<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability-Management on CuraSec</title><link>https://curasec.metacog.co.kr/tags/vulnerability-management/</link><description>Recent content in Vulnerability-Management on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/vulnerability-management/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE Dispute: Maintainer Challenges Vulnerability Classification</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-a-cve-dispute/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-a-cve-dispute/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> CVE disputes from prominent open-source maintainers illuminate how vulnerability severity gets contested and miscalibrated; worth reading to sharpen how you evaluate and prioritize CVE reports in your own dependency triage.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> CVE scoring disputes highlight systemic unreliability in the NVD/CVE pipeline that can distort risk register inputs; useful context when explaining to the board why CVSS scores alone are insufficient for prioritization.&lt;/li>
&lt;/ul></description></item><item><title>CoSA: LLM-Assisted CVSS Base Metric Prediction from Repo Context</title><link>https://curasec.metacog.co.kr/insights/2026-08-17-cosa-context-aware-severity-assessment-via-context-analysis/</link><pubDate>Mon, 17 Aug 2026 13:03:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-17-cosa-context-aware-severity-assessment-via-context-analysis/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research prototype that uses code property graphs and LLM pruning to automate CVSS scoring — relevant if you&amp;rsquo;re evaluating AI-assisted vuln triage tooling, but no deployable tool exists yet and no action is required today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>August 2026 Patch Tuesday: Exploited Zero-Day Among 415 CVEs</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-august-2026-patch-tuesday-one-exploited-zero-day-and-62-crit/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-august-2026-patch-tuesday-one-exploited-zero-day-and-62-crit/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> An actively exploited zero-day in this cycle demands prioritization over routine patching; read the full CrowdStrike analysis to identify the affected product and fast-track that specific patch ahead of the 62 criticals.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The exploited zero-day likely carries a detection angle — review the full analysis for associated TTPs or IOCs and build or tune a detection before patch coverage is complete across the estate.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A 415-CVE patch cycle with one exploited zero-day is operationally significant but below board altitude unless the zero-day proves systemic; no leadership action required until the engineering team surfaces exposure details.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft August 2026 Patch Tuesday: 398 Fixes, One Actively Exploited</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-plugs-nearly-400-security-holes/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-plugs-nearly-400-security-holes/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Apply August 2026 Patch Tuesday updates now, prioritizing the one actively exploited vulnerability and the two publicly disclosed issues first, then triage the remaining 395 by severity and exposure surface.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Once Microsoft releases specifics on the actively exploited CVE, build or tune detections for exploitation attempts; the two pre-patched public disclosures may already have known TTPs worth hunting against Windows endpoint telemetry.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A cycle of nearly 400 patches with confirmed in-the-wild exploitation is useful board-level context on Microsoft platform risk, but your engineering team owns the response — no leadership action required unless the exploited CVE turns out to be systemic.&lt;/li>
&lt;/ul></description></item><item><title>CVE issued for hallucinated SQLite flaw that does not exist</title><link>https://curasec.metacog.co.kr/insights/2026-08-03-critical-cve-issued-for-hallucinated-sqlite-vulnerability/</link><pubDate>Mon, 03 Aug 2026 13:48:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-03-critical-cve-issued-for-hallucinated-sqlite-vulnerability/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> An LLM fabricated a SQLite vulnerability that received a real CVE assignment, meaning scanner feeds and automated tooling may surface non-existent flaws. Review your pipeline&amp;rsquo;s CVE triage process to require reproducibility evidence before triggering patch workflows.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Phantom CVEs inject false positives into threat intel and vulnerability feeds; no IOCs or exploitable technique here, but analysts should validate CVE claims against primary sources before escalating or triggering hunts.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This is a signal that CVE ecosystem integrity is degrading as AI-generated content enters the NVD pipeline — worth noting when boards ask about AI risk, and when justifying human-in-the-loop controls on vulnerability management processes.&lt;/li>
&lt;/ul></description></item><item><title>AI Shortening Exploit Timelines: Vuln Management Rethink Prompted</title><link>https://curasec.metacog.co.kr/insights/2026-07-29-mythos-asks-the-right-question-it-doesn-t-answer-it/</link><pubDate>Wed, 29 Jul 2026 13:07:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-29-mythos-asks-the-right-question-it-doesn-t-answer-it/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Raises a conceptual challenge about shrinking patch windows due to AI-assisted exploitation, but offers no specific CVEs, patches, or tooling changes to act on today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The compressed exploit timeline argument is relevant framing for prioritization conversations with leadership, but no concrete program changes or vendor exposures are named.&lt;/li>
&lt;/ul></description></item><item><title>Google Launches Gemini 3.5 Flash Cyber AI for Vuln Discovery and Patching</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-google-launches-gemini-3-5-flash-cyber-ai-to-find-and-fix-so/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-google-launches-gemini-3-5-flash-cyber-ai-to-find-and-fix-so/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> A specialized AI model for automated vuln discovery and patching is worth tracking as the tooling matures, but it&amp;rsquo;s limited-access via a government/partner pilot with no public availability yet — no action today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This signals Google&amp;rsquo;s direction on AI-assisted vulnerability remediation; relevant for future tooling strategy, but limited-access pilot status means no near-term budget or procurement decision is needed.&lt;/li>
&lt;/ul></description></item><item><title>N-day exploitation windows shrinking from days to hours</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-n-day-is-becoming-n-hour-patching-faster-won-t-save-you/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-n-day-is-becoming-n-hour-patching-faster-won-t-save-you/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The article reframes patch deployment urgency: diff-based exploit reconstruction means exposure begins at patch publication, not exploitation reports. Evaluate whether your pipeline can compress patch-to-deploy windows and whether compensating controls (WAF rules, network segmentation) can cover the gap.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Useful framing for understanding why post-patch hunting matters — adversaries weaponize diffs quickly, so a &amp;rsquo;no exploitation reported&amp;rsquo; status at patch time may be obsolete within hours. Reinforces the case for assume-breach sweeps when critical patches drop.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The shrinking exploit window is a useful data point for board conversations about why patch SLAs must tighten and why compensating controls matter — but no immediate action required absent a specific incident or regulation tied to this trend.&lt;/li>
&lt;/ul></description></item><item><title>Mandiant: Blueprint for AI-Assisted Vulnerability Management Guardrails</title><link>https://curasec.metacog.co.kr/insights/2026-07-17-demystifying-ai-exploits-a-blueprint-for-ai-assisted-vulnera/</link><pubDate>Fri, 17 Jul 2026 12:06:10 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-17-demystifying-ai-exploits-a-blueprint-for-ai-assisted-vulnera/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Practical architectural framing for safely embedding LLM agents into CI/CD and vuln-discovery pipelines; worth reviewing before deploying privileged AI agents, but no immediate patch or config action required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The M-Trends 2026 finding that mean time-to-exploit has turned negative (−7 days) is useful framing for board risk discussions and for justifying investment in AI-accelerated detection; no immediate action required, but the data point belongs in the next risk briefing.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft July 2026 Patch Tuesday: Record 570 CVEs Fixed</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-patches-a-record-570-security-flaws/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-patches-a-record-570-security-flaws/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Review the full July 2026 Patch Tuesday advisory this week and triage the 570 CVEs by severity and KEV/exploitation status; the sheer volume demands a systematic prioritization pass rather than blanket deferral.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, active exploitation detail, or detection angles are surfaced in this item; the AI-assisted discovery explanation for the volume surge is context worth noting but yields no immediate hunt or rule work.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> AI-accelerated vulnerability discovery is producing structurally higher patch volumes quarter over quarter; assess whether current patch SLAs and engineering capacity can absorb this cadence, and flag the trend as a resourcing input for next planning cycle.&lt;/li>
&lt;/ul></description></item><item><title>Vulnerability reports are not special anymore</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-vulnerability-reports-are-not-special-anymore/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-vulnerability-reports-are-not-special-anymore/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Thought-piece from a credible voice arguing that the privileged treatment historically given to vuln reports no longer serves its purpose — worth reading to recalibrate how you triage and respond to incoming disclosures and CVE noise.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The essay&amp;rsquo;s thesis on vuln report commoditization is relevant context for understanding why CVE-based alert queues are increasingly low signal; no detection action follows.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Useful framing for a vuln management program review or board conversation about disclosure posture, but no immediate risk-register or regulatory action required.&lt;/li>
&lt;/ul></description></item></channel></rss>