Una nuova ondata di vulnerabilità in Erlang/OTP mette in evidenza i punti di pressione della sicurezza che contano di più nei sistemi ad alta disponibilità: decodifica a runtime, convalida della fiducia ed esposizione di rete.
Gli aggiornamenti di sicurezza correggono ora diverse vulnerabilità JetBrains, tra cui tre classificate critiche e 13 ad alta gravità, ma la domanda pratica è quali installazioni debbano ancora essere aggiornate.
Un avviso di ACN CSIRT Italia segnala un rischio stratificato in MongoDB Server e MongoDB Compass, dove le patch dipendono ora dalla versione, dal deployment e da quanta fiducia può riporre un workstation di amministrazione.
Due problemi critici e una falla ad alta gravità nei moduli FreePBX rafforzano un avvertimento noto: quando il livello amministrativo di uno stack PBX si rompe, l'intero sistema telefonico può diventare la superficie di attacco.
ACN CSIRT Italia ha segnalato un intenso ciclo di patch in SolarWinds Serv-U, un promemoria del fatto che le piattaforme di trasferimento file possono diventare da un giorno all'altro confini di sicurezza ad alto valore.
Google has pushed a Chrome security update that closes seven vulnerabilities, and the mix of critical and high-severity bugs is a reminder that browser patching is now a race against reachability.
Mozilla has pushed security updates for two critical Firefox flaws that are reportedly being exploited online, putting patch speed and endpoint visibility at the center of defense.
A monthly maintenance cycle turned into a high-priority security checkpoint as SAP’s July updates touched multiple product layers, from core application runtime to web and cloud components.
Two critical Metabase flaws were patched after security updates, and the risk profile is unsettling: an authenticated user could turn ordinary access into arbitrary code execution on affected systems.
A new Chrome security release fixes 27 vulnerabilities, including two critical ones, and it highlights how quickly a browser can become the weakest link on a managed endpoint.
Security updates for Roundcube Webmail close off several flaws, including two rated critical, in a reminder that browser-based mail sits on a fragile boundary between untrusted content and authenticated access.
A set of Fireware OS vulnerabilities, including one critical issue and nine high-severity flaws, turns attention to the patch discipline behind perimeter appliances.
Synology has pushed fixes for three MailPlus Server vulnerabilities in DSM, including two critical flaws that could permit arbitrary file read/write and disrupt service availability.
ACN CSIRT Italia flagged a compact but urgent remediation case: four vulnerabilities in JetBrains products, including three rated critical and one high.
Security fixes for golang.org/x/crypto are a reminder that patching a single module can matter far beyond the teams that imported it directly.
ACN CSIRT Italia has flagged six fixed vulnerabilities in Cacti, and the real risk is what happens when a network-monitoring tool becomes the weakest web app in the room.
With proof-of-concept exploits available for newly reported Gogs vulnerabilities, defenders should review exposure and patching priorities.
CSIRT Italia’s May 2026 operational summary is a reminder that the most useful cyber warnings are often the least flashy: the ones that show where exposure is accumulating.
Six newly identified vulnerabilities, including two classified as critical, highlight how weaknesses in a threat-intelligence platform can ripple through detection, sharing, and trust.
ACN’s advisory on patched Grafana flaws is a reminder that observability software can turn dangerous when server-side features cross into host storage.