LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
nation-state

Certificate failures can cost firms over $250,000

The move toward 47-day public TLS certificates by 2029 will increase the certificate management workload for enterprises, according to DigiCert’s Certificate Management Outlook. Organizations will need to renew certificates more than eight times as often as under the previous certificate lifecycle and conduct 40 times as many domain validations. What certificate management challenges were listed a

zeroday.news ·

Enterprises face significant challenges and financial risks due to inadequate digital certificate management, with a substantial number experiencing costly service outages from expired or mismanaged certificates. A recent report indicates that nearly one in four organizations reported their most severe certificate incident cost over $250,000.

The report, based on a survey of IT and security leaders, highlights that 34% of companies have experienced a service outage due to an expired certificate, while 40% reported downtime linked to general certificate mismanagement. Nearly three-quarters of respondents endured at least five hours of downtime from certificate issues over the past year, with 21% experiencing 25 hours or more. These incidents are largely categorized as IT infrastructure issues by 57% of organizations, though 17% classify them as security incidents.

The volume of digital certificates is growing, with over half of organizations managing more than 1,000 certificates. This increasing volume, coupled with manual processes for issuance, renewal, deployment, and remediation, is significantly burdening IT teams. Almost half of organizations engage in certificate management tasks at least 12 times a year, and another 39% do so six to ten times annually. Key concerns include certificate expiration, maintaining customer trust, ensuring regulatory compliance, and managing certificates across multiple cloud environments and platforms.

A major impending change is the move towards 47-day public TLS certificates by 2029, a directive from the CA/Browser Forum aimed at enhancing Web PKI security by keeping certificate and validation information more current and reducing the window for compromised credentials. This shift will drastically increase the certificate management workload, requiring organizations to renew certificates more than eight times as often and conduct 40 times more domain validations compared to previous lifecycles.

Nearly three-quarters of IT and security leaders anticipate an increase in certificate volumes over the next two years, and 70% are actively preparing for shorter certificate lifespans. However, some organizations are aware of the changes but have not yet begun preparations. The need for automation is critical, as manual methods like spreadsheets and calendar reminders will not scale with the increased frequency of renewals.

Automated certificate lifecycle management is now a high cybersecurity priority, ranking third after AI-powered security operations and software threat detection and response. Beyond renewals, organizations are prioritizing DevOps integration for certificate management improvements, along with enhanced visibility, compliance, software supply chain security, and a reduction in manual work.

Despite the clear benefits, several barriers hinder the adoption of comprehensive certificate automation. Cost is a significant factor, with budget constraints limiting further investment, even though over half of organizations allocate more than 10% of their security budgets to certificate management. Other challenges include incompatibility with legacy systems, a lack of executive support, uncertainty regarding the business case or return on investment, and a shortage of technical expertise. Only 10% of surveyed organizations currently have full automation in place.

nation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.