Industry News - Jun 2026
Microsoft Patches 200 Vulnerabilities
Microsoft fixed roughly 200 vulnerabilities discovered in its products with the June 2026 updates. Three issues were publicly disclosed before Microsoft patched them, however none of the flaws addressed appear to have been exploited in the wild. One of the issues is listed as CVE-2026-49160 and is described as a denial-of-service (DoS) issue affecting Windows. Another vulnerability is CVE-2026-50507, a Windows BitLocker security bypass that enables an attacker having physical access to the targeted system to access encrypted data. The third publicly disclosed patched vulnerability is CVE-2026-45586, a Windows bug that can be exploited to elevate privileges to System. Microsoft has determined that three publicly disclosed issues are likely to be exploited. In addition, 40 of the nearly 200 security holes addressed have a critical severity rating affecting Windows, Azure, Office, Outlook, Exchange, and AI tools. Their exploitation can result to remote code execution, privilege escalation, and information disclosure. IT professionals can identify unpatched and vulnerable systems using their IT asset management tools.
The Risk of Shadow AI
It is highly likely that somewhere in any organization, someone is sharing confidential data with AI for analysis. Or a developer is pasting source code into an AI coding assistant to help them fix a problem. Or, a marketing team is building an AI-powered content-generation pipeline, completely unaware that same thing was done last quarter. In fact, according to Gallup, nearly half of U.S. employees now say they use AI. Considering the potential increases in productivity, should unfettered AI usage be considered a good thing? Not in all cases, especially if a company is unaware of how AI is being used and lacks the governance to manage it effectively. Unfortunately, this is a common situation. Gartner found that nearly 70% of cybersecurity professionals suspected employees were using unsanctioned AI tools. If only half of those leaders are correct in their suspicions, it is not a good situation. CIOs can use their IOT asset management tool to identify unauthorized software across the network.
CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk
CISA established the Known Exploited Vulnerabilities (KEV) catalog in 2021. It was accompanied by BOD 22-01, directing agencies to aggressively patch bugs in the catalog within specific timeframes. It also required them to report the status of KEV vulnerabilities. Now the Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk builds on BOD 22-01 advance priorities in securing federal networks and outlines critical steps to aggressively strengthen them. Federal agencies are now required to monitor KEV catalog updates, address any new issues in the provided timelines, ensure ongoing vulnerability remediation and automate reporting of the status of KEV vulnerabilities, and inventory and tag externally accessible assets. An IT asset management tool can automate several of these tasks and provide real-time information in an agency s assets.
ServiceNow Patches Vulnerability Exploited Against Some Customers
Organizations widely use ServiceNow s cloud-based platform is for automating and managing workflows across various enterprise operations. In an advisory available to authenticated customers. The company indicated that a security update was installed on hosted customer instances on June 5. ServiceNow said that The update concerned a security issue that could allow an unauthenticated user, in certain circumstances, to gain greater access to ServiceNow instances than intended. The security update changes an endpoint configuration to limit access to authenticated users. We have detected anomalous activity relating to the security issue. For a subset of customers, we have observed evidence of successful queries of instance tables. We have notified customers if successful queries were observed via case.
Microsoft Working on Patch for RoguePlanet Zero-Day
The company s advisory reads Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as RoguePlanet (tracked as CVE-2026-50656 with a CVSS score of 7.8). Microsoft added that We are working to provide a high-quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available. IT professionals can identify vulnerable systems using the information from their IT asset management tools.
Manage Shadow IT and Shadow AI
Shadow IT van be defined as any technology being used by employees without management approval or oversight. in 1Password s 2025 annual report the company found that over 50% of employees have downloaded software without IT s approval. The report also found that nearly 25% of employees have used unsanctioned AI tools, and over a third of employees admit they don t always follow their company s AI policies. Vulnerability exploits and credential compromise are the leading attack vectors used to breach companies. Consequently, every unmanaged entry point represents risk. If IT management is not aware an application exists, they cannot manage or secure it. A robust IT asset management program can help IT professionals to locate and identify unauthorized software and take necessary actions to deal with it.
Microsoft Adds Another Year to Windows 10 Extended Update Program
Microsoft ended support for Windows 10 in 2025. However, the company is having a harder time than expected converting Windows 10 users to Windows 11. Microsoft recently changed its Windows 10 support policy, adding another year to its Extended Security Updates (ESU) program. Current Windows 10 don t have to do anything to enjoy that extra year. The Internet can be a dangerous place for unpatched Windows machines. As Windows 11 usage had only barely surpassed Windows 10 when support was terminated, it became a problem for Microsoft. Consequently, Microsoft gave everyone on the old OS a free year of extended updates. Microsoft recently updated its policy with pushing back the end of extended updates to October 12, 2027. The ESU support page was updated with that date. It professionals planning to convert to Windows can use the information generated by their IT asset management tools to identify Windows 10 systems and use the extra time to update those systems.
Industry News - May 2026
It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight
Microsoft's recent security update addressed no actively exploited zero-day vulnerabilities or previously disclosed flaws for the first time in almost two years. It did, however, contain fixes for over 130 CVEs. Microsoft considers 13 of them to be likely candidates for exploitation and 9of which are rated as critical. These include two in Microsoft Office Word and five others with severity scores of 9.8 or 9.9 on the 10-point CVSS scale. This is the third month this year where Microsoft has disclosed more than 100 CVEs in its Patch Tuesday update. IT professionals can identify unpatched and vulnerable systems using reports from their IT asset management tools.
The Rise of Shadow AI
Recent data suggests that the practice of employees using unsanctioned AI tools has spiraled out of control. A Microsoft survey of UK workers found that over 70% said they have used unapproved AI tools at work. According to Reco, an AI security platform, there are typically 200 unsanctioned AI tools being used per 1,000 workers At mid-size companies. A In a separate study Microsoft found that nearly 80% of workers using AI relied on their own tools. Leslie Nielsen, chief information security officer at Mimecast, refers to the rise of shadow AI to "death by a thousand cuts. For example, if someone uploads a document with confidential information to an AI tool, a chatbot or agent could reveal the data to someone outside the company. Case studies include Samsung where the company discovered software engineers put internal code into ChatGPT and Amazon which found ChatGPT's responses to some prompts mirrored internal company data. Companies can monitor systems using unauthorized AI tools by using their software discovery tools.
Fortinet Fixes Two Critical RCE Flaws in FortiAuthenticator and FortiSandbox
Fortinet recently released a number of patches across its product line. The patches included two critical vulnerabilities that can result to remote code execution. Fortinet flaws have been exploited in the wild many times in the past, so companies are encouraged to deploy patches as soon as possible. Piyush Sharma, CEO and co-founder of SecOps company Tuskira noted that Fortinet vulnerabilities are often attractive to threat actors because these products sit in high-trust security functions that threat actors often target. When a vulnerability affects a tool that already has privileged visibility or sits close to critical systems, exploitation can give attackers a much larger head start than a flaw in an ordinary application. The flaw in FortiAuthenticator, tracked as CVE-2026-44277, has a 9.1 CVSS severity score. The flaw in FortiSandbox also has a severity score of 9.1. In addition, Ivanti published four advisories relating to seven security defects impacting Ivanti Secure Access Client, Xtraction, Virtual Traffic Manager, and Endpoint Manager (EPM). The most severe of these is CVE-2026-8043 with a CVSS score of 9.6, which could be exploited remotely to read sensitive files and write arbitrary HTML files to a web directory. The company also resolved four other high-severity vulnerabilities. One expert noted that the five new vulnerabilities discovered in Ivanti s on-premises mobile endpoint management solution are a classic example of the legacy trap that CSOs must avoid. Robert Enderle of the Enderle Group added Patch today to survive the weekend but start planning your exit from legacy MDM as soon as possible. This isn t an isolated incident. It s a continuation of the cycle we saw in January, suggesting an underlying architecture struggling to withstand modern threats. The flaws are so serious that the US Cybersecurity and Infrastructure Security Agency (CISA) added one of the vulnerabilities to its Known Exploited Vulnerabilities Catalog as it s being actively exploited.
Exchange Server Zero-Day Vulnerability Can Be Triggered by Opening a Malicious Email
IT experts are declaring an emergency and urging CSOs to consider abandoning on-premises email solutions as a new zero-day vulnerability in Microsoft Exchange Server has been discovered. Rob Enderle of the Enderle Group warned that Because it s already being exploited in the wild, this isn t a patch next week situation; it s a mitigate right now emergency. Johannes Ullrich, dean of research at the SANS Institute added that This is another reminder to find a trusted cloud provider for e-mail. On-premises Exchange is becoming a legacy product, and while some organizations need it for internal and outbound email, its attack surface should be minimized by reducing its exposure to external email. Ullrich was responding to a recent alert from Microsoft about a cross-site scripting vulnerability affecting Exchange Outlook Web Access that could be exploited merely by sending a specially crafted email to a user. When the message is opened, and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
Vulnerabilities Have Become Cyber Attackers No. 1 Door to The Enterprise
Corporate patch management strategy may need a critical overhaul. Based on an examination of 31,000 incidents analyzed by Verizon s DBIR, flaw exploitation significantly outpaced credential abuse as the primary attack vector. Patching practices are coming under intense pressure, as time-to-exploit timeframes accelerate. This represents new reality which will likely worsen as AI assistance in attack chains rises. Verizon researchers found that exploited flaws were the root cause of breaches in over thirty percent of cases. Credential abuse resulted on over twelve percent of security failures. According to Verizon s study, only one in four critical vulnerabilities were fully remediated in 2025, with the median patch time rising to 43 days, up from 32 days the prior year. CIO s can utilize the information from their IT asset management tools to identify vulnerable and unpatched systems.
Industry News - Apr 2026
Disgruntled Researcher Leaks Bluehammer Windows Zero-Day Exploit
Exploit code has been released for an unpatched Windows privilege escalation flaw reported privately to Microsoft. The vulnerability allows attackers to gain SYSTEM or elevated administrator permissions. Called BlueHammer, the vulnerability was published by an independent security researcher The security issue has nopublished patch and no update to address it, the flaw is considered a zero-day by Microsoft's definition. Will Dormann, principal vulnerability analyst at Tharros confirmed that the BlueHammer exploit work. He noted that the flaw is a local privilege escalation that combines a time-of-check to time-of-use and a path confusion. The issue is not easy to exploit and that it gives a local attacker access to the Security Account Manager database, which contains password hashes for local accounts. Consequently, attackers can escalate to SYSTEM privileges and possibly achieve complete machine compromise. Dormann also noted that At that point, [the attackers] basically own the system, and can do things like spawn a SYSTEM-privileged shell. IT managers should be looking for a patch, and when issued use their IT asset management tools to identify vulnerable devices and patch them as soon as possible.
Fortinet Rushes Emergency Fixes for Exploited Zero-Day
The critical-severity flaw is tracked as CVE-2026-35616 , with a CVSS score of 9.1, is described as an improper access control issue. The vulnerability and could be exploited for remote code, execution. According to Fortinet, remote attackers could send crafted requests to a vulnerable FortiClient EMS to trigger the bug. The company noted that successful exploitation does not require authentication. The company warned that Fortinet has observed this to be exploited in the wild. Fortinet announced the availability of hotfixes to address the security defect in FortiClient EMS versions 7.4.5 and 7.4.6. Version 7.2 is not affected. Fortinet published detailed instructions on how to download and apply the hotfixes for both FortiClient EMS 7.4.5 and 7.4.6, and on how to verify that the hotfixes have been applied. IT professionals can utilize their IT asst management tools to identify unpatched systems.
How To Reduce Networking Costs Without Performance Loss
In addition, using hardware past its end of support increases costs and vulnerabilities. Costs also increase due to outages as older systems experience more failures. Also, legacy hardware is less power-efficient overall, costing more to operate. Network discovery and IT management tools can oftentimes pay for themselves by allowing management to identify systems that should be replaced. Savings can be realized by reducing on downtime, operating costs and reducingh cyber risk.
Industry News - Mar 2026
Shadow AI Rises as Leaders Choose Speed Over Governance
Without strong governance in place, companies risk hitting a plateau where large-scale transformational growth and innovation across the enterprise become increasingly difficult. That s the velocity paradox leaders are navigating today, balancing urgency with accountability. IT leaders can utilize the data from their IT asset management tools to determine the level id shadow-AI in their organization.
Software Vulnerabilities Are Being Weaponized Faster Than Ever
According to a report released Wednesday by VulnCheck, fewer than 1% of software vulnerabilities were exploited in the wild over the past year. However, those flaws were being weaponized faster and on a larger scale than ever before. Researchers tracked over 14,000 exploits linked to over10,000 unique CVEs in 2025. That represents over a 16% increase from the prior year. A large percentage of that increase was linked proof-of-concept code that was generated by AI. IT managers can scan for unpatched or vulnerable software using their IT asset management tools.
Shadow IT Has Entered the AI Era, and State and Local Governments Must Act Now
At a minimum, agencies should enforce policies that forbid the use of unauthorized AI agents on government networks or devices, prohibiting the provision of credentials, tokens or system access to unsanctioned AI tools and that all AI tools must be explicitly approved before any use. Management can use its IT asset management tools to identify unauthorized code in use across the network.
Microsoft Patches 83 Vulnerabilities
Microsoft s March 2026 Patch Tuesday updates resolve a single critical-severity flaw, (CVE-2026-21536 with a score of 9.8). It is a remote code execution weakness in Devices Pricing Program that has already been fully mitigated. The company stated that There is no action for users of this service to take. The purpose of this CVE is to provide further transparency. Another security defect that stands out is an elevation of privilege issue in Azure MCP Server Tools. It can be exploited by sending specially crafted input to a server tool that accepts user-supplied parameters. Fortra associate director Tyler Reguly noted that CSOs should ensure that they have solid asset inventories around the deployment of cloud-related systems and tools, so that admins know where these things exist and when they need to be fixed. This is the best way to empower your sys admins and security teams on a quiet month like this. A robust IT asset management solution is a critical tool in maintain an accurate inventory.
Emergency Microsoft Windows 11 Security Update Confirmed
The most recent Microsoft Patch Tuesday has been issued, however monthly security updates from Microsoft are still coming. The latest fix is an emergency, out-of-band, hot patch for a subset of Windows 11 enterprise users that addresses a number of critical security vulnerabilities that impact the Routing and Remote Access Service. The flaw could give attackers the ability to execute remote code and take control of the impacted device. These Common Vulnerabilities and Exposures are designated as CVE-2026-25172, CVE-2026-25173 and CVE-2026-26111. Unless patched, an attacker who is already authenticated on the domain could trick a domain-joined user to send a request to the malicious server via the RRAS snap-in. Even though a patch has already been made, the Patch Tuesday fix requires a device reboot. Oftentimes critical applications or services aren t open to rebooting on a whim, for obvious reasons. IT managers can use their IT asst management applications to identify vulnerable systems.
New KB5085516 Emergency Update Fixes Microsoft Account Sign-In
Microsoft recently issued an emergency update to address a major issue that breaks sign-ins with Microsoft accounts across multiple Microsoft apps. The problem occurs after installing the KB5079473 cumulative update that was part of this month's Patch Tuesday. It warns users that the affected devices are not connected to the Internet. The list of affected apps includes Teams and OneDrive, Microsoft Edge, Microsoft 365 Copilot, Excel and Word, which display the same error message for features that require a Microsoft account sign-in. IT managers can identify unpatched systems using their IT asset management tools.
32% Of Top-Exploited Vulnerabilities Are Over a Decade Old
Exploitation timelines continue to compress. Newly disclosed flaws reach active use almost immediately. In addition, older vulnerabilities remain active years after disclosure. Newly disclosed vulnerabilities move into active exploitation with little delay. Simultaneously, older vulnerabilities remain active. Long-term exposure also appears in broader vulnerability trends. Almost 40% of the top-targeted vulnerabilities affected end-of-life devices. Over 30% of vulnerabilities were at least 10 years old. These figures point to persistent gaps between vendor lifecycle timelines and enterprise patching practices. IT professionals can identify unpatched and vulnerable devices using the data generated by their IT asset management systems.