Tag: update
-
WordPress adds automated security checks to block risky plugin releases
WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/wordpress-automated-plugin-security-review/
-
Nutzerbeschwerden: Kopierfunktion in Excel nach Office-Update kaputt
Im Netz häufen sich Beschwerden von Nutzern, die in Excel nicht mehr kopieren können. Ursache scheint ein Bug im neuen Microsoft-Office-Update zu sein. First seen on golem.de Jump to article: www.golem.de/news/nutzerbeschwerden-kopierfunktion-in-excel-nach-office-update-kaputt-2609-212865.html
-
Microsoft fixes bug that wiped Windows desktop settings
Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bug-that-wiped-windows-desktop-settings/
-
12 Best Patch Management Software Compared (2026): Features Pricing
Quick Answer: The best patch management software in 2026 depends on your estate: Action1 offers a genuinely free tier for smaller fleets, NinjaOne and Automox lead cloud-native automation, ManageEngine wins on third-party catalog value, and Tanium rules very large enterprises. Most tools price per endpoint per month or year. Unpatched known vulnerabilities remain one of…
-
Shieldcrash: Forscher ärgert Microsoft mit neuem Defender-Exploit
Microsofts High-Quality-Update gegen den Shieldbreak-Exploit ist offenbar wenig effektiv. Ein frisch geleakter Exploit umgeht den Schutz. First seen on golem.de Jump to article: www.golem.de/news/shieldcrash-forscher-aergert-microsoft-mit-neuem-defender-exploit-2609-212855.html
-
Microsoft Fixes 974 CVEs in Record Patch Tuesday Release
Microsoft fixed a record 974 CVEs for September’s Patch Tuesday, including two actively exploited Windows flaws. Most of the vulnerabilities addressed in the September release affect Windows, but the update also covers Office, SQL Server, Exchange Server, SharePoint Server, Azure and developer tools. Microsoft urged customers to apply the updates quickly and specifically called out..…
-
4 groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
4 groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
4 groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/
-
Microsoft’s September Patch Tuesday Fixes Nearly 1,000 Flaws, Including 2 Exploited Zero-Days
Microsoft’s September 2026 Patch Tuesday fixes nearly 1,000 vulnerabilities, including two Windows zero-days already exploited in attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-microsoft-september-2026-patch-tuesday-zero-days/
-
CVE-2026-75650 Adobe Commerce Zero-Day: Patch Isn’t Enough
Adobe patched the actively exploited CVE-2026-75650 Magento zero-day, but compromised stores still need malware hunting and broad credential rotation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-adobe-commerce-cve-2026-75650-stylesmuggler/
-
Patch Tuesday: Microsoft updates address almost 1,000 flaws
Microsoft has released another record-breaking Patch Tuesday update with almost 1,000 flaws in scope First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650022/Patch-Tuesday-Microsoft-updates-address-almost-1000-flaws
-
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Today is Microsoft’s September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
-
Windows 11 cumulative updates KB5124008 & KB5122880 released
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-cumulative-updates-kb5124008-and-kb5122880-released/
-
N-able issues patch for zero-day flaw
Security researchers warned the company of unusual threat activity in a recently patched N-able environment. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/n-able-issues-patch-zero-day-flaw/829808/
-
August updates trigger 0xc0000409 errors on Windows Server 2016
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/august-updates-trigger-0xc0000409-errors-on-windows-server-2016/
-
Chrome is now shipping updates every 2 weeks as AI changes the security landscape
Google is speeding up Chrome’s release schedule to ship security patches and new features faster. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/08/chrome-is-now-shipping-updates-every-2-weeks-as-ai-changes-the-security-landscape/
-
SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/
-
Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access
Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions…
-
Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access
Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions…
-
ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access
ASUS has released a security update for the Control Center Express Agent to address CVE-2026-19397, a high-severity vulnerability related to missing authentication. This vulnerability allows an unauthenticated nearby attacker to potentially take control of an affected host through a direct connection to the agent. The issue affects versions before 1.7.24 and was published and updated…
-
SAP September 2026 Security Update Fixes 4 Critical Vulnerabilities and 15 Other Flaws
SAP released 19 new Security Notes addressing four critical vulnerabilities and 15 additional flaws throughout its enterprise portfolio. The vendor also updated one note from August. The most urgent issue is CVE-2026-44756, a memory-corruption vulnerability in Extended Passport (EPP) Processing with a CVSS score of 10.0. This flaw affects numerous SAP Kernel and Web Dispatcher…
-
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe”¯Commerce and”¯Magento Open Source that has come under active exploitation in the wild.The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.”This update resolves a critical First seen on thehackernews.com…
-
MikroTik RouterOS Vulnerabilities Actively Exploited via SSH
Attackers are actively exploiting MikroTik RouterOS flaws for unauthenticated router takeover. Here are the fixes, indicators of compromise, and post-patch checks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-mikrotik-routeros-mikrotrick-ssh-exploit/
-
Manipulierte Updates über Videokonferenzserver – Head Mare verteilt Backdoors über trojanisierte TrueConf-Installer
First seen on security-insider.de Jump to article: www.security-insider.de/head-mare-trueconf-server-manipulierte-installer-backdoor-update-a-751be3fc2f76f3d4c79eb459ee080c3d/
-
Your Storage Was Hardened Once. It Isn’t Anymore.
Configuration drift: the silent creator of security risk in storage and backup systems. Every storage and backup environment drifts. Firmware updates reset settings back to their defaults. Temporary changes made during an outage never get reverted. A vendor account created… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/your-storage-was-hardened-once-it-isnt-anymore/
-
ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions
ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue affects both cloud-hosted and on-premises ScreenConnect deployments. In response, the company has issued immediate mitigation guidance. At the same time, it is working on an official patch and securing a CVE identifier. The advisory, released…
-
ConnectWise warns of new ScreenConnect flaw without patch
ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/connectwise-warns-of-new-screenconnect-flaw-without-patch/
-
Roundcube Fixes 12 Security Flaws Including Zero-Click XSS and SSRF Bypass
Roundcube has released security updates 1.6.19 and 1.7.4, which address 12 vulnerabilities affecting its 1.6 LTS and 1.7 Webmail branches. The flaws include a zero-click stored cross-site scripting (XSS) vulnerability, several bypasses of remote content filtering, email header injection bugs, cross-user contact access issues, and a server-side request forgery (SSRF) bypass. Published on September 6,…

