patch news
306 stories · page 2 of 7
New infosec products of the week: September 11, 2026
Several cybersecurity vendors have announced new product releases this week, focusing on areas such as AI agent security, exposure management, and third-party risk. These new offerings aim to address evolving threats and operational challenges faced by security teams.

September Windows Server updates break Remote Desktop Services
Microsoft's September 2026 cumulative updates are reportedly causing widespread failures in Remote Desktop Services (RDS) across various Windows Server versions, preventing users from connecting to servers and, in some cases, necessitating hard reboots to restore functionality. The issues have been observed on Windows Server 2019, 2022, and 2025 systems following the installation of the…

CISA Updates Insider Threat Guide With New Mitigation Advice
The Cybersecurity and Infrastructure Security Agency (CISA) released an updated version of its Insider Threat Mitigation Guide on September 9. The revised guide, first issued in 2020, incorporates new case studies, statistics, and specific guidance addressing the evolving landscape of workplace risks, including hybrid and remote work models, the use of artificial intelligence, and adverse…

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
Multiple cyberespionage groups, primarily those with suspected ties to China, have been observed deploying a new exploit kit, dubbed "BlueMoon," which chains together three vulnerabilities in Chromium-based browsers and Microsoft Windows. The kit was first detected in late August and has since been used to target fewer than 20 organizations globally, though the actual number is likely higher.

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
Fortinet has released patches addressing critical vulnerabilities found in its FortiMonitorOnSight product and a related Chrome extension. The reported flaws are described as critical and unauthenticated, enabling attackers to bypass authentication mechanisms and potentially proxy a user's browser traffic.

Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
Microsoft's September 2026 Patch Tuesday release included fixes for a record-breaking 974 Common Vulnerabilities and Exposures (CVEs), significantly surpassing its previous record of 570 CVEs set in July 2026. This substantial increase in patched vulnerabilities follows a warning issued by Microsoft in July, advising customers to anticipate a surge in security updates for Windows products due…

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google has reportedly issued an urgent update for its Chrome browser, addressing a critical zero-day vulnerability that has been actively exploited in the wild. The flaw, identified as an out-of-bounds write bug within the V8 JavaScript and WebAssembly engine, allows for code execution within the browser's sandbox environment. This update is part of a broader patch release addressing numerous…

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
Microsoft's September 2026 Patch Tuesday release included a record number of fixes, addressing two zero-day vulnerabilities that have been actively exploited in the wild. The update also contained patches for several other critical issues, including a cluster of 20 "wormable" bugs and a DNS flaw described as a successor to SigRed.

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
A critical pre-authentication remote code execution (RCE) vulnerability affecting N-able N-central has been observed under active exploitation in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating that Federal Civilian Executive Branch (FCEB) agencies patch affected systems by September…

BleachBit 6.0.4 fixes secure wiping that skipped clusters on Windows
BleachBit, the open-source system cleaner, has released version 6.0.4, addressing a critical flaw in its secure file wiping functionality on Windows. Previous versions of the software could fail to securely erase entire files, leaving fragments of sensitive data on disk due to the way Windows stores files in non-contiguous clusters. The update does not specify which prior versions were…

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security updates for September 2026, addressing a total of 973 vulnerabilities across its product line. Among these, 113 were classified as "critical." The company confirmed that two of these vulnerabilities have already been exploited in the wild.

Microsoft Plugs Nearly 1,000 Security Holes
Microsoft has released an unprecedented number of security updates, addressing 974 vulnerabilities across its Windows operating systems and other software. This marks the largest single patch batch in the company's history, significantly surpassing the previous record of 570 fixes issued in July. The total number of vulnerabilities patched by Microsoft in 2026 has now exceeded 2,600, more than…

Mathspace breach exposes data on over a million students and parents
Mathspace, an Australian educational technology company, has confirmed a data breach affecting over one million students, parents, and school staff in Australia and New Zealand. The company stated that an unpatched vulnerability in its self-hosted Metabase internal reporting system allowed unauthorized parties to gain administrator access and exfiltrate data.

ConnectWise warns of new ScreenConnect flaw without patch
ConnectWise has issued a warning regarding a newly identified vulnerability in its ScreenConnect remote access platform, affecting both cloud and on-premises deployments. The company has not yet assigned a CVE ID to this flaw but has provided temporary mitigation steps while it develops a permanent patch, expected later this week.

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
A new, unpatched zero-day vulnerability affecting Magento Open Source and Adobe Commerce is actively being exploited by attackers to compromise online stores. The flaw allows for the execution of arbitrary malicious code on a store's server without requiring prior authentication, according to an advisory published by Dutch e-commerce security company Sansec. Sansec, which identified the…

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
JetBrains has reported a security incident involving a breach of its internal Cadence environment, which attackers exploited to extract AWS credentials. The incident, which occurred last month, leveraged a recently disclosed critical vulnerability in TeamCity, JetBrains' continuous integration and continuous delivery (CI/CD) server. The company is advising all Cadence users to revoke and…

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has issued security updates addressing two vulnerabilities in VMware Workstation and Fusion, one of which is a critical flaw that could enable arbitrary code execution. The critical vulnerability, identified as CVE-2026-59346, carries a CVSS score of 9.3, indicating a high level of severity.

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A large-scale cybercrime operation has compromised over 5,400 small-business websites, predominantly built on WordPress and PrestaShop, to deliver malicious payloads stored on the BNB Smart Chain (BSC) Testnet. This technique, known as EtherHiding, leverages smart contracts to host the next-stage payload, providing a resilient infrastructure that is difficult for defenders to dismantle.

Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Broadcom has issued patches for two critical vulnerabilities in VMware Workstation and Fusion that could allow an attacker to escape a virtual machine and execute code on the host system. The company confirmed these issues in its VMSA-2026-0007 advisory, noting that no workarounds are available, and users should update to version 26H1u1 immediately.

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Google Chromium V8 vulnerability, identified as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) catalog. This type confusion flaw, affecting Chrome's JavaScript and WebAssembly engine, has a CVSS score of 8.8 and is actively being exploited in the wild.

HPE Patches Critical RCE Vulnerabilities in AOS-CX
Hewlett Packard Enterprise (HPE) has issued security updates to mitigate critical remote code execution (RCE) vulnerabilities identified in its ArubaOS-CX operating system. These vulnerabilities, which have been assigned the identifier CVE-2026-73749, pose a significant risk, as reflected by their CVSS score of 9.8.

Most of the bugs Claude Mythos found have never been checked by a human
Anthropic's Claude Mythos Preview, an AI model designed for vulnerability detection, identified over 23,000 potential security flaws across 281 open-source projects. However, only a small fraction of these candidates have undergone human review, with the vast majority remaining unchecked due to a reported shortage of personnel.

New infosec products of the week: September 4, 2026
Several cybersecurity vendors have announced new product releases and updates this week, focusing on areas such as AI-driven threat protection, enterprise security for personal AI agents, cyberstorage resilience, and automated black-box penetration testing.

Cisco searched for IOS XR bugs and found so many it rolled them into an update release
Cisco has issued a warning to customers regarding several critical vulnerabilities across its product lines, including three rated as critical. Two of these impact the Cisco IOS XR operating system, which powers the company's carrier-grade equipment, while the third affects certain Nexus 9000 Series Switches.

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models
Cloudflare has announced a new capability for its Managed Defense service, integrating OpenAI’s Daybreak models to enhance the discovery and remediation of vulnerabilities. This initiative aims to provide context-aware insights into security threats, moving beyond traditional signature-based detection to understand the broader implications of vulnerabilities within a system.

HPE patches critical ArubaOS-CX remote code execution flaw
Hewlett Packard Enterprise (HPE) has released patches for a critical remote code execution vulnerability, identified as CVE-2026-73749, affecting its ArubaOS-CX network operating system. This buffer overflow flaw allows unauthenticated attackers to achieve elevated privileges and execute code by sending specially crafted packets to a vulnerable daemon process.

Windows memory integrity switches on automatically for eligible devices in October 2026
Microsoft has announced that beginning in October 2026, Windows quality updates will automatically enable memory integrity protection on eligible devices. This change will also activate Virtualization-based Security (VBS) on machines where it is not already running, as VBS is a prerequisite for memory integrity.

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has reported the discovery of eight security vulnerabilities across seven distinct command-line AI coding agents. The core mechanism of these flaws involves a malicious Git configuration file within a repository, which can instruct the AI agent to execute an arbitrary command on the developer's machine. Four of these identified vulnerabilities remain unpatched at the time of…

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
A critical unauthenticated remote code execution (RCE) vulnerability chain has been addressed in GeoNetwork, an open-source geospatial metadata catalog. The flaw, which combines two distinct vulnerabilities, could allow attackers to execute arbitrary code on systems running GeoNetwork without requiring any prior authentication. This issue is particularly significant given GeoNetwork's role as…

Chrome and Firefox Updates Patch Dozens of Vulnerabilities
Recent updates for Google Chrome and Mozilla Firefox have addressed numerous security vulnerabilities, according to reports. The patches collectively resolve dozens of flaws, including critical issues such as use-after-free errors, sandbox escapes, and privilege escalation bugs, enhancing the overall security posture of both widely used web browsers.

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Threat actors are actively exploiting a recently disclosed critical security flaw in JFrog Artifactory, according to a report from watchTowr. The vulnerability, identified as CVE-2026-82329 with a CVSS score of 9.8, is an authentication bypass issue that could allow attackers to gain administrative access to Artifactory instances. This exploitation is occurring mere days after the public…

Hackers push malicious Virtualizor update in BGP hijacking attack
Softaculous, the developer of the Virtualizor VPS management software, has confirmed that a BGP hijacking attack allowed threat actors to deliver malicious updates to a limited number of Virtualizor installations. The incident occurred between August 28, 20:57 UTC, and August 30, 06:10 UTC, when attackers rerouted a block of Hetzner-hosted IP addresses associated with Softaculous's update…

The Collective Cyber Defense letter wrote your next vendor questionnaire
A recent report highlights a letter, signed by over 200 companies, that outlines key metrics for enhancing cyber defenses, particularly in the context of artificial intelligence. The letter, dated August 27, reportedly includes specific criteria that signatories are endorsing under their respective corporate logos. These criteria are presented as potential benchmarks for evaluating vendor…

Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes
CrowdSec has released version 1.8.0 of its open-source security engine, introducing new bot detection capabilities for its web application firewall (WAF) component and addressing two denial-of-service (DoS) vulnerabilities in its log acquisition datasources. The update, which became available on August 31, also includes improvements for Kubernetes integration and performance enhancements.

NIS2 compliance: Fixing IAM and access control before the 2026 audit
The NIS2 Directive is imposing new, legally binding cybersecurity obligations on organizations across the European Union, with member states now moving from transposition into enforcement. Compliance deadlines are approaching, with national implementation laws coming into force and mandatory self-registration periods closing. Non-compliance can lead to significant penalties, including fines up…

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
Cybersecurity researchers at Kaspersky have uncovered a new malware campaign utilizing a modified version of a legitimate Chinese desktop wallpaper application, QN Wallpaper, to deliver the ValleyRAT backdoor. The campaign, which has been detected over 100,000 times in 2026, leverages DLL sideloading to evade detection and establish persistent control over infected systems.

Chrome Web Store extensions caught stealing crypto, browser data
Multiple extensions for Google Chrome and Microsoft Edge have been identified as delivering a sophisticated malware framework designed to steal cryptocurrency, sensitive user data, and browser history. The operation, uncovered by application security company Socket, appears to have been active since early 2024.

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch
PaperCut, a widely used print management software, has confirmed active exploitation of a pre-authentication remote code execution vulnerability in its servers, with nearly half of tracked installations remaining unpatched. The flaw, which affects schools, hospitals, and offices globally, was confirmed by PaperCut on August 27, following observations of real-world attacks.

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited
Attackers are actively exploiting a previously patched vulnerability in Citrix NetScaler ADC and Gateway, identified as CVE-2026-8452. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed this exploitation by adding the flaw to its Known Exploited Vulnerabilities (KEV) catalog.

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Recent reports indicate the disclosure of five critical security flaws affecting various WordPress plugins and themes. These vulnerabilities, identified in products such as WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, collectively present risks ranging from authentication bypass to full site takeover and remote code execution (RCE). The findings highlight persistent security…

PaperCut releases second emergency patch for exploited flaws
PaperCut has issued a second emergency security update for its NG and MF print management software, addressing two actively exploited vulnerabilities after researchers identified multiple methods to bypass the initial fixes. The company had previously released an emergency patch for PaperCut NG/MF versions 25 and 26, warning of zero-day exploitation, but initially withheld technical details…

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Reports indicate that attackers are actively chaining two distinct security vulnerabilities in PaperCut NG and MF to achieve unauthenticated remote code execution on vulnerable systems. The vendor has released an emergency patch to address the newly exploited flaw, which includes additional hardening measures. This attack chain reportedly allows an unauthenticated attacker to gain remote…

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies apply patches for a critical vulnerability, CVE-2026-8452, affecting Citrix NetScaler appliances by Saturday, August 29. This directive, issued under Binding Operational Directive (BOD) 26-04, follows the addition of CVE-2026-8452 to CISA's Known Exploited Vulnerabilities (KEV) Catalog.

Ubiquiti patches three max severity security vulnerabilities
Ubiquiti has released security updates to address three critical vulnerabilities that could allow unauthenticated remote attackers to compromise affected devices. The patches were issued on August 26, 2026, for flaws impacting the UniFi Protect Application, UniFi Talk Application, and UniFi OS.

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter
A joint analysis by Tenable and SentinelOne reveals that edge infrastructure is a shared attack surface, with both state-sponsored actors and cybercriminals independently targeting the same vulnerabilities and vendors. This convergence challenges the perception that edge device exploitation is primarily a nation-state problem, demonstrating a broader threat landscape.

Chrome 152 Patches Over 300 Vulnerabilities
Google has released Chrome 152, an update that addresses over 300 vulnerabilities within the browser. The majority of these security flaws were identified internally by Google, leveraging artificial intelligence (AI) tools for discovery. However, the update also includes patches for high-value vulnerabilities that continue to be found by external security researchers.

Production data in testing is still common, and Tricentis’ CISO wants it gone
Tricentis, a software testing company, has confirmed that its security team identified and addressed a prompt injection vulnerability in an AI-powered capability during pre-release red-teaming. The flaw led to a one-week delay in the feature's deployment while backend fixes were implemented to prevent potential data exposure.

CISA Warns of Exploited Gitea Vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding an actively exploited remote code execution (RCE) vulnerability in Gitea, an open-source Git service. The flaw, identified as CVE-2026-60004, was addressed by Gitea developers in late July with the release of version 1.27.1. CISA's alert indicates that the vulnerability is currently being leveraged in…