threat-intel
Silent Patches Don’t Stop Attackers—They Blind Defenders
High
Summary
Broadcom’s new program offering early access to CVE-only patches for Spring Framework users is exacerbating the problem of silent patching. While Broadcom continues to issue CVEs, the program effectively provides pre-alerting to exploit intelligence for a price, enabling well-resourced attackers to operate with impunity within a larger ecosystem of targets. The practice of silently releasing patches, without full disclosure, hinders vulnerability management and detection efforts, leaving defenders with incomplete data and a significant disadvantage.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data