Skip to content

Vulnerability Management

12-hour patching window: what CERT-In’s advisory means for your internet-facing systems

If you run an internet-facing site or service, a new advisory from India’s CERT-In could change how you manage fixes. It calls for patching critical vulnerabilities within 12 hours of disclosure, where feasible, to slow down attackers who use AI… Read More »12-hour patching window: what CERT-In’s advisory means for your internet-facing systems

Microsoft patches 138 vulnerabilities in latest Patch Tuesday: what you need to do now

A routine Patch Tuesday turned into a reminder that staying up to date is not optional this year. Microsoft released a large set of security updates addressing 138 vulnerabilities across Windows and related services. Some fixes address critical remote code… Read More »Microsoft patches 138 vulnerabilities in latest Patch Tuesday: what you need to do now

Microsoft Patch Tuesday: 138 Vulnerabilities Fixed, Including DNS and Netlogon RCE Flaws

If you’re using Windows devices, today’s Patch Tuesday matters. Microsoft released a big round of fixes: 138 vulnerabilities addressed across Windows and related services, with notable critical flaws in DNS and Netlogon that could allow remote code execution. What happened… Read More »Microsoft Patch Tuesday: 138 Vulnerabilities Fixed, Including DNS and Netlogon RCE Flaws

Cisco Catalyst SD-WAN Controller authentication bypass: what it means and how to respond

If you manage a network with Cisco Catalyst SD-WAN hardware, a recently disclosed authentication bypass vulnerability is drawing attention from security teams. The short version: attackers could potentially gain admin access if systems aren’t patched, so it’s worth acting quickly… Read More »Cisco Catalyst SD-WAN Controller authentication bypass: what it means and how to respond

Microsoft May 2026 Patch Tuesday: What you need to know about the big vulnerability update

This week’s Patch Tuesday from Microsoft brings a broad set of vulnerability fixes across Windows, Office, and related services. If you’ve ever delayed applying updates, this is a good reminder that keeping software up to date is a practical, everyday… Read More »Microsoft May 2026 Patch Tuesday: What you need to know about the big vulnerability update

CISA adds Microsoft Exchange vulnerability to Known Exploited Vulnerabilities Catalog — practical steps to protect your mail server

Here’s the hard truth for anyone who runs Exchange: a small update to a government alert can save you from a big breach. A Microsoft Exchange Server cross-site scripting vulnerability (CVE-2026-42897) has been added to the CISA Known Exploited Vulnerabilities… Read More »CISA adds Microsoft Exchange vulnerability to Known Exploited Vulnerabilities Catalog — practical steps to protect your mail server

Critical Apache HTTP/2 flaw could cause DoS and remote code execution — what you should do now

A new Apache HTTP Server vulnerability in the HTTP/2 feature could let attackers take down or potentially compromise sites. If you run Apache with HTTP/2, this matters now more than ever. What happened Over the last 24 hours, researchers have… Read More »Critical Apache HTTP/2 flaw could cause DoS and remote code execution — what you should do now