GUEST RESEACH: Microsoft patched a whopping 157 CVEs in its inaugural Patch Tuesday for 2025. Not only is this the largest number of CVEs patched in January, it is the largest number of CVEs patched across any Patch Tuesday release since 2017. Microsoft set a record in April 2024, patching 147 CVEs. Since 2017, the average number of CVEs patched in January was 60. Prior to 2025, the largest January Patch Tuesday release was 2023, which saw Microsoft patch 98 CVEs. In 2024, Microsoft opened the year with 48 CVEs patched. Please find below a comment from Satnam Narang, sr. staff research engineer at Tenable and a full analysis in this blog.
Microsoft has evidence of in-the-wild exploitation and/or public disclosure for eight of the vulnerabilities published today, with three listed on CISA KEV. This is now the fourth consecutive month where Microsoft has published zero-day vulnerabilities on Patch Tuesday without evaluating any of them as critical severity at time of publication. It also sees the publication of nine critical remote code execution (RCE) vulnerabilities. Unusually, no browser vulnerabilities have yet been published this month.
A well-known security researcher has slammed Microsoft for its "astonishingly bad" security advisories, pointing to the wording in a TCP/IP remote code execution vulnerability released on 10 August this year as an example.
A new version of the application mobility product VMware HCX has three features that the company believes will be particularly valuable for enterprise users.
There are special issues in ensuring an "always-on enterprise” in virtualised environments. Veeam has it covered.
Consumer and small business NAS vendor QNAP is moving into the enterprise market.
A new FlashArray from Pure Storage is offered as a standalone product and as part of a converged infrastructure building block for VMware or Hyper-V users.
It's now just 100 days before Windows Server 2003 goes out of support. Here's how one Australian college is benefiting from upgrading to Windows Server 2012 R2 before it had to.
New software with new capabilities for Tintri storage arrays is scheduled for release in the next few months.
HP has announced new storage options for customers moving towards a software-defined data centre.
CA Technologies' Project Oolong - a plan to provide unified data protection across conventional disk backup right through to high availability failover for servers - has become a reality with the arrival of CA arcserve Unified Data Protection.
Tintri's VMstore flash-based storage for virtualised and cloud environments will soon support Microsoft's Hyper-V.
Services provider Dimension Data has expanded its range of cloud services with a Windows-based private cloud offering.
The latest wave of product improvements from Hitachi Data Systems (HDS) cuts the total cost of ownership by up to 30% and enables performance of up to one million IOPS.
WatchGuard's XTMv unified threat management system now includes support for Microsoft's Hyper-V virtualisation software.
Videoconferencing specialist LifeSize has updated its UVC platform with full support for Hyper-V virtualisation, a new management application, and other improvements.
Dell has announced the 12th generation of its PowerEdge server family, with features designed to take advantage of Windows Server 2012.
New Flash Accel software from NetApp uses server-based flash storage to improve performance by up to 90%.
Kerio Connect 7.3 is a more appropriate messaging and collaboration server for organisations with between 50 and 500 employees than Microsoft Exchange or Google Apps, company officials claim.
Microsoft has announced that its patent-licensing deal with Novell, which expires in November this year, will be renewed for a further four years.
Most cybersecurity is making up for weak platforms. We need to address the fundamentals, design platforms that prevent out-of-bounds access[…]
For most developers the security/performance trade off is still the hardest one to tackle, even as the cost of processing[…]
RISC has been overhyped. While it is an interesting low-level processor architecture, what the world needs is high-level system architectures,[…]
There are two flaws that are widespread in the industry here. The first is that any platform or language should[…]
Ajai Chowdhry, one of the founders and CEO of HCL is married to a cousin of a cousin of mine.[…]