Tag: update
-
Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help
Microsoft’s August 2026 Patch Tuesday included a fix for CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The severity has a CVSS score of 8.0 from Microsoft. As of September 1, threat intelligence group Shadowserver has… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/microsoft-exchange-vulnerability-cve-2026-62911-what-administrators-should-do-and-how-zscaler-can-help/
-
Sangoma Switchvox Flaw Under Attack: 4,000 VoIP Systems Exposed
Hackers are exploiting a critical Sangoma Switchvox flaw that enables unauthenticated remote code execution. Admins should patch and check for compromise. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-sangoma-switchvox-cve-2026-9586-rce/
-
Sangoma Switchvox Flaw Under Attack: 4,000 VoIP Systems Exposed
Hackers are exploiting a critical Sangoma Switchvox flaw that enables unauthenticated remote code execution. Admins should patch and check for compromise. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-sangoma-switchvox-cve-2026-9586-rce/
-
SonicWall SMA1000 Zero-Days Under Active Attack: Patch Now
SonicWall says attackers are actively exploiting two SMA1000 vulnerabilities that can be chained for unauthenticated remote code execution. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-sonicwall-sma1000-zero-days-active-attack/
-
Financial firms face ‘vulnerability bottlenecks’ from frontier AI
The Financial Conduct Authority warns that frontier AI models are finding security vulnerabilities faster than firms can patch them First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650080/Financial-firms-face-vulnerability-bottlenecks-from-frontier-AI
-
KB5120998 mouse reset bug affects only non-English PCs
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/
-
SonicWall urges immediate patching of chained vulnerabilities
Just weeks after a wave of ransomware attacks, new flaws in SMA1000 series appliances are being exploited. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/sonicwall-immediate-patching-chained-vulnerabilities/829567/
-
Recent Update to FAQ Regarding SAQ Eligibility Criteria Could Affect Your PCI DSS Compliance
Recent Update to FAQ Regarding SAQ Eligibility Criteria Could Affect Your PCI DSS Compliance September 3, 2026 Dan Mengel BLOG 5 min. What Happened On August 31, 2026, the PCI Security Standards Council (PCI SSC) updated FAQ 1331 on its website…. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/recent-update-to-faq-regarding-saq-eligibility-criteria-could-affect-your-pci-dss-compliance/
-
Microsoft says KB5120998 Windows update resets desktop settings
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-says-kb5120998-windows-update-resets-desktop-settings/
-
Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted kernel-mode code and drivers can run on supported systems. Memory Integrity is a security feature built on Virtualization-based Security (VBS), a Windows…
-
Plex warns users to patch security vulnerabilities immediately
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/
-
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/
-
Critical Cisco Nexus 9000 Flaw Lets Remote Attackers Execute Code as Root Without Authentication
Cisco has released security updates addressing a critical vulnerability in Nexus 9000 Series switches that could allow unauthenticated remote attackers to execute arbitrary code with root privileges. This vulnerability, tracked as CVE-2026-20212, has a CVSS score of 9.8 and affects Nexus 9000 platforms that are equipped with Cisco Silicon One ASICs. Cisco Nexus 9000 Flaw…
-
Google Unveils Gemini 3.8 Flash Cyber for Autonomous Vulnerability Discovery and Automated Patching
Google has introduced Gemini 3.8 Flash Cyber, a specialized AI model focused on cybersecurity. This model is designed to autonomously identify software vulnerabilities, generate code fixes, and validate patches before deployment. Access to this model is restricted to vetted defenders through Google’s new Fairwind Program, which aims to provide advanced cyber capabilities to government agencies,…
-
Windows memory integrity switches on automatically for eligible devices in October 2026
Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/03/windows-memory-integrity-update/
-
Google Launches Fairwind Program for Gemini 3.8 Flash Cyber Access
Google launched a new program Wednesday that gives select organizations access to a more capable version of Gemini designed to find and patch software vulnerabilities. The Fairwind Program combines Google’s new Gemini 3.8 Flash Cyber model with CodeMender, its AI agent for vulnerability remediation. Google said Fairwind initially includes government agencies, Google Cloud customers and..…
-
Google Launches Fairwind Program for Gemini 3.8 Flash Cyber Access
Google launched a new program Wednesday that gives select organizations access to a more capable version of Gemini designed to find and patch software vulnerabilities. The Fairwind Program combines Google’s new Gemini 3.8 Flash Cyber model with CodeMender, its AI agent for vulnerability remediation. Google said Fairwind initially includes government agencies, Google Cloud customers and..…
-
Google Launches Fairwind Program for Gemini 3.8 Flash Cyber Access
Google launched a new program Wednesday that gives select organizations access to a more capable version of Gemini designed to find and patch software vulnerabilities. The Fairwind Program combines Google’s new Gemini 3.8 Flash Cyber model with CodeMender, its AI agent for vulnerability remediation. Google said Fairwind initially includes government agencies, Google Cloud customers and..…
-
Google Launches Fairwind Program for Gemini 3.8 Flash Cyber Access
Google launched a new program Wednesday that gives select organizations access to a more capable version of Gemini designed to find and patch software vulnerabilities. The Fairwind Program combines Google’s new Gemini 3.8 Flash Cyber model with CodeMender, its AI agent for vulnerability remediation. Google said Fairwind initially includes government agencies, Google Cloud customers and..…
-
Google Launches Fairwind Program for Gemini 3.8 Flash Cyber Access
Google launched a new program Wednesday that gives select organizations access to a more capable version of Gemini designed to find and patch software vulnerabilities. The Fairwind Program combines Google’s new Gemini 3.8 Flash Cyber model with CodeMender, its AI agent for vulnerability remediation. Google said Fairwind initially includes government agencies, Google Cloud customers and..…
-
Google Launches Fairwind Program for Gemini 3.8 Flash Cyber Access
Google launched a new program Wednesday that gives select organizations access to a more capable version of Gemini designed to find and patch software vulnerabilities. The Fairwind Program combines Google’s new Gemini 3.8 Flash Cyber model with CodeMender, its AI agent for vulnerability remediation. Google said Fairwind initially includes government agencies, Google Cloud customers and..…
-
SonicWall advises customers to patch two new SMA1000 zero-days
First seen on scworld.com Jump to article: www.scworld.com/news/sonicwall-advises-customers-to-patch-two-new-sma1000-zero-days
-
SonicWall advises customers to patch two new SMA1000 zero-days
First seen on scworld.com Jump to article: www.scworld.com/news/sonicwall-advises-customers-to-patch-two-new-sma1000-zero-days
-
VMware enhances AI security with AgentMinder and vDefend updates
First seen on scworld.com Jump to article: www.scworld.com/brief/vmware-enhances-ai-security-with-agentminder-and-vdefend-updates-1
-
Shadow AI: What Clients Aren’t Telling Their MSPs
MSPs are expected to understand their clients’ technology environments. They know which endpoints are managed, which applications are business-critical, which systems require patching or maintenance, where sensitive data resides and who has access to it. Increasingly, however, critical technology decisions… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/shadow-ai-what-clients-arent-telling-their-msps/
-
Shadow AI: What Clients Aren’t Telling Their MSPs
MSPs are expected to understand their clients’ technology environments. They know which endpoints are managed, which applications are business-critical, which systems require patching or maintenance, where sensitive data resides and who has access to it. Increasingly, however, critical technology decisions… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/shadow-ai-what-clients-arent-telling-their-msps/
-
Fake Software Update Installs a Real Crypto Wallet Rigged So It Can Never Open
Security researchers at Huntress have discovered a malware campaign that tricks victims into installing a real, fully functional copy of Exodus, a popular cryptocurrency wallet application, only to disable it so it can never actually be opened, using it instead as cover for a hidden spying tool. The firm said it identified four separate organisations…
-
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.”The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft First seen on thehackernews.com Jump to article: thehackernews.com/2026/09/fake-software-installers-disable.html
-
What a 14-Day Federal Patch Clock Costs a Team That Isn’t a Federal Agency
(MLflow, CVE-2026-64849, August 2026)By Pablo Bleck, Engineering Manager & Software Engineer, ActiveStateMLflow shipped its webhook API open by default across a platform with more than 30 million monthly downloads, and a CISA listing turned that unauthenticated endpoint into a 14-day… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/what-a-14-day-federal-patch-clock-costs-a-team-that-isnt-a-federal-agency/
-
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that…

