models are reshaping the cyber-threat landscape and posing systemic risks to the global financial system. Chaired by Bank of England governor Andrew Bailey, the FSB urged firms and authorities to bolster vulnerability management, response and recovery capabilities, and to prepare for disruptions from concentrated third-party tech providers. The letter highlighted both the defensive potential of AI and the need for matched resilience and preparedness.
read more →

CTEM reshapes continuous exposure and risk management

🔍 Continuous Threat Exposure Management (CTEM) expands traditional vulnerability management by delivering ongoing visibility across endpoints, networks, identities, cloud, applications, and users. It emphasizes broader scope, exploitability validation, and accountability for remediation to close real attack vectors rather than just tally vulnerabilities. Automation and contextual intelligence are core to CTEM, but human oversight remains essential. Teams must overcome tool fragmentation, organizational silos, and cultural resistance to adopt CTEM as an operational model rather than a single product.
read more →

The patch window is collapsing: a new control plane

🔒 Modern vulnerability timelines are compressing as disclosures, exploit research, and AI-assisted workflows accelerate attacks while enterprise remediation remains slow due to operational constraints. Visibility and prioritization improve awareness but don’t reduce exposure quickly enough. Network-enforced, context-aware controls can provide rapid, targeted protections to limit exploitability during the interval between disclosure and patching.
read more →

Nucleus expands AI to detect exposures earlier

🛡️ Nucleus Security is rolling out Nucleus Helix, an AI Agent for natural-language interaction with security data and workflows, plus Nucleus Discover and expanded Nucleus Insights to accelerate early exposure detection and vulnerability intelligence. The company says these capabilities aim to shorten the gap between disclosure and scanner coverage by using environment context, prior scan data and real-time threat intelligence to identify likely affected systems before scanner plugins are available. Nucleus positions Helix as a reasoning assistant while deterministic automation executes approved workflows, and plans to release Helix and Discover in September with Insights available now.
read more →

AI-Driven Development Raises App Vulnerability Risk

🔍 Sonatype finds enterprise applications now contain 4.31 times more critical and high-severity vulnerabilities since AI-driven software development accelerated. The firm analyzed four years of development data and reports application creation has increased nearly fivefold in the AI era. While the median age of unresolved vulnerabilities has fallen 59%, indicating faster fixes, the growth in risk outpaces traditional security processes.
read more →

Study: Mid‑Market Firms Drive Majority of Ransomware Hits

📊 A Black Kite study finds that 73% of ransomware victims since 2023 were mid‑market firms with $10m–$1bn in revenue. The report analyzed 13,336 disclosed incidents and scanned 120,128 mid‑market companies, revealing that lower mid‑market organizations bore the largest share of attacks. Manufacturing is the sector most targeted, and common security gaps include KEVs, patching failures, high‑severity CVEs and deficient DMARC. Black Kite warns AI will compound the triage burden for small security teams.
read more →

ETSI Proposes 17 Standards for EU Cyber Resilience Act

🛡️ The European Telecommunications Standards Institute (ETSI) has launched an approval process for 17 draft cybersecurity standards to align products with the EU Cyber Resilience Act (CRA). The drafts, published on 13 August, define minimum security features—such as modern cryptography, secure-by-default settings, SBOMs and update capabilities—across network, edge, IoT and security product categories. Submissions from 41 member bodies are under public enquiry, with stakeholder comments invited through mid-September to mid-November 2026 and final standards expected by December 2026 ahead of CRA enforcement in December 2027.
read more →

Oracle launches Database Security Central free trial

🔒 Oracle has introduced Database Security Central, a tool that provides a centralized view of security risk across database environments and will be free through February 2027. It arrives as attackers increasingly target Oracle database flaws and following Oracle’s move to monthly patch releases. The tool assesses posture, detects configuration drift, highlights privileged access risks, monitors sensitive data access, and centralizes policy management and audit evidence collection.
read more →

AI-driven vulnerability discovery and its implications

🔍 A Black Hat USA 2026 keynote highlighted rapid growth in AI-assisted vulnerability discovery and the strain it places on defenders. Research from Arizona State University found that advanced models and workflows dramatically increased the number of bugs found, creating reporting and patching backlogs. This surge raises concerns about responsible disclosure, patching practices, and the potential for AI to eventually reduce new vulnerabilities as models and development processes improve.
read more →

Rethinking cyber defense as AI accelerates exploits

🔒 Microsoft warns that AI-driven tools are accelerating vulnerability discovery and exploit generation, making traditional reactive patching and detection-centric defenses insufficient. David Weston of Microsoft highlighted MDASH findings showing rapid, low-cost exploit generation and urged industry shifts toward memory-safe languages like Rust, proactive secure-by-construction methods, and AI-assisted remediation. The talk, delivered at Black Hat USA, framed resilience and prevention as the new priorities.
read more →