peter bassill · operator
$ grep -l "tag:patching" writing/

tag: patching.

7 pieces tagged patching, newest first. The full taxonomy is on the tag index.

2026·09·29 Patching is step five: inside the NetScaler zero-days Attackers exploited two Citrix NetScaler ADC and Gateway flaws for weeks before fixes shipped on 27 September. How CVE-2026-88771 turns a log line into a root shell, who is affected, and why the NCSC lists patching fifth. vulnerability management · incident response · patching · threat intel · board 12 min 2026·09·27 Critical is not the same as urgent: what 70,686 CVEs in 2026 actually ask of you Of 70,686 CVEs published between 1 January and 22 September, 161 are known to be exploited. What NVD, EPSS, CISA's catalogue and Exploit-DB say about severity, deadlines and the software attackers use, and a one-line triage rule. vulnerability management · patching · threat intel · research · board 19 min 2026·07·18 wp2shell: WordPress core has an unauthenticated RCE. Patch now. wp2shell (CVE-2026-63030) is an unauthenticated remote code execution flaw in WordPress core — not a plugin — patched on 17 July in 6.9.5 and 7.0.2. No public exploit yet, but one is coming fast. Why a core flaw is different, and why you should patch every site now. wordpress · web security · patching 8 min 2026·07·17 Patch FortiSandbox by Sunday: when the security appliance is the hole CISA has told federal agencies to patch two actively-exploited FortiSandbox flaws by Sunday — both unauthenticated, CVSS 9.1 remote code execution. The malware sandbox is the way in. Why the KEV is your real triage list, and why your security appliances are the target. patching · vulnerability management · threat intel 7 min 2026·07·15 Six hundred patches, two emergencies, and one broken Dell Microsoft's July Patch Tuesday broke its record again — 622 CVEs, or 570 depending who's counting — then Microsoft blocked its own update on overheating Dells. The headline number is theatre; the real list is two exploited zero-days. A triage, not a panic. patching · vulnerability management · craft 9 min 2025·09·22 Setting Up Unattended Security Upgrades on Ubuntu Most Linux servers that get compromised had a patch available weeks before the breach. Unattended-upgrades applies security fixes while you sleep. tutorial · defence · patching · linux · hardening · ubuntu 8 min tutorial 2021·04·06 Hafnium and the patch-window asymmetry Five weeks after the Microsoft Exchange ProxyLogon disclosure, the dust is settling on what may turn out to be the most consequential mass-exploitation event of the decade. What it teaches us is structural, not tactical. incident · patching · craft · ned 7 min

→ all tags  ·  all writing