#patching

[ follow ]
fromComputerworld
3 days ago

Cyber agencies produce 'long overdue' best practices for securing Microsoft Exchange Server

The guidance states admins should treat on-prem Exchange servers as being "under imminent threat," and itemizes key practices for admins: First, it notes, "the most effective defense against exploitation is ensuring all Exchange servers are running the latest version and Cumulative Update (CU)"; It points out that Microsoft Exchange Server Subscription Edition (SE) is the sole supported on-premises version of Exchange, since Microsoft ended support for previous versions on October 14, 2025; It urges admins to ensure Microsoft's Emergency Mitigation Service remains enabled for delivery of interim mitigations; Maintaining a security baseline enables administrators to identify non-conforming systems and those with incorrect security configurations, as well as allowing them to perform rapid remediation that reduces the attack surface available to an adversary;
Information security
fromIT Pro
2 weeks ago

Threat actors are exploiting flaws more quickly - here's what business leaders should do

In July, Microsoft fixed a flaw in its file sharing service SharePoint that was already being exploited by attackers. Later that month, Microsoft warned that hackers were making use of the zero-day to distribute ransomware, adding even more risk to the serious vulnerability. The SharePoint flaw is just one example of attackers becoming faster at exploiting vulnerabilities before they can be properly addressed by vendors and patched by organizations.
Information security
Information security
fromArs Technica
1 month ago

As hackers exploit one high-severity SAP flaw, company warns of 3 more

CVE-2025-42957 allows low-privileged SAP users to achieve near-complete system compromise remotely, risking fraud, data theft, espionage, and ransomware.
Information security
fromTheregister
2 months ago

Thousands of Citrix NetScaler boxes still sitting ducks

Thousands of Citrix NetScaler appliances remain unpatched against critical CVE-2025-7775, enabling active exploitation and widespread risk despite vendor fixes.
fromTechzine Global
3 months ago

SharePoint vulnerability actively exploited: Microsoft rolls out emergency patches

Microsoft has issued an urgent warning about a critical zero-day vulnerability in SharePoint Server, registered as CVE-2025-53770, allowing remote code execution.
Privacy professionals
Information security
fromSecuritymagazine
6 months ago

Incomplete NVIDIA patch could leave AI infrastructure and data at risk

NVIDIA's security update is inadequate, leaving systems exposed to critical vulnerabilities that could lead to serious breaches and operational issues.
[ Load more ]