DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

July 2025 Patch Tuesday: Comment from Satnam Narang, Sr. Staff Research Engineer, Tenable

DigitalCIO Bureau by DigitalCIO Bureau
July 9, 2025
in Tech News
0
Microsoft Patch Tuesday 2023 Wrapped
75
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

“For the third consecutive July, Microsoft patched over 125 CVEs: 130 in 2023, 138 in 2024, and 127 in 2025. This month’s count is well above the average of 100 since July 2017. 

 “The 11-month streak of patching at least one zero day that was exploited in the wild ended this month. However, there was still one zero day patched this month.

 “While there were a few Microsoft SQL Server vulnerabilities patched this month, CVE-2025-49719, an information disclosure bug in SQL Server, was disclosed publicly prior to being patched. Despite its public disclosure, it is less likely to be exploited by an attacker. Users of SQL Server can update to the latest version, which includes driver fixes. However, if users have built their own apps or use software from another vendor that happens to use SQL Server, they need to update to Microsoft OLE DB Driver for SQL Server version 18 or 19 or ensure compatibility before updating. Microsoft has details in its advisory including a matrix for supported general distribution releases and cumulative update versions.

 “The highest-rated vulnerability this month is CVE-2025-47981, a remote code execution flaw in SPNEGO Extended Negotiation (NEGOEX), an extension of the SPNEGO negotiation mechanism used to allow for negotiating what security mechanism is used before authenticating. This is a peculiar bug because, while it is considered more likely to be exploited, it only affects Windows 10 version 1607 and above due to a specific group policy object being enabled by default. Since 2022, there haven’t been many flaws in SPNEGO NEGOEX. There was one in 2022 (CVE-2022-37958) and one earlier this year in January (CVE-2025-21295), both of which were rated as not likely to be exploited.

 “SharePoint continues to be a hot target: two new remote code execution bugs (CVE-2025-49701 and CVE-2025-49704) require prior authentication to a vulnerable SharePoint Server with Site Owner privileges at minimum to exploit these flaws. Each year, a large number of SharePoint bugs are disclosed across Patch Tuesday releases. So far in 2025, there have been 16 SharePoint flaws. In prior years, there were 20 in 2022, 25 in 2023 and 20 in 2024.

 “While not Patch Tuesday released, I’d be remiss not to highlight the concerns around CitrixBleed 2. CitrixBleed one was a significant flaw that had a long tail impact because of the ability for attackers to steal session tokens, which can’t be neutralised until they’ve been invalidated. CitrixBleed 2 also allows session token theft, which makes this just as severe as CitrixBleed. So even if an organisation has applied the available patches, if those session tokens are still valid, attackers can replay them back. It’s vital for organisations to not only apply the patches, but it is paramount to review log files for known indicators of compromise and invalidate session tokens promptly.” – Satnam Narang, sr. staff research engineer, Tenable

Tags: Satnam NarangTenable
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Cyera Secures $400M Series F, Hits $9B Valuation

by DigitalCIO Bureau
January 13, 2026
0
Cyera Secures $400M Series F, Hits $9B Valuation

Cyera has announced a $400 million Series F funding round, bringing its total funding to over $1.7 billion. This raise comes just six months after the previous round...

Read moreDetails

Trend Micro Closes Vulnerabilities in Apex Central

by DigitalCIO Bureau
January 9, 2026
0
Financial organizations receive an average of 2200+ application security vulnerability alerts every month: Dynatrace CISO Regional Bank 2023 report

The National Cyber ​​Security Centre (NCSC) is warning of vulnerabilities in Trend Micro Apex Central. These vulnerabilities could potentially cause a Denial-of-Service (DoS) attack. Updates addressing the vulnerability...

Read moreDetails

Aditya Birla Ventures invests in GenAI Company Articul8 AI

by DigitalCIO Bureau
January 9, 2026
0
AMD Acquires Open-Source AI Software Expert Nod.ai

Aditya Birla Ventures has announced its investment in the first tranche of Articul8 AI, Inc.’s oversubscribed Series B financing round. Articul8 AI, an enterprise generative AI (GenAI) software...

Read moreDetails

Snowflake Acquires Observe

by DigitalCIO Bureau
January 9, 2026
0
CRISIL To Acquire Bridge To India Energy

Snowflake has signed a definitive agreement to acquire Observe, a leader in AI-powered observability. With this acquisition, Snowflake will deliver the next generation of AI-powered observability, built on open standards...

Read moreDetails

CrowdStrike Acquires Identity Security Startup SGNL

by DigitalCIO Bureau
January 9, 2026
0
CrowdStrike Launches on Amazon Business

CrowdStrike has signed a definitive agreement to acquire SGNL, a leader in Continuous Identity. This acquisition will accelerate CrowdStrike’s leadership in Next-Gen Identity Security, enabling access for human, non-human (NHI),...

Read moreDetails
Next Post

Dassault Systèmes Acquires Ascon Qube To Extend Virtual Twin Offering

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Coforge and Newgen Elevates Partnership

Coforge and Newgen Elevates Partnership

September 25, 2023
Genesys and Salesforce Launch AI-Powered Customer Experience and Relationship Management Solution

Genesys and Salesforce Launch AI-Powered Customer Experience and Relationship Management Solution

September 11, 2023
Tata Elxsi, Telefónica achieve automation of cloud infra for telecoms

UiPath Unveils New Family of LLMs at AI Summit to Empower Enterprises to Harness Full Capabilities of GenAI

March 21, 2024

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud IBM Infographics Internet of Things (IoT) Kaspersky Microsoft New Relic NTT DATA NVIDIA Palo Alto Networks Panel Discussion Qlik Salesforce ServiceNow Sophos Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?