News Grower

Independent coverage of AI, startups, and technology.

Ars Technica Apr 22, 2026 at 19:32 Big Tech Stable Warm

Microsoft issues emergency update for macOS and Linux ASP.NET threat

When authentication fails, things can go very, very wrong.

Signal weather

Stable

The story has moved beyond the first headline and now acts as a reliable context anchor.

By Dan Goodin Original source
Microsoft issues emergency update for macOS and Linux ASP.NET threat

Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers to gain SYSTEM privileges on devices that use the Web development framework to run Linux or macOS apps. The software maker said Tuesday evening that the vulnerability, tracked as CVE-2026-40372, affects versions 10.0.0 through 10.0.6 of the Microsoft. AspNetCore. DataProtection NuGet, a package that’s part of the framework. The critical flaw stems from a faulty verification of cryptographic signatures. It can be exploited to allow unauthenticated attackers to forge authentication payloads during the HMAC validation process, which is used to verify the integrity and authenticity of data exchanged between a client and a server. Beware: Forged credentials survive patching During the time users ran a vulnerable version of the package, they were left open to an attack that would allow unauthenticated people to gain sensitive SYSTEM privileges that would allow full compromise of the underlying machine. Even after the vulnerability is patched, devices may still be compromised if authentication credentials created by a threat actor aren’t purged. Read full article Comments

Stay on the signal

Follow Microsoft issues emergency update for macOS and Linux ASP.NET threat

Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.

We send a confirmation link first, then only meaningful digests.

Story map

Understand this topic fast

A quick entry into the story: why it matters now, who is involved, and where to go next for context.

Why it matters now

This story is still moving and pulling follow-up coverage.
There are already 6 connected articles in the same storyline to continue from here.
The story keeps orbiting around Ars Technica, Authentication, and Emergency, so the entity pages are the fastest way to build context.
Ars Technica already has 4 follow-up stories on the same theme.

Topic constellation

Open the live map for this story

See which entities, story threads, sources, and follow-up articles shape this story right now.

Click nodes to continue

Entity Cluster Article Hub Source

Story timeline

Continue with this story

A short sequence of events and follow-up stories to understand the arc quickly.

Jun 8, 2026 at 17:20 Ars Technica

Man jailed for a month despite Flock showing he was 5 miles from crime scene

Cop seemingly ignored Flock camera timestamp to justify arrests.

Jun 8, 2026 at 16:56 Ars Technica

F1 in Monaco: Finally, the cars were flat-out in qualifying

The cars are too big to race well, but the competition for pole position is thrilling.

Jun 8, 2026 at 16:05 Ars Technica

A Falcon 9 booster turns 5 years old—and just set a remarkable reuse record

We take the Falcon 9 rocket for granted. But we probably shouldn't.

Jun 8, 2026 at 14:02 Ars Technica

Michigan politicians want to ban Chinese-badged cars from even visiting the US

The latest bill would ban day trips from Canada or Mexico in Chinese cars.

Jun 8, 2026 at 11:15 SecurityLab

Без Windows, без приложений, без привычного интерфейса. Microsoft придумала новый вид корпоративного гаджета — и уже нашла первых тестировщиков

Microsoft показала устройства, которые заменят обычный компьютер на работе.

Apr 22, 2026 at 19:32 Ars Technica

Microsoft issues emergency update for macOS and Linux ASP.NET threat

When authentication fails, things can go very, very wrong.

How reliable this looks

Signal and trust for Ars Technica

This source works at a steady pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.

Trusted

Reliability

92

Freshness

100

Sources in storyline

2

Related articles

More stories that share tags, source, or category context.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page