Goto

Collaborating Authors

 vulnerability


That April Windows update you skipped? Hackers are exploiting it now

PCWorld

PCWorld reports that CISA has flagged four actively exploited security vulnerabilities affecting Windows, VMware vCenter, Microsoft SharePoint, and Apple macOS systems. Critical flaws carry severity scores as high as 9.8 out of 10, with attackers using them to deploy ransomware, install Monero mining malware, and bypass authentication entirely. Users and administrators are urged to apply available patches immediately, including recent Windows, SharePoint, VMware, and macOS updates, to avoid becoming targets. The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about four security vulnerabilities that are being exploited by attackers in the wild. CISA has added the vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV) . Microsoft Windows and SharePoint, VMware vCenter, and Apple macOS are affected. Inclusion in the KEV catalog sends an important signal: CISA doesn't simply list every known vulnerability out there, but only those for which there is concrete evidence of active exploitation by attackers. The agency points out that such vulnerabilities are among the most commonly used attack vectors and pose a significant risk.


Firefox 154 fixes 58 security bugs, adds Nvidia GeForce Now streaming

PCWorld

The latest Firefox update patches nearly 60 security vulnerabilities and adds faster video skipping, new app icons, and Nvidia game streaming support. The newest major release of Firefox 154 for Windows, macOS, Linux, and Android brings a number of usability improvements, such as game streaming with Nvidia GeForce Now, faster video skipping, and new optional app icons, as well as nearly 60 security vulnerabilities fixed. Updates are also available for the ESR versions. The next major version of Firefox 155 is scheduled for September 1st. With it, Mozilla is switching--like Google Chrome and Microsoft Edge--to a fortnightly release cycle for its major versions.


Apple's iOS 26.6.1 patches 29 security flaws - here's why you'll want to install it

ZDNet

I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen Apple's iOS 26.6.1 patches 29 security flaws - here's why you'll want to install it Along with MacOS and iPadOS, the latest update to iOS fixes a host of security bugs that could otherwise leave your device vulnerable to compromise or crashes. Among the bugs are ones that could trigger compromises or crashes. No flaw has been exploited in the wild yet, but you should still update. Though iOS 27 is expected to launch next month, Apple continues to update iOS 26 to address the latest security bugs. On Monday, the company released iOS 26.6.1 (as well as iPadOS 26.6.1 and MacOS 26.6.2) with fixes for 29 vulnerabilities.


Update your Mac: Screen Share vulnerability gives attackers full control of your computer

Mashable

Look Up Mashable's Best: E-readers, robovacs, laptops, earbuds, smart home and more Say More Safety Net Creator Hub Versus Gift Ideas For Everyone On Your List Mashable Selects Switch Off Trending Now In My Bag VidCon with Mashable All Series Apple's latest macOS update consists of a single patch to deal with a critical exploit. Apple has released a critical security update for macOS that patches a Screen Share-related vulnerability. Mac users, if you haven't updated your MacBook or desktop Mac computer in the last week or so, install that latest update now. The most recent Mac update from Apple includes a patch for a major vulnerability that could allow an attacker to take over a targeted Mac. The exploit involves an authentication bug in Mac's Screen Share functionality, Ars Technica reported .


Mark Zuckerberg's AI Manifesto Is 6,500-Words--and Barely Says Anything

WIRED

AI is shifting the culture, from tech CEO manifestos to 1 am job interviews. Today on Brian Barrett, Zoë Schiffer, and Leah Feiger break down Meta CEO Mark Zuckerberg's 6,500-word AI manifesto and why it ultimately rings hollow. Plus, why are job seekers scheduling bot-run interviews at 1 am? WIRED's Andy Greenberg also joins to unpack the best findings from Black Hat and Defcon, from a hacked kids' smartwatch to a coin-sized device that can hijack a Boeing 737. McDonald's Built a 515-Page Dossier on Me. It Says I'll Never Stop Eating There Write to us at [email protected] . You can always listen to this week's podcast through the audio player on this page, but if you want to subscribe for free to get every episode, here's how: If you're on an iPhone or iPad, open the app called Podcasts, or just tap this link . I thought it was fun. The dialogue was kind of whatever, beautiful shots of the Sicilian ocean. And I went with my husband who loves to remind me that he studied Latin and Greek in high school, and he actually liked it too. I think everyone who is complaining about it needs to stop.


Microsoft's August update fixes a Windows flaw that's already being attacked

PCWorld

PCWorld reports that Microsoft's August update patches a significant number of security vulnerabilities, including one Windows Winsock flaw already being actively exploited by attackers in the wild. The update covers critical risks across Windows, Office, Exchange Server, and cloud services, with some flaws allowing remote code execution or full account takeover without user interaction. Users are strongly advised to install these updates immediately to protect their systems from potential exploitation. As part of August's Patch Tuesday, Microsoft released security updates that address 398 new vulnerabilities. Alongside Windows and Office, other products and services are also affected: Teams, Exchange Server, Hyper-V, Windows Defender, Visual Studio, and Microsoft's cloud services. Microsoft classifies 42 of the vulnerabilities as critical. Among the remainder, all but one are classified as high risk. One Windows flaw is already being exploited in the wild, while two vulnerabilities were already publicly known beforehand. The next scheduled Patch Tuesday will be on September 8th, 2026.


Microsoft fixes 421 bugs and a Windows zero-day in August Patch Tuesday - update ASAP

ZDNet

I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen The exploited zero-day flaw could allow an attacker to gain system privileges on a Windows PC. One vulnerability has already been exploited in the wild. Microsoft continues its onslaught against security vulnerabilities, fixing a whopping 421 bugs in August's Patch Tuesday update. But looking beyond the sheer number, Windows users should install this month's update, as it patches a zero-day flaw that's already been exploited by attackers. Aimed at Windows 11 25H2/24H2, Windows 11 23H2, and Windows 10, the 421 vulnerabilities encompass a range of Microsoft products, including Office, Exchange, Azure, and SharePoint.


A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

WIRED

Researchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants' device. As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets' devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim. Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports--Windows, macOS, Linux, iOS, and Android.


OpenAI gives Daybreak partners access to a more powerful cybersecurity model

Engadget

OpenAI is giving some members of its Daybreak cybersecurity program access to a new model that's less likely to refuse higher-risk tasks. The company is also expanding access to Daybreak to more partners, including Accenture, IBM, CrowdStrike, Cisco, Sophos and Cloudflare. OpenAI says the companies will use the cyber models available through Daybreak to protect their customers. Under the expanded program, Daybreak is available to partners in two tiers. Daybreak Blue gives them access to frontier general-purpose models, including GPT‑5.6 Sol, OpenAI's most advanced one yet.


An OpenClaw agent reportedly hacked a gym's booking system and kicked someone off a waiting list

Engadget

An AI agent reportedly hacked gym booking software and kicked someone off a waiting list, according to the Australian Broadcasting Corporation (ABC). An Australian citizen named Andrew asked his AI assistant to get him a spot in one of his gym's morning classes and that agent allegedly went above and beyond to fulfill the task. Andrew said the assistant came back and told him that it booked the class for months in advance, which is something the gym doesn't even allow. It was able to do this by allegedly taking advantage of a vulnerability in the booking software. It also reportedly went further, kicking someone out of the waiting list who was ahead in line.