vulnerability management
132 stories on vulnerability management, newest first, from 140 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- CISA Warns of Actively Exploited WordPress Vulnerability
- CISA Flags Active Exploitation of SharePoint and MikroTik Router Flaws
- Actively Exploited Roundcube Webmail Flaw Puts Email Credentials at Risk
- ACSC Flags 'High Alert' Over AI Agents Acting Without Authorisation
- Ubuntu Moves to Weekly Kernel Patches as AI-Driven Bug Discovery Overwhelms Defenders
-
Wiz Recognised as a Leader in Forrester's Proactive Security Platforms Report
Also covered by CrowdStrike
- AI-Powered 'Scan for Good' Initiative Finds and Fixes Hundreds of Public Sector Security Gaps
- CISA Pushes for a 'Quality Era' in Vulnerability Reporting as CVE Volumes Surge
- CISA Flags Actively Exploited Flaws in WSO2 and Adobe Commerce/Magento
- CISA Unveils Plan to Improve Quality of Global Vulnerability Database
- F5 BIG-IP Zero-Day Under Active Attack: Patch Now, CISA Warns
- New Benchmark Puts AI Security Agents to the Test
- Check Point Warns of Actively Exploited Zero-Day in Security Management Server
- CISA Flags Actively Exploited Flaws in Check Point, Arista and F5 Products
- Government VPN Breach Exposes 246,000 Records: Lessons for Small Business
- AI-Discovered Bugs Pile Up, But Attackers Aren't Rushing to Exploit Them
- Zyxel Network Switch Flaw Added to US Government's Actively Exploited Vulnerability List
- Record Data Breaches Highlight Australia's Network Security Gap
- Microsoft Fixes Maximum-Severity Flaw in Azure AI Foundry
- CISA Flags Two Actively Exploited Linux Kernel Flaws
- CISA Shifts Away from Weekly Vulnerability Bulletins in Favor of Risk-Based Alerts
- Cisco Warns of Second Actively Exploited Zero-Day in Two Days
- Critical Check Point Flaw Lets Attackers Take Over Management Servers Without Logging In
- New Webinar: How to Tell If a New Vulnerability Can Actually Be Used Against You
- Attackers Exploit New Flaws in Days, Businesses Take Weeks to Patch: Why Pentesting Needs to Change
- CISA to Retire Weekly Vulnerability Bulletin as It Shifts to Risk-Based Approach
- Google Pixel Phones Hit by Zero-Click Attack: Update Now
- CISA Flags Actively Exploited Google Pixel Vulnerability
- Why Threat Intelligence Alone Isn't Stopping Breaches
- AI Is Finding More Software Flaws Than Ever, But What About Systems You Can't Patch?
- AI Bug-Hunters Are Causing Patching Pain Now, But Could Ease the Load by 2027
- September Patch Tuesday: Microsoft Fixes 973 Vulnerabilities in Massive Update
- Apple Issues Record-Breaking Security Update: Over 260 Flaws Fixed
- Microsoft Rushes Out Emergency Fixes After Huge Patch Tuesday
- Maximum-Severity GitLab Flaw Threatens Software Supply Chains
- Check Point Flags New Protections for Metabase, Windows, GitLab and Chrome Vulnerabilities
- CISA Flags Five Actively Exploited Flaws in Artifactory, ScreenConnect and RouterOS
- CISA Flags Active Exploitation of JFrog Artifactory and ConnectWise ScreenConnect Flaws
- Why a 'Critical' Vulnerability Alert Might Not Be Your Real Risk
- Hackers Chain Two JFrog Artifactory Bugs to Seize Admin Control and Plant Backdoors
- Cisco Firewall Bugs Under Active Attack: Qilin Ransomware and State-Backed Hackers Exploiting Two Flaws
- Mathspace Breach Exposes Data of Over 1 Million Students, Parents and Teachers
- CISA Warns of Active Exploitation of Two MikroTik RouterOS Vulnerabilities
- CISA Warns of Active Attacks on Cisco, Citrix and Fortinet Flaws, Sets Patch Deadline
- Vulnerability Discovery Is Outpacing Fixes, Research Shows
- CISA Flags Four Actively Exploited Flaws in Fortinet, Citrix, Cisco and Chrome
- Webinar Tackles the Toughest Question After a New CVE: Are We Exposed?
- Microsoft's September Patch Tuesday Sets Record With 974 Security Fixes
- SAP Rushes Fix for Maximum-Severity 'Overpass' Flaw Affecting 10,000+ Systems
-
Microsoft's Biggest Patch Tuesday Ever: 974 Flaws Fixed, Two Already Under Attack
Also covered by Cisco Talos, Krebs on Security, CrowdStrike
- Microsoft's Record Patch Tuesday: Two Actively Exploited Flaws Demand Urgent Attention
- Microsoft's Latest Patch Tuesday Breaks Records: 974 Vulnerabilities Fixed
- Zero-Day Flaw Found in CrowdStrike Falcon Sensor Allows Privilege Escalation
- AI-Powered Bug Hunting Is Flooding Vendors With Vulnerability Reports
- Plex Patches Multiple Undisclosed Security Flaws — Update Now
- Google Patches Actively Exploited Chrome Zero-Day: Update Now
- OpenAI's New GPT-6 Astra Can Hunt Exploits at Expert Level — Here's What SMBs Need to Know
- Cisco Patches Critical Flaw Allowing Root Access on Nexus 9000 Switches
- Critical Flaw in Popular WordPress Migration Plugin Puts 3 Million Sites at Risk
- CISA Flags Seven Actively Exploited Vulnerabilities Used to Plant Reverse Shells and Crypto Miners
- Why Fixing Vulnerabilities in Code Beats Patching in Production
- AI-Driven Vulnerability Surge May Be Less Daunting Than Expected, Research Finds
- Rockwell Automation Fixes Over a Dozen Security Flaws in Industrial Software
- CISA Flags Seven Actively Exploited Vulnerabilities Businesses Should Patch Now
- Unpatched ownCloud Flaw Exposes Philippines Nuclear Agency Data
- Vendor Launches Real-Time Vulnerability Scanning as Attackers Exploit Flaws Within Hours
- CISA Warns: PaperCut Vulnerabilities Now Under Active Attack
- Weekly Threat Recap: Backdoored Routers, Rogue AI Agents, and Old Bugs Still Doing Damage
- Weekly Roundup: Log4j Scare Resurfaces, Iranian Hacker Sanctions, and Other Security News
- AI Agents Used to Exploit Linux Kernel Flaw on OpenAI's Own Systems
- AI Is Helping Hackers Move Faster Than Old-School Security Tools Can Keep Up
- Black Hat 2026: AI Agents and Vulnerability Reporting Take Centre Stage
- Weekly Threat Roundup: Massive IoT Botnet, Water System Attacks, and Fake Software Traps SMBs Should Know About
- Visa Expands AI Tool to Automatically Fix Cyber Vulnerabilities
- AI Is Speeding Up Cyberattacks — Is Your Security Ready to Keep Pace?
- US Cybersecurity Agency Flags Six Actively Exploited Vulnerabilities, Including Citrix NetScaler Flaw
- CISA Report: Most Cyberattacks Exploit Basic, Known Software Flaws
- CISA Flags Actively Exploited Gitea Vulnerability — Patch Now
- AI Is Reshaping Vulnerability Management for Businesses of All Sizes
- Cybercriminals Get Smarter: AI, Trusted Tools and Old Vulnerabilities Fuel New Wave of Attacks
- AI Is Finding Security Flaws Faster Than Businesses Can Fix Them
- AI Is Speeding Up Cyberattacks - Why Patching Alone Won't Save Your Business
- AI Model Update Boosts Automated Vulnerability Scanning for Businesses
- Cisco Issues Urgent Patches for Nine Flaws, Five Rated Maximum Severity
-
Microsoft Releases 22 New Security Patches — Update Now
Also covered by Security Week
- Citrix Patches Critical Authentication Bypass Flaw in NetScaler Products
- Atlassian and Splunk Release Fixes for Dozens of Serious Security Flaws
- CISA Flags Two Actively Exploited TrueConf Server Vulnerabilities
- Cisco Fixes Critical Security Flaws in Crosswork and Secure Workload Products
- CISA Flags Four Critical Flaws Under Active Attack — Patch Now
- Google and Mozilla Release Critical Security Updates for Chrome and Firefox
- Google Uses AI-Powered Code Review to Outpace Attackers Exploiting Stolen Source Code
- Why 'Patch Everything Eventually' No Longer Works Against Today's Cyber Threats
- CISA Flags Four Actively Exploited Bugs in Microsoft, VMware and Apple Products
- Critical GitLab Flaw Could Let Hackers Delete Projects Without Logging In
- Weekly Threat Recap: Old Bugs, Exposed Services and Browser Hijacks Keep Costing Businesses
- CISA Flags Actively Exploited Flaw in Ray-Project AI Framework
- AI Is Fueling a Flood of New Vulnerabilities—Can AI Also Help Fix It?
- AI Security Sweep Flags Nearly 8,000 Potential Flaws in Bitcoin Software
- Siemens Building Controllers Vulnerable to Network-Based Disruption
- Intel and AMD Patch Over 80 Security Flaws in Latest Updates
- SonicWall Fixes Critical Flaws in Discontinued Management Platform
-
Microsoft's August 2026 Patch Tuesday Fixes 421 Vulnerabilities, 62 Critical
Also covered by Security Week
- Microsoft's August Patch Tuesday Brings Another Wave of Security Fixes
-
Microsoft's Latest Patch Batch Fixes Nearly 400 Security Flaws — One Already Under Attack
Also covered by The Hacker News
- Gunra Ransomware Gang Bypasses MFA by Exploiting Old Fortinet Vulnerabilities
- Adobe Sounds Alarm on Critical Flaws in ColdFusion and Campaign Classic
- SAP Issues Urgent Patches for Critical Security Flaws
- Three Actively Exploited Vulnerabilities Added to CISA's Critical List — Cisco, Microsoft and Metabase Affected
- Critical Security Flaws Found in Mira Hormone Monitor Devices and App
- Gunra Ransomware Targets Fortinet and Schneider Electric Vulnerabilities to Infiltrate Networks
- Patch Now: August Update Fixes Actively Exploited Windows Flaw Among 415 Security Bugs
- Critical Zero-Day in Metabase Analytics Tool Could Expose Countless Business Systems
- Beyond the Checklist: Why Aussie Businesses Need to Rethink How They Patch
- New China-Linked Ransomware 'StormEncryptor' Signals Evolving Threat to Businesses
- AI Is Supercharging Software Development — Is Your Security Keeping Pace?
- AI-Powered Red Team Uncovers Critical Flaws in Bitcoin Software
- OpenAI Pauses 'Astra' AI Model Over Autonomous Hacking Concerns
- Critical Flaw in Progress Kemp LoadMaster Added to US Government's Actively Exploited Vulnerabilities List
- Truck Brake Recall Quietly Fixed Hidden Cybersecurity Flaws
- Google Releases Chrome 151 Update to Fix Critical Security Flaws
- Cisco Issues Urgent Patches for Critical Networking Vulnerabilities
- AI-Assisted Audit Finds 85 Critical Flaws in Bitcoin Ecosystem Projects
- Google Patches AI 'Agent-to-Agent' Flaw That Could Have Hit Software Supply Chains
- Actively Exploited JetBrains TeamCity Vulnerability Added to CISA's Must-Patch List
- US Cyber Agency Warns of Active Attacks on Langflow, Tomcat, and N-central Software
-
AI-Powered Attackers Outpace Defenders, Forcing Bitcoin Swap Service Offline
Also covered by Decrypt
- CISA Flags Three More Actively Exploited Software Flaws — Is Your Business Affected?
- Microsoft Pays Out $20 Million to Security Researchers in Bug Bounty Program
- AI Gateways Like LiteLLM Are Becoming Prime Targets for Attackers
- Microsoft's Latest Patch Tuesday Fixes a Record 570 Security Flaws
- AI Agents Are Getting Alarmingly Good at Finding and Exploiting Software Bugs