Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Agentic AI: How to Save on Tokens
    • Lightweight ebike conversion kit electrifies your bike
    • Taylor Swift Wants to Trademark Her Likeness. These TikTok Deepfake Ads Show Why
    • New Releases on Prime Video in May 2026: Jack Reacher, Spider-Noir and More
    • 4 YAML Files Instead of PySpark: How We Let Analysts Build Data Pipelines Without Engineers
    • Metajets use light propulsion for future space travel
    • Malta’s startup residency: A pathway for founders expanding into Europe (Sponsored)
    • Sanctioned Chinese AI Firm SenseTime Releases Image Model Built for Speed
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Wednesday, April 29
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Microsoft issues emergency update for macOS and Linux ASP.NET threat
    News

    Microsoft issues emergency update for macOS and Linux ASP.NET threat

    Editor Times FeaturedBy Editor Times FeaturedApril 23, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    Microsoft launched an emergency patch for its ASP.NET Core to repair a high-severity vulnerability that permits unauthenticated attackers to realize SYSTEM privileges on units that use the Net growth framework to run Linux or macOS apps.

    The software program maker said Tuesday night that the vulnerability, tracked as CVE-2026-40372, impacts variations 10.0.0 by 10.0.6 of the Microsoft.AspNetCore.DataProtection NuGet, a package deal that’s a part of the framework. The vital flaw stems from a defective verification of cryptographic signatures. It may be exploited to permit unauthenticated attackers to forge authentication payloads throughout the HMAC validation course of, which is used to confirm the integrity and authenticity of knowledge exchanged between a shopper and a server.

    Beware: Cast credentials survive patching

    In the course of the time customers ran a susceptible model of the package deal, they had been left open to an assault that might enable unauthenticated individuals to realize delicate SYSTEM privileges that might enable full compromise of the underlying machine. Even after the vulnerability is patched, units should still be compromised if authentication credentials created by a menace actor aren’t purged.

    “If an attacker used cast payloads to authenticate as a privileged consumer throughout the susceptible window, they might have induced the applying to concern legitimately-signed tokens (session refresh, API key, password reset hyperlink, and so forth.) to themselves,” Microsoft mentioned. “These tokens stay legitimate after upgrading to 10.0.7 until the DataProtection key ring is rotated.”

    Microsoft describes ASP.NET Core as a “high-performance” internet growth framework for writing .Internet apps that run on Home windows, macOS, Linux, and Docker. The open-source package deal is “designed to permit runtime parts, APIs, compilers, and languages [to] evolve shortly, whereas nonetheless offering a secure and supported platform to maintain apps operating.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

    April 29, 2026

    The European Commission issues preliminary DSA findings against Meta, saying Instagram and Facebook fail to prevent under-13 users from accessing the services (Gian Volpicelli/Bloomberg)

    April 29, 2026

    Alberta online gambling expansion sparks concern among First Nations casino operators

    April 29, 2026

    Better Markets urges courts to let states regulate prediction markets, not CFTC

    April 29, 2026

    Q&A with Sam Altman and AWS CEO Matt Garman about OpenAI’s new partnership with AWS, Bedrock Managed Agents, Trainium chips, and more (Ben Thompson/Stratechery)

    April 28, 2026

    Snapchat launches AI Sponsored Snaps, a conversational ad format in the Chat tab that lets users talk to brand-specific AI agents for product recommendations (Aisha Malik/TechCrunch)

    April 28, 2026
    Leave A Reply Cancel Reply

    Editors Picks

    Agentic AI: How to Save on Tokens

    April 29, 2026

    Lightweight ebike conversion kit electrifies your bike

    April 29, 2026

    Taylor Swift Wants to Trademark Her Likeness. These TikTok Deepfake Ads Show Why

    April 29, 2026

    New Releases on Prime Video in May 2026: Jack Reacher, Spider-Noir and More

    April 29, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Gambling Is Not Investing coalition challenges prediction markets over sports betting consumer protections

    March 3, 2026

    Crypto.com quietly discloses that customers will face three-second delay on sports wagers

    December 10, 2025

    Student Solves a Long-Standing Problem About the Limits of Addition

    June 29, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.