← BACK TO FEED
TAG

patch management2 articles

ServiceNow RCE Flaw Exploited Within Days of Patch — But Who's Actually Behind It?

A critical remote code execution vulnerability in ServiceNow (CVE-2026-6875) is reportedly being exploited in the wild just days after patches were released on July 14 and technical details were publicly disclosed. Threat intelligence firm Defused observed exploitation activity on July 18, though closer analysis revealed the payload was identical to a published proof-of-concept rather than an independently developed exploit. ServiceNow states it has found no evidence of compromise on its hosted instances, and there is speculation the activity may originate from security researchers rather than malicious threat actors.

21 Jul 2026

One Researcher Is Making Microsoft's Life Very Difficult, Six Weeks Running

A security researcher known as "Nightmare Eclipse" has disclosed six Windows vulnerabilities over six weeks, including three new ones — YellowKey, GreenPlasma, and MiniPlasma — revealed shortly after Microsoft's May 2026 Patch Tuesday. These flaws target core Windows security components, enabling attacks such as BitLocker bypass, privilege escalation to SYSTEM, and exploitation of a vulnerability Microsoft believed it had patched in 2020. Microsoft has only officially patched one of the six flaws so far, and experts warn that the researcher's deliberate timing — releasing disclosures immediately after Patch Tuesday — maximises the window of exposure before the next patch cycle.

20 May 2026