LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
patch

BleachBit 6.0.4 fixes secure wiping that skipped clusters on Windows

The open source cleaner BleachBit reached version 6.0.4 this week, erasing caches, browser traces, and files on Windows, Linux, and now macOS. If you shredded a sensitive file on Windows with an earlier build, parts of it may still sit on the disk where the wipe missed. Fragmentation is the ordinary case, since Windows scatters a file across noncontiguous clusters whenever it cannot find one open

zeroday.news ·

BleachBit, the open-source system cleaner, has released version 6.0.4, addressing a critical flaw in its secure file wiping functionality on Windows. Previous versions of the software could fail to securely erase entire files, leaving fragments of sensitive data on disk due to the way Windows stores files in non-contiguous clusters. The update does not specify which prior versions were affected or the extent of data that might have survived a wipe. Users who have shredded sensitive files on Windows with earlier builds are advised to wipe free space on their drives to mitigate the risk.

The new version also introduces several other security enhancements and new features. BleachBit 6.0.4 now supports macOS, offering a Safari cleaner and enabling existing cleaners for browsers like Google Chrome and Firefox on the platform. While command-line support is fully functional on macOS, the graphical user interface is still under development. On macOS, BleachBit will warn users if Full Disk Access is not enabled, use native notifications, and delete empty folders when cleaning the trash.

A significant privacy improvement targets "supercookies" that persist beyond standard cookie purges. BleachBit now deletes dynamic HSTS (HTTP Strict Transport Security) data in six Chromium-based browsers and in Zen, a Firefox derivative. HSTS lists, which record sites that mandate HTTPS, can be exploited by websites to store tracking identifiers that survive normal cookie clearing.

Security hardening measures have been implemented across various aspects of the software. Shredding arbitrary files now prevents operations on the working directory or its parent, closing a vulnerability where empty strings or directory shortcuts could cause unintended deletions. On POSIX systems, BleachBit explicitly refuses to delete critical system directories like /, /proc, /sys, and /run. The software also no longer follows symlinks during wiping operations, and on Windows, it rejects wiping files through symlinks and truncating reparse points. Malformed file URIs from the clipboard are now skipped during shredding, and the application issues a warning if a drive being shredded is world-writable, as this compromises the security of the wipe.

To prevent potential command injection and DLL preloading attacks, the Windows build now calls `ipconfig` and `taskkill` using their absolute paths. Untrusted cleaner definitions are restricted from executing process or Windows Registry actions, and on POSIX systems, cleaner files located in world-writable files or directories are no longer loaded. XML parsing entry points universally reject DTDs, and the update check parses its XML as bytes to ensure DTD rejection even with declared encodings. Insecure `winapp2` and update-check URLs are now refused, and the wildcard count in `winapp2.ini` glob patterns is capped to defend against regex denial-of-service attacks. SQLite and URI construction in `Special.py` have been hardened against injection, downloaded chaff models are checksummed, and URLs opened in a browser are restricted to `http` and `https` schemes.

When running as root, BleachBit sanitizes the `PATH` environment variable, removes code-loading environment variables for subprocesses, and strips `LD_LIBRARY_PATH` from the environment passed to external commands. Debug logs are created with `0600` permissions and download directories with `0700`. The development process itself has also seen security upgrades, with Windows builds and tests migrated from AppVeyor to GitHub Actions, the addition of a CodeQL workflow for bug detection, a static analysis workflow for the CI/CD pipeline, and a fix for a potential code injection during CI translation updates.

New cleaners have been added for Android Studio, the Gradle cache, the fish shell, Zsh, and Python command history. These history files can contain sensitive information, including credentials, making their secure deletion important on shared machines. The Claude cleaner now also removes top-level log files.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.