peter bassill · operator
$ grep -l "tag:patching" writing/

tag: patching.

4 pieces tagged patching, newest first. The full taxonomy is on the tag index.

2026·07·18 wp2shell: WordPress core has an unauthenticated RCE. Patch now. wp2shell (CVE-2026-63030) is an unauthenticated remote code execution flaw in WordPress core — not a plugin — patched on 17 July in 6.9.5 and 7.0.2. No public exploit yet, but one is coming fast. Why a core flaw is different, and why you should patch every site now. wordpress · web security · patching 8 min 2026·07·17 Patch FortiSandbox by Sunday: when the security appliance is the hole CISA has told federal agencies to patch two actively-exploited FortiSandbox flaws by Sunday — both unauthenticated, CVSS 9.1 remote code execution. The malware sandbox is the way in. Why the KEV is your real triage list, and why your security appliances are the target. patching · vulnerability management · threat intel 7 min 2026·07·15 Six hundred patches, two emergencies, and one broken Dell Microsoft's July Patch Tuesday broke its record again — 622 CVEs, or 570 depending who's counting — then Microsoft blocked its own update on overheating Dells. The headline number is theatre; the real list is two exploited zero-days. A triage, not a panic. patching · vulnerability management · craft 9 min 2021·04·06 Hafnium and the patch-window asymmetry Five weeks after the Microsoft Exchange ProxyLogon disclosure, the dust is settling on what may turn out to be the most consequential mass-exploitation event of the decade. What it teaches us is structural, not tactical. incident · patching · craft · ned 7 min

all tags  ·  all writing