Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Sony AI robot beats players as humanoid robot wins Beijing race

    April 23, 2026

    10 GitHub Repositories To Master Claude Code

    April 23, 2026

    Microsoft issues emergency update for macOS and Linux ASP.NET threat

    April 23, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Microsoft issues emergency update for macOS and Linux ASP.NET threat
    Microsoft issues emergency update for macOS and Linux ASP.NET threat
    Tech Reviews

    Microsoft issues emergency update for macOS and Linux ASP.NET threat

    gvfx00@gmail.comBy gvfx00@gmail.comApril 23, 2026No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers to gain SYSTEM privileges on devices that use the Web development framework to run Linux or macOS apps.

    The software maker said Tuesday evening that the vulnerability, tracked as CVE-2026-40372, affects versions 10.0.0 through 10.0.6 of the Microsoft.AspNetCore.DataProtection NuGet, a package that’s part of the framework. The critical flaw stems from a faulty verification of cryptographic signatures. It can be exploited to allow unauthenticated attackers to forge authentication payloads during the HMAC validation process, which is used to verify the integrity and authenticity of data exchanged between a client and a server.

    Table of Contents

    Toggle
    • Beware: Forged credentials survive patching
      • Related posts:
    • If you're not playing music in the shower every morning, I think you need to start, because some of ...
    • NASA overhauls Artemis program, delaying Moon landing to 2028
    • This web app lets you 'channel surf' YouTube like a '90s kid watching cable

    Beware: Forged credentials survive patching

    During the time users ran a vulnerable version of the package, they were left open to an attack that would allow unauthenticated people to gain sensitive SYSTEM privileges that would allow full compromise of the underlying machine. Even after the vulnerability is patched, devices may still be compromised if authentication credentials created by a threat actor aren’t purged.

    “If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves,” Microsoft said. “Those tokens remain valid after upgrading to 10.0.7 unless the DataProtection key ring is rotated.”

    Microsoft describes ASP.NET Core as a “high-performance” web development framework for writing .Net apps that run on Windows, macOS, Linux, and Docker. The open-source package is “designed to allow runtime components, APIs, compilers, and languages [to] evolve quickly, while still providing a stable and supported platform to keep apps running.”

    Related posts:

    The all-electric Jeep Recon gets official specs and launch price

    All the new tech that caught our eye in Las Vegas

    Nvidia hits record $5 trillion mark as CEO dismisses AI bubble concerns

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe best Stranger Things season since 2019
    Next Article 10 GitHub Repositories To Master Claude Code
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    Kalshi suspended three political candidates from its platform for insider trading

    April 23, 2026
    Tech Reviews

    Sony’s New AI Robot Can Probably Beat You in Table Tennis

    April 22, 2026
    Tech Reviews

    The 12 best Garmin watch deals for running, swimming, and hiking at Amazon — save up to $250 on best-rated models

    April 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025138 Views

    BMW Will Put eFuel In Cars Made In Germany From 2028

    October 14, 202511 Views

    Best Sonic Lego Deals – Dr. Eggman’s Drillster Gets Big Price Cut

    December 16, 20259 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025138 Views

    BMW Will Put eFuel In Cars Made In Germany From 2028

    October 14, 202511 Views

    Best Sonic Lego Deals – Dr. Eggman’s Drillster Gets Big Price Cut

    December 16, 20259 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.