<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Patch-Management on CuraSec</title><link>https://curasec.metacog.co.kr/tags/patch-management/</link><description>Recent content in Patch-Management on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 19 Aug 2026 11:36:35 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/patch-management/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows 11 24H2 Home/Pro ends support in 2 months</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-windows-11-24h2-home-and-pro-reach-end-of-support-in-2-month/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-windows-11-24h2-home-and-pro-reach-end-of-support-in-2-month/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Audit endpoints for Windows 11 Home/Pro 24H2 and schedule upgrades to a supported build before the deadline; unpatched systems will stop receiving security updates, creating compounding exposure.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Confirm whether any managed devices (dev machines, contractor endpoints) run Home/Pro 24H2 and ensure IT has an upgrade plan in place; unsupported devices become a compliance and vendor-attestation liability.&lt;/li>
&lt;/ul></description></item><item><title>Apple Patches 108 Vulnerabilities in iOS, iPadOS, and macOS</title><link>https://curasec.metacog.co.kr/insights/2026-08-18-apple-patches-ios-and-macos-mon-aug-17th/</link><pubDate>Tue, 18 Aug 2026 11:37:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-18-apple-patches-ios-and-macos-mon-aug-17th/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> 108 CVEs across iOS/iPadOS and macOS 26 is a large batch worth prioritizing; schedule updates for macOS developer workstations and managed iOS fleet this patch cycle — no KEV or PoC signals to force emergency action.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Windows Server 2022 mainstream support ends October 2026</title><link>https://curasec.metacog.co.kr/insights/2026-08-18-windows-server-2022-reaches-end-of-mainstream-support-in-60/</link><pubDate>Tue, 18 Aug 2026 11:37:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-18-windows-server-2022-reaches-end-of-mainstream-support-in-60/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Mainstream support ending means no new feature or non-security fixes, though extended support (security patches) continues. Start migration planning to Windows Server 2025 this quarter to avoid a rushed lift when extended support eventually terminates.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Add Windows Server 2022 migration to the infrastructure roadmap and next budget cycle; security patches continue under extended support, so there is no immediate risk, but delaying planning creates future upgrade-cost pressure.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft patches LegacyHive Windows zero-day vulnerability</title><link>https://curasec.metacog.co.kr/insights/2026-08-14-microsoft-patches-legacyhive-windows-zero-day-vulnerability/</link><pubDate>Fri, 14 Aug 2026 11:54:18 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-14-microsoft-patches-legacyhive-windows-zero-day-vulnerability/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> A Windows zero-day now has a patch, so apply the out-of-band update as soon as your change window allows; no KEV listing or public PoC signals suggest immediate active exploitation pressure, but the zero-day classification warrants prioritizing this above routine patches.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The zero-day label is worth tracking in case exploitation evidence surfaces, but the item provides no IOCs, TTPs, or affected-behavior details to build or tune detections against right now.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Apple July 2026 Patch Round: OS and Safari Updates</title><link>https://curasec.metacog.co.kr/insights/2026-07-29-apple-patches-everything-july-2026-wed-jul-29th/</link><pubDate>Wed, 29 Jul 2026 13:07:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-29-apple-patches-everything-july-2026-wed-jul-29th/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Ensure managed Apple devices and Safari are updated to the July 2026 releases; prioritize macOS 26 and Safari patches, and note that macOS 14/15 received separate coverage — audit fleet version distribution.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Apple macOS Tahoe 26.6 Security Update Released</title><link>https://curasec.metacog.co.kr/insights/2026-07-29-about-the-security-content-of-macos-tahoe-26-6/</link><pubDate>Wed, 29 Jul 2026 13:07:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-29-about-the-security-content-of-macos-tahoe-26-6/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Apple&amp;rsquo;s security content page for macOS Tahoe 26.6 lists patched CVEs with no enrichment signals indicating active exploitation; schedule deployment of macOS 26.6 to managed endpoints and review the full CVE list for any vulnerabilities affecting shared components (e.g., WebKit, kernel) that may also surface in server or CI runner environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Exchange 2016/2019 ESU ends October 2026</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-microsoft-to-stop-exchange-2016-2019-security-updates-in-oct/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-microsoft-to-stop-exchange-2016-2019-security-updates-in-oct/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you still run Exchange 2016 or 2019 on-premises, schedule migration to Exchange Online or a supported version before October; after that date, unpatched RCE vulnerabilities will go unfixed on a historically targeted mail server.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Confirm whether on-premises Exchange 2016/2019 remains in the estate; EOL removes the vendor&amp;rsquo;s security backstop and raises audit/compliance risk — budget and timeline for migration or decommission should be locked this quarter.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft shares manual fix for WSUS sync delays and timeouts</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-microsoft-shares-manual-fix-for-wsus-sync-delays-and-timeout/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-microsoft-shares-manual-fix-for-wsus-sync-delays-and-timeout/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your patch management relies on WSUS, apply the manual mitigation steps Microsoft published to restore scan reliability before the next patch cycle.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>N-day exploitation windows shrinking from days to hours</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-n-day-is-becoming-n-hour-patching-faster-won-t-save-you/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-n-day-is-becoming-n-hour-patching-faster-won-t-save-you/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The article reframes patch deployment urgency: diff-based exploit reconstruction means exposure begins at patch publication, not exploitation reports. Evaluate whether your pipeline can compress patch-to-deploy windows and whether compensating controls (WAF rules, network segmentation) can cover the gap.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Useful framing for understanding why post-patch hunting matters — adversaries weaponize diffs quickly, so a &amp;rsquo;no exploitation reported&amp;rsquo; status at patch time may be obsolete within hours. Reinforces the case for assume-breach sweeps when critical patches drop.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The shrinking exploit window is a useful data point for board conversations about why patch SLAs must tighten and why compensating controls matter — but no immediate action required absent a specific incident or regulation tied to this trend.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft investigating WSUS sync delays affecting patch distribution</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-microsoft-confirms-windows-server-update-services-sync-delay/</link><pubDate>Mon, 20 Jul 2026 13:16:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-microsoft-confirms-windows-server-update-services-sync-delay/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your patch pipeline depends on WSUS, validate that downstream clients are still receiving updates; consider a temporary alternative sync source or manual approval workflow until Microsoft resolves the issue.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Windows Server 2022 ends mainstream support in October 2026</title><link>https://curasec.metacog.co.kr/insights/2026-07-17-windows-server-2022-reach-end-of-mainstream-support-in-90-da/</link><pubDate>Fri, 17 Jul 2026 12:06:10 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-17-windows-server-2022-reach-end-of-mainstream-support-in-90-da/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Audit your Server 2022 inventory and document any features relying on mainstream-only support; no immediate patching action required since security updates continue through extended support until 2031.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Note the October 2026 mainstream support end on your risk register and vendor lifecycle tracking; security patches continue, so no urgent action, but budget planning for eventual migration or extended support agreements should begin this quarter.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft blocks Windows 11 updates on some Dell PCs due to shutdowns</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-some-dell-pcs-shut-down-after-recent-windows-updat/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-some-dell-pcs-shut-down-after-recent-windows-updat/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you manage Dell endpoints running Windows 11, verify whether the update block applies to your hardware models and plan an alternate patching path once Microsoft lifts the safeguard hold.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>curl pauses vulnerability intake for July 2026</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-curl-will-not-accept-vulnerability-reports-during-july-2026/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-curl-will-not-accept-vulnerability-reports-during-july-2026/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you discover a curl vulnerability in July 2026, hold the report until August — the project has suspended intake this month, so plan your disclosure timeline and any workarounds accordingly.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A high-profile open-source maintainer pausing vulnerability intake raises questions about responsible disclosure windows and key-person risk in critical dependencies; worth noting for vendor/OSS risk discussions.&lt;/li>
&lt;/ul></description></item></channel></rss>