Tag: update
-
September updates cause RDS failures on Windows Server
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-cause-rds-failures-on-windows-server/
-
September updates break audio on some Windows PCs
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-break-audio-on-some-windows-pcs/
-
Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages
Tags: updateThe Debian project shipped Debian 13.7 codenamed >>trixie.<< The project folded in 92 security advisories it had already published separately, added corrections to … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/14/debian-13-7-point-release/
-
Sicherheitslücke in Klimaanlage: Midea Portasplit bekommt ein wichtiges Update
Angreifer können die Klimaanlage Midea Portasplit ohne Anmeldung per Bluetooth steuern. Ein neues Firmware-Update korrigiert das. First seen on golem.de Jump to article: www.golem.de/news/klimaanlage-sicherheitsluecke-in-midea-portasplit-wird-geschlossen-2609-212963.html
-
Cyber Resilience Act trifft Frontier AI: Warum Unternehmen mehr Schwachstellen schneller managen müssen
Mit dem Cyber Resilience Act wird Schwachstellenmanagement zur Managementaufgabe. KI-gestützte Analysen entdecken mehr Sicherheitslücken in kürzerer Zeit zugleich erhöhen enge Meldefristen, wachsende Patch-Mengen und komplexe Lieferketten den operativen Druck. Unternehmen müssen deshalb Prozesse, Datenbasis und Wiederanlaufplanung jetzt auf kontinuierliche Cyberresilienz ausrichten. Management Summary Regulatorischer Zeitdruck: Ab 11. September 2026 greifen die Meldepflichten des Cyber… First…
-
BlueMoon: Neues Exploit-Kit nutzt Patch-Lücken für gezielte Angriffe
Sicherheitsforscher von Proofpoint haben eine gezielte Spearphishing-Kampagne entdeckt, bei der mehrere staatlich unterstützte Spionagegruppen ein neues Exploit-Kit namens BlueMoon einsetzen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/bluemoon-exploit-kit-patch-luecken
-
Microsoft Defender’s ShieldBreak Fix May Already Have Another Bypass
A researcher says ShieldCrash bypasses Microsoft’s latest Defender fix, extending a patch-and-bypass chain involving RoguePlanet and ShieldBreak. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-microsoft-defender-shieldcrash-patch-bypass/
-
GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
-
GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
-
GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
-
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026-65638, affects CSF versions 14.00 through 16.29 and has been addressed in version 16.30 and later. CSF is widely used on Linux servers and in cPanel/WHM environments…
-
Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code
GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution. The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September…
-
Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-teams-outlook-launch-failures-on-arm-windows-pcs/
-
Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection
Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities could allow authenticated attackers to trigger stored cross-site scripting (XSS), bypass Protected Rule authorization controls, or execute unintended SQL commands against configured backend databases under specific deployment conditions. All three vulnerabilities were disclosed on September…
-
Beschwerden häufen sich: Windows-Updates machen RDP-Verbindungen kaputt
Zahlreiche Nutzer können seit dem September-Patchday keine RDP-Verbindung mehr zu Windows-Servern aufbauen. Ein Fix ist noch nicht in Sicht. First seen on golem.de Jump to article: www.golem.de/news/beschwerden-haeufen-sich-windows-updates-machen-rdp-verbindungen-kaputt-2609-212898.html
-
CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance urging service providers to deliver timely, accurate, and transparent communications during major information technology (IT) and operational technology (OT) outages. The document, titled ‘Communicating Under Pressure: Best Practices for Service Providers’, was developed with the Federal Bureau of Investigation (FBI) and international partners.…
-
12 Best Server Security Solutions Compared (2026): Features Pricing
Quick Answer: CrowdStrike and SentinelOne lead server EDR; Trend Micro Deep Security owns virtual patching for unpatchable estates; Microsoft Defender for Servers is the per-resource anchor for Azure/hybrid; Bitdefender and ESET deliver efficacy at value. Server pricing runs per server/workload always confirm Linux feature parity. Servers are where ransomware crews head after the first phish:…
-
WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review
WordPress has launched an automated security review system that uses multiple AI models and Jetpack Scan to analyze every plugin release before distributing it to websites via the WordPress.org update API. This new control is designed to prevent vulnerable or malicious plugin updates from reaching millions of WordPress installations through dashboard-based, one-click updates. WordPress Blocks…
-
Ubuntu 24.04.5 LTS release patches security bugs across ten flavors
Tags: updateCanonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the >>Noble Numbat<< release. Anyone … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/11/ubuntu-24-04-5-lts-released/
-
Breach Roundup: ShinyHunters Claims Florida DMV Hack
Also, N-Able Patches Critical N-Central Zero-Day, Nightmare Eclipse Zero-Day. This week: ShinyHunters claims Florida DMV breach, N-able patch, Bimbo Bakeries breach, French police arrest suspected ZeroBytes hackers, Patch Tuesday, a new Nightmare Eclipse zero-day, Grindr agrees to $35 million U.K. privacy settlement, SAP patch. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-shinyhunters-claims-florida-dmv-hack-a-32792
-
4 Spy Groups Used BlueMoon on Chrome, Windows in One Week
Four spy groups used BlueMoon to chain Chrome and Windows zero-days in one week, showing why fast patching and post-compromise hunting matter. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-bluemoon-chrome-windows-exploit-kit/
-
September Windows Server updates break Remote Desktop Services
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/september-windows-server-updates-break-remote-desktop-services/
-
Microsoft Excel KB5002914 update breaks copy and paste for some users
Microsoft Excel users report that this week’s KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-excel-kb5002914-update-breaks-copy-and-paste-for-some-users/
-
CISA Updates Insider Threat Guide With New Mitigation Advice
CISA has updated its insider threat guide with new advice on remote work, AI and risk detection First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-updates-insider-threat-guide/
-
Chinese Hackers Deploy Chrome Zero-Day Exploit Chain
Chinese hackers launch Chrome zero-day exploit chain attacks against NGOs. Learn how this Chrome zero-day exploit chain exploits patch gaps. First seen on securityonline.info Jump to article: securityonline.info/chrome-zero-day-exploit-chain/
-
Chinese Hackers Deploy Chrome Zero-Day Exploit Chain
Chinese hackers launch Chrome zero-day exploit chain attacks against NGOs. Learn how this Chrome zero-day exploit chain exploits patch gaps. First seen on securityonline.info Jump to article: securityonline.info/chrome-zero-day-exploit-chain/
-
Chinese Hackers Deploy Chrome Zero-Day Exploit Chain
Chinese hackers launch Chrome zero-day exploit chain attacks against NGOs. Learn how this Chrome zero-day exploit chain exploits patch gaps. First seen on securityonline.info Jump to article: securityonline.info/chrome-zero-day-exploit-chain/
-
Four groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
Microsoft says September updates fix mouse settings reset issues
Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-resolves-mouse-settings-reset-bug-windows-11-update/
-
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
Tags: authentication, cisa, cisco, citrix, cve, cybersecurity, exploit, flaw, fortinet, infrastructure, kev, update, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.The vulnerabilities are listed below – CVE-2026-20079 (CVSS score: 10.0) – An authentication First seen…

