Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Emergency First Responders Say Waymos Are Getting Worse
    • Motorola Razr Fold vs. Samsung Galaxy Z Fold 7: How the Book-Style Phones Compare
    • Agentic AI: How to Save on Tokens
    • Lightweight ebike conversion kit electrifies your bike
    • Taylor Swift Wants to Trademark Her Likeness. These TikTok Deepfake Ads Show Why
    • New Releases on Prime Video in May 2026: Jack Reacher, Spider-Noir and More
    • 4 YAML Files Instead of PySpark: How We Let Analysts Build Data Pipelines Without Engineers
    • Metajets use light propulsion for future space travel
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Thursday, April 30
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Microsoft issues emergency update for macOS and Linux ASP.NET threat
    News

    Microsoft issues emergency update for macOS and Linux ASP.NET threat

    Editor Times FeaturedBy Editor Times FeaturedApril 23, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    Microsoft launched an emergency patch for its ASP.NET Core to repair a high-severity vulnerability that permits unauthenticated attackers to realize SYSTEM privileges on units that use the Net growth framework to run Linux or macOS apps.

    The software program maker said Tuesday night that the vulnerability, tracked as CVE-2026-40372, impacts variations 10.0.0 by 10.0.6 of the Microsoft.AspNetCore.DataProtection NuGet, a package deal that’s a part of the framework. The vital flaw stems from a defective verification of cryptographic signatures. It may be exploited to permit unauthenticated attackers to forge authentication payloads throughout the HMAC validation course of, which is used to confirm the integrity and authenticity of knowledge exchanged between a shopper and a server.

    Beware: Cast credentials survive patching

    In the course of the time customers ran a susceptible model of the package deal, they had been left open to an assault that might enable unauthenticated individuals to realize delicate SYSTEM privileges that might enable full compromise of the underlying machine. Even after the vulnerability is patched, units should still be compromised if authentication credentials created by a menace actor aren’t purged.

    “If an attacker used cast payloads to authenticate as a privileged consumer throughout the susceptible window, they might have induced the applying to concern legitimately-signed tokens (session refresh, API key, password reset hyperlink, and so forth.) to themselves,” Microsoft mentioned. “These tokens stay legitimate after upgrading to 10.0.7 until the DataProtection key ring is rotated.”

    Microsoft describes ASP.NET Core as a “high-performance” internet growth framework for writing .Internet apps that run on Home windows, macOS, Linux, and Docker. The open-source package deal is “designed to permit runtime parts, APIs, compilers, and languages [to] evolve shortly, whereas nonetheless offering a secure and supported platform to maintain apps operating.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

    April 29, 2026

    The European Commission issues preliminary DSA findings against Meta, saying Instagram and Facebook fail to prevent under-13 users from accessing the services (Gian Volpicelli/Bloomberg)

    April 29, 2026

    Alberta online gambling expansion sparks concern among First Nations casino operators

    April 29, 2026

    Better Markets urges courts to let states regulate prediction markets, not CFTC

    April 29, 2026

    Q&A with Sam Altman and AWS CEO Matt Garman about OpenAI’s new partnership with AWS, Bedrock Managed Agents, Trainium chips, and more (Ben Thompson/Stratechery)

    April 28, 2026

    Snapchat launches AI Sponsored Snaps, a conversational ad format in the Chat tab that lets users talk to brand-specific AI agents for product recommendations (Aisha Malik/TechCrunch)

    April 28, 2026
    Leave A Reply Cancel Reply

    Editors Picks

    Emergency First Responders Say Waymos Are Getting Worse

    April 29, 2026

    Motorola Razr Fold vs. Samsung Galaxy Z Fold 7: How the Book-Style Phones Compare

    April 29, 2026

    Agentic AI: How to Save on Tokens

    April 29, 2026

    Lightweight ebike conversion kit electrifies your bike

    April 29, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Clair Obscur Expedition 33 is game of the year

    December 12, 2025

    GHARAGE Ventures unveils €40 million Fund I, anchored by Gebr. Heinemann, to back travel and RetailTech startups

    March 4, 2026

    Svenska Spel faces new Spelinspektionen compliance probe amid ongoing regulatory scrutiny

    November 5, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.