News Grower

Independent coverage of AI, startups, and technology.

Ars Technica Apr 22, 2026 at 19:32 Big Tech Rising Hot

Microsoft issues emergency update for macOS and Linux ASP.NET threat

When authentication fails, things can go very, very wrong.

Signal weather

Rising

Momentum is building quickly, so this card is a good early entry point into the topic.

By Dan Goodin Original source
Microsoft issues emergency update for macOS and Linux ASP.NET threat

Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers to gain SYSTEM privileges on devices that use the Web development framework to run Linux or macOS apps. The software maker said Tuesday evening that the vulnerability, tracked as CVE-2026-40372, affects versions 10.0.0 through 10.0.6 of the Microsoft. AspNetCore. DataProtection NuGet, a package that’s part of the framework. The critical flaw stems from a faulty verification of cryptographic signatures. It can be exploited to allow unauthenticated attackers to forge authentication payloads during the HMAC validation process, which is used to verify the integrity and authenticity of data exchanged between a client and a server. Beware: Forged credentials survive patching During the time users ran a vulnerable version of the package, they were left open to an attack that would allow unauthenticated people to gain sensitive SYSTEM privileges that would allow full compromise of the underlying machine. Even after the vulnerability is patched, devices may still be compromised if authentication credentials created by a threat actor aren’t purged. Read full article Comments

Stay on the signal

Follow Microsoft issues emergency update for macOS and Linux ASP.NET threat

Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.

We send a confirmation link first, then only meaningful digests.

Story map

Understand this topic fast

A quick entry into the story: why it matters now, who is involved, and where to go next for context.

Why it matters now

Fresh coverage with immediate momentum.
There are already 6 connected articles in the same storyline to continue from here.
The story keeps orbiting around Ars Technica, Authentication, and Emergency, so the entity pages are the fastest way to build context.
Ars Technica already has 4 follow-up stories on the same theme.

Topic constellation

Open the live map for this story

See which entities, story threads, sources, and follow-up articles shape this story right now.

Click nodes to continue

Entity Cluster Article Hub Source

Story timeline

Continue with this story

A short sequence of events and follow-up stories to understand the arc quickly.

Apr 22, 2026 at 21:16 Ars Technica

Tesla reports Q1 2026 earnings: Still profitable

Car sales are up, battery sales and emissions credits are down.

Apr 22, 2026 at 20:27 Ars Technica

Lawsuit: Nintendo is getting tariff refunds—its customers should get them instead

Lawsuit demands Nintendo pass Trump tariff refunds on to its customers.

Apr 22, 2026 at 20:06 Ars Technica

RFK Jr. won't back CDC director on vaccines as agency scraps positive data

Kennedy's tesimony sets up another clash over vaccines with next CDC director.

Apr 22, 2026 at 19:42 Ars Technica

You want your Moon landings in HD? So does NASA—here's how it's happening.

"You just push this button, and in three hours, you're counting photons."

Apr 22, 2026 at 19:32 Ars Technica

Microsoft issues emergency update for macOS and Linux ASP.NET threat

When authentication fails, things can go very, very wrong.

Apr 22, 2026 at 18:34 Ars Technica

Anthropic tested removing Claude Code from the Pro plan

Untenable demand has Anthropic exploring new approaches to rationing its service.

How reliable this looks

Signal and trust for Ars Technica

This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.

Trusted

Reliability

92

Freshness

100

Sources in storyline

1

Related articles

More stories that share tags, source, or category context.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page