Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Tesla’s revenue rises again as it prepares for more AI and robotics

    How SpaceX preempted a $2B fundraise with a $60B buyout offer

    The Iranian women Trump ‘saved’ from execution are simultaneously real and AI-manipulated

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • Shop
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    AI News TodayAI News Today
    Home»AI News»Microsoft issues emergency update for macOS and Linux ASP.NET threat
    AI News

    Microsoft issues emergency update for macOS and Linux ASP.NET threat

    By No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Microsoft issues emergency update for macOS and Linux ASP.NET threat
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers to gain SYSTEM privileges on devices that use the Web development framework to run Linux or macOS apps.

    The software maker said Tuesday evening that the vulnerability, tracked as CVE-2026-40372, affects versions 10.0.0 through 10.0.6 of the Microsoft.AspNetCore.DataProtection NuGet, a package that’s part of the framework. The critical flaw stems from a faulty verification of cryptographic signatures. It can be exploited to allow unauthenticated attackers to forge authentication payloads during the HMAC validation process, which is used to verify the integrity and authenticity of data exchanged between a client and a server.

    Beware: Forged credentials survive patching

    During the time users ran a vulnerable version of the package, they were left open to an attack that would allow unauthenticated people to gain sensitive SYSTEM privileges that would allow full compromise of the underlying machine. Even after the vulnerability is patched, devices may still be compromised if authentication credentials created by a threat actor aren’t purged.

    “If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves,” Microsoft said. “Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated.”

    Microsoft describes ASP.NET Core as a “high-performance” web development framework for writing .Net apps that run on Windows, macOS, Linux, and Docker. The open-source package is “designed to allow runtime components, APIs, compilers, and languages [to] evolve quickly, while still providing a stable and supported platform to keep apps running.”

    ASP.NET emergency issues Linux MacOS Microsoft threat update
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleGoogle updates Workspace to make AI your new office intern
    Next Article Elon Musk admits millions of Tesla owners need upgrades for true ‘Full Self-Driving’
    • Website

    Related Posts

    AI News

    How SpaceX preempted a $2B fundraise with a $60B buyout offer

    AI News

    Tesla just increased its capex to $25B. Here’s where the money is going.

    AI News

    Crypto scam lures ships into Strait of Hormuz, falsely promising safe passage

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Tesla’s revenue rises again as it prepares for more AI and robotics

    0 Views

    How SpaceX preempted a $2B fundraise with a $60B buyout offer

    0 Views

    The Iranian women Trump ‘saved’ from execution are simultaneously real and AI-manipulated

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Tesla’s revenue rises again as it prepares for more AI and robotics

    0 Views

    How SpaceX preempted a $2B fundraise with a $60B buyout offer

    0 Views

    The Iranian women Trump ‘saved’ from execution are simultaneously real and AI-manipulated

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.