CVE-2026-71337 Windows Storage Management Provider Elevation of Privilege Vulnerability
Updated an acknowledgement. This is an informational change only.
Coverage tagged "Windows".
Updated an acknowledgement. This is an informational change only.
Updated an acknowledgement. This is an informational change only.
Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline SOCRadar Threat Research Unit (STRU) has uncovered an end-to-end cybercrime operation dubbed Operation Master, in…
Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key.
Over the last few days, Google issued several different Chrome updates. On September 22, Google released a Stable Channel Update for Desktop. This is the most important one for desktop users.
Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates.
Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware, dubbed CLOSEDQUORUM, that holds a vote…
Posted by Nathan Herz on Sep 23 Hello Kubernetes Community, An NTLM coercion vulnerability exists on Windows nodes when the subPath supplied in a pod's volumeMounts is set to a symbolic link that…
The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into…
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
The Stable channel has been updated to 155.0.8059.12/.13 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in…
Serial number: AV26-955 Date: September 23, 2026 As of September 22, 2026, Google published a security advisory to address vulnerabilities in the following product: Stable Channel Chrome for Desktop…
The Beta channel has been updated to 155.0.8059.12 for Windows, Mac and Linux. A partial list of changes is available in the Git log. Interested in switching release channels?
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal…
Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed…
A fake Claude Max giveaway uses a spoofed Google sign-in window to steal users’ login credentials, Malwarebytes researchers have found. “Browser-in-the-browser” is not a new technique. Researchers…
Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems.
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on…
Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a…