Skip to content

Remediating Windows vulnerabilities with a single tool

Matt Day Matt Day

Vulnerability Response is now available for Windows. Find, prioritize, and patch in one place, the same way you do for Mac.

Today you likely run one tool to find vulnerabilities and another to patch them, with someone keeping both honest in between. That someone is usually you.

With Vulnerability Management on Windows, that gap closes. Full visibility into software risk and autonomous response to patch what's vulnerable, in the same place you already manage Mac computers.

The remediation gap costs more than it used to

Attacks happen faster. Roughly 30% of vulnerabilities on the CISA KEV list get weaponized within 24 hours of disclosure. Verizon’s most recent Data Breach Investigations Report found vulnerability exploitation now drives 20% of breaches, up 34% year over year.

Every handoff between the time the vulnerability gets found and the time it gets patch is time your fleet stays exposed. Closing that handoff is the point of bringing scanning and patching into the same place.

Iru closes the remediation gap

Vulnerability Management gives you full visibility into software risk with automated response to patch vulnerable software. We've done this for Mac for a while. It's now live for Windows too.

In one console, Iru’s Vulnerability Management and Response finds the vulnerability, tells you what it means for your fleet, and fixes it. Set up the enforcement controls based on severity, and deploy in a few clicks.

  • Severity-based remediation: Set the remediation action per CVE severity: enforce the update immediately, enforce it on a timeframe you choose, or take no action.
  • Non-disruptive patching: Updates install silently when possible. If the app is open at the enforcement deadline, the user gets a countdown to save their work first.
  • Coverage beyond the patch catalog: 200+ of the most common Windows apps patch automatically through Auto Apps. Everything else runs through custom app library items, covering MSI, EXE, or PowerShell-based installs with the same enforcement logic.
  • Full visibility into what's actually vulnerable. Every installed application is inventoried, mapped against known CVEs in the National Vulnerability Database (NVD) and ranked by severity, with a flag for active exploitation in the wild. Each CVE tracks a status, active, remediated, or risk-accepted, with device-level counts, so you know what has been fixed.

The results show. For Mac, customer accounts running Vulnerability Response remediated 85.4% of critical and high severity vulnerabilities, against 64.8% for accounts without it, and cut median time to remediate from 2.58 days to 1.21 days.

One place, less of your time

Scanning and patching used to live in separate tools. Attackers didn't wait for you to catch up: they got faster at turning vulnerabilities into exploits.

Every step between "we found this" and "this is resolved" is exposure time, and time spent switching tools instead of closing the gap. With Vulnerability Management on Windows, you remediate the same way you already do on Mac, with the same results.

See what one console looks like against your own fleet. Book a demo and we'll walk through scanning, prioritization, and enforcement on Windows and Mac together.

Recent Articles

Featured image: Rustbot, the macOS malware used in the latest Rust Supply Chain Attack
Cristian Molina 10 min read

Rustbot, the macOS malware used in the latest Rust Supply Chain Attack

On August 20, 2026, attackers published malicious versions of three widely used Rust packages to crates.io, the official Rust package registry. On macOS, the payload is a remote access trojan (RAT) that collects cloud credentials, SSH keys, cryptocurrency wallet data, and browser profile information, then sends it to attacker-controlled infrastructure. It installs a launch agent to survive reboots and accepts follow-on commands from its operators. Once running, it decrypts its configuration, profiles the host, Reads the local browser stores, installs persistence via LaunchAgent, and beacons out. The packages were available for approximately two hours before removal. The attackers also withdrew the previous stable versions, which pushed automated dependency resolution toward the compromised releases. Any environment that compiled an affected project during that window should be treated as compromised. This blog documents Iru's analysis of the native Apple Silicon ARM64 implant.

Threat Intelligence
Featured image: Inside the screensharingd Bugs: How macOS Screen Sharing Went from Root File Access to Pre-Auth Compromise
Csaba Fitzl 6 min read

Inside the screensharingd Bugs: How macOS Screen Sharing Went from Root File Access to Pre-Auth Compromise

In late July 2026, a cluster of vulnerabilities in macOS Screen Sharing turned what initially looked like a fairly constrained privilege problem into one of the more interesting macOS remote-attack stories in years.

Threat Intelligence
Featured image: Apple is deprecating hdiutil in macOS 27 Golden Gate. Are your scripts ready?
Arek Dreyer 3 min read

Apple is deprecating hdiutil in macOS 27 Golden Gate. Are your scripts ready?

If you spent part of last weekend fielding Slack messages about hdiutil, you're not alone. Jeff Johnson's lapcatsoftware.com blog flagged that the man page for hdiutil in the macOS 27 Golden Gate beta now carries a deprecation notice:

Educational

See Iru in action

Discover why thousands of teams choose Iru

By submitting this form I agree to Iru’s Privacy Policy and consent to be contacted by Iru about its products and services.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.