news.mlab.sh
Back to the feed
threat-intel

Silent Patches Don’t Stop Attackers—They Blind Defenders

High
Summary

Broadcom’s new program offering early access to CVE-only patches for Spring Framework users is exacerbating the problem of silent patching. While Broadcom continues to issue CVEs, the program effectively provides pre-alerting to exploit intelligence for a price, enabling well-resourced attackers to operate with impunity within a larger ecosystem of targets. The practice of silently releasing patches, without full disclosure, hinders vulnerability management and detection efforts, leaving defenders with incomplete data and a significant disadvantage.

Read the full article at SecurityWeek

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.