Tagged articles

patch management

18 articles · Page 1 of 1
Frontline Investigation
Frontline Investigation
Oct 1, 2026 · Information Security

Patch Installed, Risk Unresolved: The Three States of True Vulnerability Remediation

A vulnerability patch showing 'installed' doesn't guarantee risk is resolved; true remediation requires verifying exposure convergence and business acceptability, aligning security and business validation, and documenting residual risks with clear ownership and review timelines.

NIST guidelinesbusiness continuityevidence-based remediation
0 likes · 7 min read
Patch Installed, Risk Unresolved: The Three States of True Vulnerability Remediation
Frontline Investigation
Frontline Investigation
Aug 17, 2026 · Information Security

Why Fast Vulnerability Alerts Don't Translate to Quick Fixes

The article explains that while vulnerability detection has accelerated, actual remediation remains slow due to misaligned priorities between security, business, and operations teams; it argues for aligning threat, business, and verification timelines, prioritizing based on service risk rather than severity scores, and treating remediation as an organizational rhythm rather than a technical task.

CISA KEVNIST SP 800-40Risk Prioritization
0 likes · 12 min read
Why Fast Vulnerability Alerts Don't Translate to Quick Fixes
Linux Tech Enthusiast
Linux Tech Enthusiast
Jul 5, 2026 · Information Security

Essential Linux System Security Configurations You Must Know

This guide details fourteen essential Linux security hardening steps—including shared account checks, account lock policies, root remote‑login restrictions, password complexity and aging, critical directory permissions, logging, SSH hardening, unnecessary service removal, Ctrl‑Alt‑Del disabling, and patch installation—targeted at Red Hat AS 3/4 systems.

LinuxPAMRed Hat
0 likes · 18 min read
Essential Linux System Security Configurations You Must Know
21CTO
21CTO
Apr 20, 2026 · Information Security

How Anthropic’s Opus Model Generates Real‑World Chrome Exploits and What It Means for Security

Anthropic’s Opus 4.6 model can automatically craft a working V8 JavaScript engine exploit for Chrome 138, costing $2,283 in API usage, which demonstrates how AI‑driven code generation is reshaping vulnerability research, shortening patch windows, and forcing a rethink of software security practices.

AI securityChrome vulnerabilityOpus model
0 likes · 7 min read
How Anthropic’s Opus Model Generates Real‑World Chrome Exploits and What It Means for Security
dbaplus Community
dbaplus Community
Nov 7, 2024 · Operations

Why Windows Server 2025 Auto‑Upgraded Your 2022 Servers—and How to Fix It

Shortly after Microsoft released Windows Server 2025, many administrators discovered that their Windows Server 2022 machines were silently upgraded to the unlicensed 2025 version, exposing several known bugs, licensing issues, and a mis‑labelled update that required immediate mitigation and rollback strategies.

LicensingWindows Serverauto-upgrade
0 likes · 11 min read
Why Windows Server 2025 Auto‑Upgraded Your 2022 Servers—and How to Fix It
ZhongAn Tech Team
ZhongAn Tech Team
Apr 19, 2024 · Mobile Development

Implementing a Flutter Hot‑Fix Solution for ZA Bank: Architecture, Process, and Lessons Learned

This article details ZA Bank’s implementation of a Flutter hot‑fix solution, describing the evaluation of various approaches, the selection of a FlutterWeb‑based page‑downgrade strategy, the design of backend patch management, challenges such as font loading and package size, and the resulting high fix rate and performance improvements.

Cross‑PlatformFlutterFlutterWeb
0 likes · 24 min read
Implementing a Flutter Hot‑Fix Solution for ZA Bank: Architecture, Process, and Lessons Learned
Open Source Linux
Open Source Linux
Mar 1, 2021 · Cloud Computing

How Google’s VM Manager Simplifies Large‑Scale Cloud VM Operations

Google’s VM Manager automates the deployment, patching, configuration, and inventory of massive Compute Engine VM clusters, offering a single dashboard to streamline security, observability, and performance for enterprises moving workloads to the cloud.

Google CloudInfrastructure automationVM Manager
0 likes · 4 min read
How Google’s VM Manager Simplifies Large‑Scale Cloud VM Operations
Didi Tech
Didi Tech
Jun 9, 2020 · Databases

Didi HBase Team’s Upgrade from 0.98 to 1.4.8: Challenges, Solutions, and Lessons Learned

Didi's HBase team upgraded eleven clusters from version 0.98 to 1.4.8, tackling maintenance burdens and custom‑patch divergence, validating RPC and HFile compatibility, performing extensive functional and performance tests, opting for a rolling upgrade, fixing a region‑split data‑loss bug, merging critical upstream patches, and establishing a reusable migration methodology.

DidiHBaseRolling Upgrade
0 likes · 10 min read
Didi HBase Team’s Upgrade from 0.98 to 1.4.8: Challenges, Solutions, and Lessons Learned
Efficient Ops
Efficient Ops
May 9, 2018 · Operations

How eBay Automates Cross‑Platform Patch Deployment at Scale

This article details eBay's 11‑year journey in automating system‑wide patch deployment across Windows and Linux servers, covering challenges, process evolution, security considerations, testing strategies, and future plans for kernel hot‑patching and container‑based updates.

automationcross-platformoperations
0 likes · 17 min read
How eBay Automates Cross‑Platform Patch Deployment at Scale
Efficient Ops
Efficient Ops
Jan 9, 2018 · Operations

Automating Patch Management for 10,000+ Servers with StackStorm & SaltStack

This article explains how Ctrip’s senior engineer Hu Junya built an automated operations platform using SaltStack for remote control, StackStorm for workflow orchestration, and a custom Jobs tool for batch gray releases, enabling safe, scalable patch deployment across thousands of servers.

DevOpsStackStormbatch deployment
0 likes · 11 min read
Automating Patch Management for 10,000+ Servers with StackStorm & SaltStack
MaGe Linux Operations
MaGe Linux Operations
May 14, 2017 · Information Security

Why the ONION & WNCRY Ransomware Hit 70 Countries – Protection Tips

The recent ONION and WNCRY ransomware outbreak, originating from leaked NSA tools like EternalBlue, rapidly infected over 70 nations, targeting hospitals, universities and other institutions, and this article explains the attack timeline, infection mechanisms, impact on Chinese campuses, and practical mitigation steps such as backups, patching, port blocking and domain filtering.

EternalBlueRansomwarenetwork security
0 likes · 8 min read
Why the ONION & WNCRY Ransomware Hit 70 Countries – Protection Tips
Efficient Ops
Efficient Ops
Mar 12, 2017 · Information Security

Understanding the CVE-2017-5638 Struts2 RCE: Impact, Stats, and Fixes

The article examines the high‑risk CVE‑2017‑5638 vulnerability in Apache Struts2, detailing its remote code execution mechanism, global impact statistics across industries and regions, and provides comprehensive detection methods and three tiers of remediation solutions.

Apache StrutsCVE-2017-5638Remote Code Execution
0 likes · 6 min read
Understanding the CVE-2017-5638 Struts2 RCE: Impact, Stats, and Fixes
Efficient Ops
Efficient Ops
Dec 14, 2015 · Operations

Top Ops Security Pitfalls and How to Safeguard Your Infrastructure

This article examines the most common operational security vulnerabilities—such as unpatched Struts, server‑status leaks, backup file exposure, SVN leaks, and weak default credentials—explains why they are critical, and offers practical recommendations for enterprises to improve their ops‑security posture.

Infrastructureoperations securitypatch management
0 likes · 15 min read
Top Ops Security Pitfalls and How to Safeguard Your Infrastructure