LIVE · cybersecurity feed
Live wire
patch

Microsoft confirms Windows Server Update Services sync delays

Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. [...]

zeroday.news · 12d ago

Microsoft has confirmed an ongoing issue affecting Windows Server Update Services (WSUS) servers, leading to extended synchronization times and operational timeouts. This problem, which began in recent days with a noticeable increase in impact starting July 13, 2026, prevents IT administrators from deploying the latest Windows updates via WSUS or Configuration Manager.

WSUS, a service designed to help organizations manage and distribute Microsoft product updates from a local server, typically synchronizes with Microsoft Update servers daily to retrieve update metadata. However, affected servers are unable to complete this synchronization, impacting both client platforms (Windows 10, version 1607 and later) and server platforms (Windows Server 2012 and later).

Microsoft has implemented initial mitigation measures on Saturday, July 18, 2026, which have reportedly restored normal synchronization times and operations for newly installed or rebuilt WSUS servers. However, the company is still developing additional mitigations for existing WSUS servers that were previously affected and continue to experience synchronization difficulties.

The company stated that it is working on steps to help customers safely remove affected metadata from their environments on these previously impacted servers.

This is not the first time WSUS has encountered issues. In May of the previous year, Microsoft addressed a similar problem that caused errors for enterprise customers attempting to update Windows 11 versions 22H2 and 23H2. Additionally, in July 2025, an issue preventing WSUS from syncing with Microsoft Update for the deployment of the latest updates was resolved. A month later, in August 2025, another problem that blocked the delivery of the August 2025 security update via WSUS was also fixed.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.