Tagged articles

vulnerability management

40 articles · Page 1 of 1
Frontline Investigation
Frontline Investigation
Oct 1, 2026 · Information Security

Patch Installed, Risk Unresolved: The Three States of True Vulnerability Remediation

A vulnerability patch showing 'installed' doesn't guarantee risk is resolved; true remediation requires verifying exposure convergence and business acceptability, aligning security and business validation, and documenting residual risks with clear ownership and review timelines.

NIST guidelinesbusiness continuityevidence-based remediation
0 likes · 7 min read
Patch Installed, Risk Unresolved: The Three States of True Vulnerability Remediation
Ubuntu
Ubuntu
Sep 27, 2026 · Information Security

Ubuntu Kernel Patches Go Weekly: AI-Driven Vulnerability Flood Forces 4x Speedup

Canonical has accelerated Ubuntu kernel patch releases from a four-week cycle to weekly due to AI-automated vulnerability discovery overwhelming patching capacity, exemplified by a container-escape vulnerability (CVE-2026-80521) with public proof-of-concept but no patch yet for three LTS releases, prompting mitigation guidance including live patching, capability dropping, and microVM isolation.

AI-driven threatsLinux kernelUbuntu
0 likes · 13 min read
Ubuntu Kernel Patches Go Weekly: AI-Driven Vulnerability Flood Forces 4x Speedup
TechVision Expert Circle
TechVision Expert Circle
Sep 3, 2026 · Information Security

AI-Driven Attacks Are Here: The Four-Layer Firewall CTOs Must Build Now

This article analyzes how AI-powered attacks have transformed the threat landscape with automated vulnerability discovery, personalized phishing, and code mutation, why traditional defenses fail against speed, scale, and mutation asymmetry, and presents a four-layer AI security governance architecture with a practical checklist for CTOs to implement immediate protections.

AI AgentsAI GovernanceAI red teaming
0 likes · 15 min read
AI-Driven Attacks Are Here: The Four-Layer Firewall CTOs Must Build Now
Frontline Investigation
Frontline Investigation
Sep 2, 2026 · Information Security

Why Fixed Vulnerabilities Keep Reappearing: The Hidden Drift in Attack Surface Management

This article explains why asset exposure surfaces reappear after vulnerability patching, distinguishing static patch management from dynamic attack surface relationships, identifying three drift types (asset, connection, responsibility), and proposing three confirmations (object, path, change) to ensure risks truly exit rather than just being patched.

CISA KEVNIST CSFasset drift
0 likes · 10 min read
Why Fixed Vulnerabilities Keep Reappearing: The Hidden Drift in Attack Surface Management
Frontline Investigation
Frontline Investigation
Aug 17, 2026 · Information Security

Why Fast Vulnerability Alerts Don't Translate to Quick Fixes

The article explains that while vulnerability detection has accelerated, actual remediation remains slow due to misaligned priorities between security, business, and operations teams; it argues for aligning threat, business, and verification timelines, prioritizing based on service risk rather than severity scores, and treating remediation as an organizational rhythm rather than a technical task.

CISA KEVNIST SP 800-40Risk Prioritization
0 likes · 12 min read
Why Fast Vulnerability Alerts Don't Translate to Quick Fixes
Frontline Investigation
Frontline Investigation
Jul 14, 2026 · Information Security

Vulnerability Management's Overlooked Core: Asset Visibility Over Patches

The article argues that effective vulnerability management depends less on patching speed and more on asset visibility, proposing a four-perspective model (asset, exposure, business, remediation) and a four-question risk prioritization framework aligned with NIST CSF and CISA KEV to move beyond severity scores toward contextual risk reduction.

CISA KEVMLPS 2.0NIST CSF
0 likes · 14 min read
Vulnerability Management's Overlooked Core: Asset Visibility Over Patches
Frontline Investigation
Frontline Investigation
Jun 25, 2026 · Information Security

Why Vulnerability Management Fails: The Hidden Attack Surface Problem

The article argues that traditional vulnerability management assumes accurate asset inventories, but modern dynamic environments create unknown exposure points. Asset exposure surface management continuously discovers external-facing assets, maps ownership, assesses risk context, and aligns remediation with business priority, as emphasized by CISA and NIST frameworks.

Asset Exposure ManagementAttack SurfaceCISA KEV
0 likes · 14 min read
Why Vulnerability Management Fails: The Hidden Attack Surface Problem
Frontline Investigation
Frontline Investigation
Jun 21, 2026 · Information Security

Beyond IOCs: Building a Closed-Loop Threat Intelligence Operations Framework

This article explains how to move threat intelligence from static IOC collection into a five-step closed loop—collect, normalize, correlate, remediate, review—integrating with assets, vulnerabilities, logs, and ticketing to prioritize real risks, avoid alert fatigue, and enable actionable security operations.

IOCMITRE ATT&CKSecurity Operations
0 likes · 16 min read
Beyond IOCs: Building a Closed-Loop Threat Intelligence Operations Framework
phodal
phodal
Mar 12, 2026 · Information Security

How AI-Generated Code Amplifies Vulnerabilities and What Security Scans Reveal

An in‑depth analysis of Codex Security’s scans shows that AI‑assisted code production doesn’t create new bug types but dramatically speeds up the spread of existing flaws, prompting a shift toward automated, engineering‑driven defenses for large‑scale code generation.

AI securitySoftware Engineeringautomation
0 likes · 11 min read
How AI-Generated Code Amplifies Vulnerabilities and What Security Scans Reveal
Black & White Path
Black & White Path
Mar 10, 2026 · Information Security

OpenAI Unveils Codex Security: An AI Agent That Autonomously Finds, Verifies, and Fixes Vulnerabilities

OpenAI's new Codex Security agent, codenamed "Aardvark," shifts application security from static scanning to a full‑process AI loop that builds custom threat models, validates exploits in a sandbox, generates patch code, and has already identified hundreds of critical bugs across millions of code commits.

Application SecurityCodex SecurityOpenAI
0 likes · 7 min read
OpenAI Unveils Codex Security: An AI Agent That Autonomously Finds, Verifies, and Fixes Vulnerabilities
Java Companion
Java Companion
Feb 24, 2026 · Backend Development

Spring Boot Online Dependency Vulnerability Scanner: One‑Click Detection of Potential Security Issues

This guide presents a lightweight Spring Boot dependency vulnerability scanner that automatically collects all project JARs, matches them against a CVE database, visualizes risk levels, provides detailed remediation steps and can be integrated into local development, emergency response, and CI/CD pipelines.

CI/CDCVEDependency Scanning
0 likes · 20 min read
Spring Boot Online Dependency Vulnerability Scanner: One‑Click Detection of Potential Security Issues
Black & White Path
Black & White Path
Feb 11, 2026 · Information Security

New Policy Unveiled: Data Security, Risk Assessment, and Vulnerability Management Markets Poised for Surge

The new “Automotive Data Outbound Security Guidelines (2026)” issued by MIIT and other ministries seeks to balance data security with cross‑border flow, defining a two‑layer demand, detailing data categories, assessment, contracts, certification, and protection measures, and signalling a massive market opportunity for data‑security services in the automotive industry.

Automotivedata securityinformation security
0 likes · 15 min read
New Policy Unveiled: Data Security, Risk Assessment, and Vulnerability Management Markets Poised for Surge
DevOps in Software Development
DevOps in Software Development
Dec 1, 2025 · Information Security

Why Trusted Component Repositories Are Critical for Military Software Security

The article examines how modern military software, built largely from third‑party components, faces supply‑chain attacks, explains the need for SBOMs, and proposes a centralized trusted component repository with automated scanning, compliance checks, and full‑lifecycle auditing to secure defense systems.

DevOpsSBOMdefense software security
0 likes · 8 min read
Why Trusted Component Repositories Are Critical for Military Software Security
Qunar Tech Salon
Qunar Tech Salon
Jul 31, 2025 · Information Security

How Multi‑Agent AI Transforms SDLC White‑Box Vulnerability Management

An in‑depth exploration of a Multi‑Agent AI system that automates SDLC white‑box vulnerability management, detailing industry‑standard processes, the system’s architecture, specialized agents, prompt engineering, tool integration, and real‑world results that boost audit efficiency and accuracy while enabling true security left‑shift.

AISDLCSecurity Automation
0 likes · 24 min read
How Multi‑Agent AI Transforms SDLC White‑Box Vulnerability Management
Bilibili Tech
Bilibili Tech
Aug 2, 2024 · Information Security

Security Development Lifecycle (SDL) at Bilibili: Implementation, Data Lifecycle Security, and DevSecOps

At Bilibili, the security team adapted Microsoft’s Security Development Lifecycle by establishing capability practices such as training, threat modeling, secure coding, and component scanning, integrating these processes into development pipelines through dedicated business partners, extending protection to the full data lifecycle, and evolving toward automated DevSecOps with in‑pipeline DAST and a custom vulnerability management platform.

Application SecurityDASTDevSecOps
0 likes · 15 min read
Security Development Lifecycle (SDL) at Bilibili: Implementation, Data Lifecycle Security, and DevSecOps
21CTO
21CTO
Apr 18, 2024 · Information Security

Why 90% of Java Services Harbor Critical Vulnerabilities – Datadog 2024 Report

Datadog’s 2024 DevSecOps report reveals that 90% of Java services contain at least one severe vulnerability—far higher than other languages—largely due to indirect dependencies, and stresses the need for comprehensive dependency scanning, prioritized remediation, and robust alert triage to manage the flood of low‑impact automated attacks.

Dependency ScanningDevSecOpsJava
0 likes · 5 min read
Why 90% of Java Services Harbor Critical Vulnerabilities – Datadog 2024 Report
FunTester
FunTester
Jan 29, 2024 · Information Security

Fundamentals of API Security: Principles, Practices, and Lifecycle Management

This article provides a comprehensive overview of API security, covering authentication and authorization, privacy and encryption, input validation, detection, rate limiting, logging, secure coding, vulnerability management, lifecycle phases, and the importance of education and training to protect modern software ecosystems.

API SecurityAuthenticationAuthorization
0 likes · 14 min read
Fundamentals of API Security: Principles, Practices, and Lifecycle Management
vivo Internet Technology
vivo Internet Technology
Oct 31, 2023 · Information Security

Network Port Security: Risks, Attack Methods, and Governance Practices

Network port security demands continuous discovery, automated vulnerability scanning, traffic‑baseline anomaly detection, and disciplined governance—including source authentication, first‑packet drop, and lifecycle management—to mitigate DDoS, application‑layer, and exploitation attacks while ensuring minimal‑privilege openings and timely closure.

DDoScc-attacknetwork security
0 likes · 25 min read
Network Port Security: Risks, Attack Methods, and Governance Practices
MaGe Linux Operations
MaGe Linux Operations
Sep 12, 2023 · Information Security

Mastering Container Vulnerability Management: Secure DevOps Strategies

This article explains how containers work, outlines the challenges of detecting and fixing vulnerabilities throughout the software lifecycle, and presents practical strategies—including CI/CD pipeline, registry, runtime, and host scanning—plus key principles for building a robust container security program.

CI/CDDevOpscontainer security
0 likes · 7 min read
Mastering Container Vulnerability Management: Secure DevOps Strategies
php Courses
php Courses
Jul 3, 2023 · Information Security

June API Security Vulnerability Report: MinIO, Joomla Rest API, and Argo CD Issues with Remediation Guidance

The June API security report highlights three critical vulnerabilities—MinIO unauthorized data exposure, Joomla Rest API unauthenticated access, and multiple Argo CD API flaws—detailing their impacts and providing concrete remediation steps to protect sensitive data and maintain system integrity.

API SecurityArgo CDJoomla
0 likes · 4 min read
June API Security Vulnerability Report: MinIO, Joomla Rest API, and Argo CD Issues with Remediation Guidance
Huolala Safety Emergency Response Center
Huolala Safety Emergency Response Center
Aug 19, 2022 · Information Security

Huolala’s First Security Salon: Purple Team, Data Compliance & Platform Design

The online Huolala Security Salon on August 19 featured eight expert sessions covering enterprise security foundations, purple‑team tactics, security training programs, data‑security compliance practices, LLSRC award recognitions, game vulnerability analysis, the evolution of code‑audit techniques, and the design of a flexible security operations platform.

Security OperationsSecurity Trainingdata compliance
0 likes · 7 min read
Huolala’s First Security Salon: Purple Team, Data Compliance & Platform Design
DeWu Technology
DeWu Technology
Jul 15, 2022 · Information Security

Software Composition Analysis (SCA): Overview, Challenges, and Implementation

Software Composition Analysis (SCA) identifies and tracks open‑source components across languages, matches them to vulnerability databases, and integrates risk detection into CI pipelines, helping organizations mitigate widespread flaws like Log4j2 while addressing challenges of diverse package formats, binary analysis, and accurate vulnerability correlation.

SCASoftware Securitydependency analysis
0 likes · 8 min read
Software Composition Analysis (SCA): Overview, Challenges, and Implementation
Programmer DD
Programmer DD
Dec 22, 2021 · Information Security

Why Was Alibaba Cloud Suspended for Six Months Over the Log4j2 Flaw?

The Chinese cybersecurity authority has suspended Alibaba Cloud’s partnership for six months after the company discovered a critical Log4j2 vulnerability but failed to promptly report it, highlighting gaps in vulnerability disclosure and threat‑management processes.

Alibaba Cloudcybersecuritylog4j2
0 likes · 2 min read
Why Was Alibaba Cloud Suspended for Six Months Over the Log4j2 Flaw?
ITPUB
ITPUB
Dec 10, 2021 · Information Security

Why the Log4j2 RCE Bug Is a Global Threat and How to Fix It

The Log4j2 remote code execution vulnerability (CVE‑2021‑44228, CNVD‑2021‑95914) affects all Java‑based applications from version 2.0 to 2.15.0‑rc1, allowing unauthenticated attackers to execute arbitrary code, and requires immediate inventory, patching, and hardening measures across all affected systems.

JavaRCElog4j2
0 likes · 6 min read
Why the Log4j2 RCE Bug Is a Global Threat and How to Fix It
Qunar Tech Salon
Qunar Tech Salon
Jun 4, 2021 · Information Security

Automated Risk Monitoring and Upgrade of Jar Components at Qunar

This article describes Qunar's end‑to‑end automated workflow for detecting high‑risk Jar component vulnerabilities, collecting asset information, orchestrating remediation with a SOAR platform, and leveraging the TCDEV auto‑upgrade service to reduce manual effort and improve security operations efficiency.

SOARSecurity OperationsTCDEV
0 likes · 8 min read
Automated Risk Monitoring and Upgrade of Jar Components at Qunar
iQIYI Technical Product Team
iQIYI Technical Product Team
Dec 25, 2020 · Information Security

iQiyi Security Incident Response Center Vulnerability Handling Policy (Version 3.0)

iQiyi Security Incident Response Center Vulnerability Handling Policy version 3.0 outlines scope, principles, reporting process, severity scoring, reward system, user levels, dispute resolution, and prohibitions, emphasizing dedicated handling, point-based rewards, and strict rules for disclosures and malicious activity.

bug bountyinformation securityrisk assessment
0 likes · 13 min read
iQiyi Security Incident Response Center Vulnerability Handling Policy (Version 3.0)
Ctrip Technology
Ctrip Technology
Jul 9, 2020 · Information Security

Ctrip's DevSecOps Practices and Challenges

The article details Ctrip's DevSecOps challenges and solutions, covering security team structuring, threat modeling, SCA and SAST integration, IAST/DAST architecture, vulnerability management, and the resulting improvements in automated security testing within a high‑frequency CI/CD environment.

CI/CDDevSecOpsIAST
0 likes · 12 min read
Ctrip's DevSecOps Practices and Challenges
dbaplus Community
dbaplus Community
Aug 29, 2018 · Information Security

Operations Security: Why It Matters, Common Pitfalls & Real‑World Cases

Operations security, the intersection of IT operations and security, has become critical as high‑profile vulnerabilities like Struts2, OpenSSL Heartbleed, and massive DDoS attacks expose the costly ROI of ops‑related flaws; this article defines the field, explains its importance, lists common bad practices, typical vulnerabilities, and real‑world case studies.

Best Practicesinformation securityoperations security
0 likes · 17 min read
Operations Security: Why It Matters, Common Pitfalls & Real‑World Cases
Tencent Cloud Developer
Tencent Cloud Developer
Mar 29, 2018 · Information Security

GitHub Security Alerts Accelerate Vulnerability Fixes for Ruby and JavaScript Projects

GitHub’s security alerts, launched in October, have dramatically cut remediation times for Ruby and JavaScript projects—nearly half of alerts are addressed within a week and 98% of actively maintained repositories patch within seven days—identifying over 400 million vulnerabilities across more than 500 thousand repositories, with detailed notifications delivered via the platform, email, and a new weekly summary, and future support planned for Python.

Dependency ScanningGitHubJavaScript
0 likes · 3 min read
GitHub Security Alerts Accelerate Vulnerability Fixes for Ruby and JavaScript Projects
JavaScript
JavaScript
Oct 31, 2017 · Information Security

Understanding OWASP Top 10: Key Web Security Risks and Mitigation Strategies

The OWASP Top 10 project ranks the ten most critical web application security risks by analyzing threats, vulnerabilities, technical impact, and business consequences, offering developers, testers, and security teams actionable guidance to improve risk awareness and implement focused protection measures.

Application SecurityOWASPTop 10
0 likes · 2 min read
Understanding OWASP Top 10: Key Web Security Risks and Mitigation Strategies
21CTO
21CTO
Sep 19, 2017 · Information Security

What Really Caused the Equifax Breach? Unpacking Apache Struts Vulnerabilities (CVE‑2017‑5638 & CVE‑2017‑9805)

The Equifax data breach exposed 143 million Americans' personal information due to unpatched Apache Struts flaws, chiefly CVE‑2017‑5638 and possibly CVE‑2017‑9805, prompting a swift response from the Apache Software Foundation and highlighting the critical need for timely vulnerability management.

Apache StrutsCVE-2017-5638CVE-2017-9805
0 likes · 7 min read
What Really Caused the Equifax Breach? Unpacking Apache Struts Vulnerabilities (CVE‑2017‑5638 & CVE‑2017‑9805)
Efficient Ops
Efficient Ops
May 11, 2017 · Information Security

Mastering Linux Security: Real‑World Attack Vectors and Defense Strategies

This article shares practical insights from a security director at YY Live, detailing the complex Linux security landscape, common vulnerabilities, real‑world attack techniques such as Redis abuse and privilege escalation, and a multi‑layered defense approach that balances rapid business iteration with robust protection.

DDoS mitigationLinux securityintrusion-detection
0 likes · 21 min read
Mastering Linux Security: Real‑World Attack Vectors and Defense Strategies
Efficient Ops
Efficient Ops
Dec 14, 2015 · Operations

Top Ops Security Pitfalls and How to Safeguard Your Infrastructure

This article examines the most common operational security vulnerabilities—such as unpatched Struts, server‑status leaks, backup file exposure, SVN leaks, and weak default credentials—explains why they are critical, and offers practical recommendations for enterprises to improve their ops‑security posture.

Infrastructureoperations securitypatch management
0 likes · 15 min read
Top Ops Security Pitfalls and How to Safeguard Your Infrastructure