Patch [FIX] Tuesday – [AI Hits the Hat Trick], Ep. 32
Autonomous IT12 Touko

Patch [FIX] Tuesday – [AI Hits the Hat Trick], Ep. 32

The May 2026 Microsoft Patch Tuesday release looks quiet on the surface – no actively exploited zero-days, no public disclosures at release, and a CVE count below the four-month average. Don't let that fool you.

In this episode, Jason Kikta and Landon Miles break down everything that happened between April and May patch cycles, including Apple's macOS Tahoe 26.5 release with 79 CVEs, the Dirty Frag Linux kernel privilege escalation chain, and two pre-authenticated network remote code execution vulnerabilities in Windows core services that belong at the top of your patch list.

They also dig into one of the month's most significant trends: AI-assisted vulnerability research showing up by name in Microsoft, Apple, and Linux acknowledgments in the same patch cycle – including Anthropic researchers credited on a critical Windows graphics component RCE. Ten AI-attributed vulnerability discoveries shipped fixes across all three major operating systems this month.

What's covered:

  • CVE-2026-41089: Windows NetLogon RCE (CVSS 9.8) and CVE-2026-41096: Windows DNS Client RCE (CVSS 9.8)
  • CVE-2026-40402: Hyper-V guest-to-host escalation (CVSS 9.3)
  • macOS Tahoe 26.5: Wi-Fi kernel RCE, nine kernel CVEs, 20 WebKit vulnerabilities
  • Dirty Frag Linux privilege escalation chain and the Copy Fail connection
  • AI-credited discoveries from Anthropic, calif.io, Theori, and NIST's Center for AI Standards and Innovation


- Patch Tuesday Blog
- DirtyFrag Blog
- What "Mythos Ready" Means

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(227)

Autonomous IT, Live! Turn to Face the StrAInge, Patch Speed vs AI Attacks, E08

Autonomous IT, Live! Turn to Face the StrAInge, Patch Speed vs AI Attacks, E08

In April, Jason Kikta and Dmitri Alperovitch landed on a structural conclusion: AI had collapsed patch-to-exploit time to under an hour, 1-10-60 was no longer fast enough, and the only answer was prev...

25 Elo 42min

Patch [FIX] Tuesday – [Race Conditions, Registry Hives, and Cloud CVEs], Ep. 35

Patch [FIX] Tuesday – [Race Conditions, Registry Hives, and Cloud CVEs], Ep. 35

August 2026 delivers the second-largest Patch Tuesday on record with nearly 400 CVEs, and Landon Miles, Jason Kikta, and Serena DiPenti sort out which ones actually matter. They start with the only ac...

11 Elo 22min

Secure IT – PKI, Certificates, and What Breaks When Trust Fails, E22

Secure IT – PKI, Certificates, and What Breaks When Trust Fails, E22

Public Key Infrastructure (PKI) underpins nearly every secure interaction in modern IT, but it's also one of the most misunderstood and overlooked foundations of security.In this episode of Secure IT,...

22 Heinä 17min

Patch [FIX] Tuesday – [The 570-CVE Month], Ep. 34

Patch [FIX] Tuesday – [The 570-CVE Month], Ep. 34

570 vulnerabilities. That's July's Patch Tuesday count, nearly triple last month and a record by a wide margin. Jason Kikta is joined by host Landon Miles and offensive-security researcher Serena DiPe...

14 Heinä 29min

 Executive IT – What IT hiring actually looks like when AI does the work, E07

Executive IT – What IT hiring actually looks like when AI does the work, E07

Eighteen months after the Hands-On IT podcast tackled the state of IT careers, Chelsea Rickey, SVP of Human Resources at Automox, comes back to the conversation to assess what held up, what changed, a...

1 Heinä 15min

Product Talk – CISA's BOD 26-04 Directive Explained, E26

Product Talk – CISA's BOD 26-04 Directive Explained, E26

CISA's BOD 26-04 replaces severity-based patching with an exploit-evidence model and remediation clocks as short as three days, fleet-wide, no exceptions. Peter Pflaster and Jason Kikta unpack the fou...

11 Kesä 27min

Patch [FIX] Tuesday – [Nothing Weaponized, Everything Exposed], E33

Patch [FIX] Tuesday – [Nothing Weaponized, Everything Exposed], E33

June 2026 has no headliner. Instead of one critical bug, the release spreads thin across the kernel, the network stack, a code editor, an AI assistant, a bootloader, and a nine-year-old Linux root bug...

9 Kesä 23min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
rss-viihde-media
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
otetaan-yhdet
rss-voi-venaja
rss-vaalirankkurit-podcast
vallattomat
et-sa-noin-voi-sanoo-esittaa
rss-asiastudio
rss-podme-livebox
rss-kaikki-uusiksi
rss-girls-finish-f1rst
rss-raha-talous-ja-politiikka
rss-kuka-mina-olen
rss-seksicast
rss-mina-ukkola
tervo-halme