Why disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.

Malwarebytes has completed a significant internal modernization effort, migrating its Windows endpoint security product to the .NET 10 runtime. This update, while largely invisible to end-users, is described as a foundational change aimed at enhancing security, performance, and maintainability.
The company emphasized that such platform upgrades are critical for security software, which operates with elevated privileges and interacts closely with the Windows operating system. A static platform, according to Malwarebytes, inevitably falls behind as Windows, threats, and hardware evolve. Modernizing the runtime allows for better security, faster code execution, reduced memory consumption, and improved diagnostic capabilities. It also provides engineers with updated language features and tooling, boosting efficiency.
Malwarebytes for Windows is a complex system comprising a user interface, multiple Windows services, an installer, a self-update mechanism, a plugin architecture, and third-party managed dependencies, all built upon native drivers and a detection engine. The .NET 10 migration specifically targeted the managed components, leaving the native core untouched, but required careful coordination to ensure all layers continued to function seamlessly together.
Key requirements for the migration included ensuring identical behavior for security-sensitive code, maintaining compatibility with native drivers and anti-tamper layers, correctly deploying new runtime files and cleaning up old ones via the installer and update pipeline, preserving compatibility with plugins and third-party dependencies, and ensuring existing installations remained functional. Particular attention was paid to the boundary between managed and native code, which communicates through interfaces like P/Invoke and COM, as subtle changes could manifest unpredictably across millions of endpoints.
The company outlined three primary drivers for dependency updates: elective modernization for new features or security improvements, baseline shifts necessitated by evolving platform requirements (such as the deprecation of Windows 7 support as part of this .NET 10 update), and forced patches due to disclosed vulnerabilities. Regardless of the reason, Malwarebytes applies the same rigorous approach to testing, release, and staged rollout.
The benefits of moving to .NET 10 include leveraging Microsoft's ongoing security work, such as safer defaults, stronger cryptography, and mitigations for memory and interoperability bugs. It also ensures the product remains on a supported, actively developed platform, simplifying future updates. Enhanced built-in tracing, metrics, and crash diagnostics in modern .NET improve the ability to identify and resolve reliability issues in the field. Furthermore, improvements in the just-in-time compiler, garbage collector, and core libraries are expected to yield performance and memory efficiency gains for background processes.
The migration process adhered to a principle of "never advance faster than the evidence allows." Work began on a dedicated branch, retargeting the platform and refreshing all managed dependencies. This early stage helped identify consequences such as renamed libraries or new file requirements. The deployment aspect was critical, requiring the installer and update service to adapt to the new runtime's file layout, removing obsolete dependencies and delivering replacements cleanly during both fresh installations and in-place updates.
Validation involved extensive automated testing across services, installation, and update paths; compatibility checks against real-world configurations; performance benchmarking to detect regressions in startup, memory, and scan behavior; and a staged deployment process starting with small user populations. Continuous monitoring and automated regression detection in the field were also integral. This cross-functional effort involved platform, quality assurance, installation and update, and release engineering teams. While the isolation of the migration protected the main codebase, it introduced the tradeoff of potential code drift.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets