Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Amsterdam Developer Fesses Up To Using AI Assets

    June 11, 2026

    Apple TV’s Slow Horses Officially Returns With Season 6 Episodes This Fall

    June 11, 2026

    2027 Ford Explorer: What’s New?

    June 11, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Microsoft issues emergency update for macOS and Linux ASP.NET threat
    Microsoft issues emergency update for macOS and Linux ASP.NET threat
    Tech Reviews

    Microsoft issues emergency update for macOS and Linux ASP.NET threat

    gvfx00@gmail.comBy gvfx00@gmail.comApril 23, 2026No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers to gain SYSTEM privileges on devices that use the Web development framework to run Linux or macOS apps.

    The software maker said Tuesday evening that the vulnerability, tracked as CVE-2026-40372, affects versions 10.0.0 through 10.0.6 of the Microsoft.AspNetCore.DataProtection NuGet, a package that’s part of the framework. The critical flaw stems from a faulty verification of cryptographic signatures. It can be exploited to allow unauthenticated attackers to forge authentication payloads during the HMAC validation process, which is used to verify the integrity and authenticity of data exchanged between a client and a server.

    Table of Contents

    Toggle
    • Beware: Forged credentials survive patching
      • Related posts:
    • Unique Gifts for People Who Have Everything
    • Best Wi-Fi 7 Adapters: 2026's Top 5 Options
    • Feds seize $15 billion from alleged forced labor scam built on “human suffering”

    Beware: Forged credentials survive patching

    During the time users ran a vulnerable version of the package, they were left open to an attack that would allow unauthenticated people to gain sensitive SYSTEM privileges that would allow full compromise of the underlying machine. Even after the vulnerability is patched, devices may still be compromised if authentication credentials created by a threat actor aren’t purged.

    “If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves,” Microsoft said. “Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated.”

    Microsoft describes ASP.NET Core as a “high-performance” web development framework for writing .Net apps that run on Windows, macOS, Linux, and Docker. The open-source package is “designed to allow runtime components, APIs, compilers, and languages [to] evolve quickly, while still providing a stable and supported platform to keep apps running.”

    Related posts:

    Acasis FlowCore Series promises per-bay Thunderbolt 5 speed while challenging traditional multi-driv...

    UK government will buy tech to boost AI sector in $130M growth push

    The best smartwatches for 2025

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe best Stranger Things season since 2019
    Next Article 10 GitHub Repositories To Master Claude Code
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    Today’s NYT Strands Hints, Answer and Help for June 11 #830- CNET

    June 11, 2026
    Tech Reviews

    AMD exec says DDR5 RAM pricing won’t normalize until 2028 — and it’s sad that given other predictions, I feel this is overly optimistic

    June 11, 2026
    Tech Reviews

    Best Wi-Fi 7 Routers: 2026’s Top Five

    June 10, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025189 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025117 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202595 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025189 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025117 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202595 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.