Patching stories
Government and critical infrastructure operators may need years to upgrade vulnerable encryption before quantum computers make it obsolete.
AI-driven vulnerability discovery is leaving companies less time to patch, prompting new focus on clean recovery, air-gapped backups and testing.
AI-driven vulnerability scanning is forcing firms to rethink complacency as Check Point says existing defences still help against Mythos.
Microsoft patched a CVE-2025-59199 flaw in October after researchers showed a single click could let low-integrity code escape Windows 11's sandbox.
It targets operators where outages can threaten safety and continuity, as industrial and healthcare environments face faster-moving AI-driven attacks.
Many SAP users face rising costs and migration risk as support deadlines loom, pushing demand for independent maintenance alternatives.
More than half of patched flaws in major DevOps tools were high or critical in 2025, putting software supply chains at greater risk.
The move targets vulnerabilities in software used by large firms, as AI makes it easier to find and exploit flaws.
Security teams in Australia and New Zealand may soon triage flaws faster as TrendAI uses Claude Opus 4.8 to assess exploitability and impact.
Security teams could cut alert backlogs as the new system flags only flaws that can be exploited in a specific environment.
Security teams may need to react faster as AI-boosted attackers can exploit flaws within hours, leaving patching cycles behind.
The new service aims to help firms keep pace as AI-powered criminals automate attacks faster than security teams can patch flaws.
The platform aims to help AI developers move beyond benchmark tests, as models struggle to tackle real-world vulnerabilities safely and reliably.
Only a small fraction of disclosed flaws are likely to hit suppliers, leaving security teams to focus on the 58 highest-risk CVEs.
Patching alone has left some older SonicWall devices exposed to VPN attacks, with reliaQuest finding the first known in-the-wild use of CVE-2024-12802.
Exposed systems are becoming the main target, as Rapid7 says flaws were used in 38% of incidents and patch windows shrank to five days.
Most Spring teams are exposed to container risks as 64% of respondents were unaware Dockerfile choices can affect security.
Attackers still exploit basic gaps for months, with 88% of SMB breaches in 2025 involving ransomware, the report says.
Refurbished kit is gaining ground as firms face cost pressure, yet weaker patching could leave ageing devices exposed to cyber attacks.
Security teams face a shrinking window to spot and fix flaws as AI models like Mythos find exposures in minutes, not days.