12 Sep, 2026

Windows 11 cumulative updates KB5124008 & KB5122880 released

Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. Today’s updates areĀ mandatory as they contain theĀ September 2026Ā Patch TuesdayĀ security patches for 1,000 vulnerabilities discovered in previous months. You can install today’s update by going to Start > Settings > Windows Update and clicking on ‘Check for Updates.’ You can also manually download […]

7 mins read

Microsoft releases Windows 10 KB5122878 extended security update

Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month’s record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. If you are running Windows 10 Enterprise LTSC or are enrolled in the ESU program, you can install this update like normal by going into Settings, clicking on Windows Update, and manually […]

2 mins read

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Today is Microsoft’s September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. This Patch Tuesday addresses 105 “Critical” vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass. The approximate number of bugs in […]

4 mins read

ShinyHunters hackers claim breach of Florida “DAVID” DMV database

The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as “DAVID” and stole over 200,000 records about drivers in the state. As proof of the breach, the threat actor has released a screenshot of Jeffrey Epstein’s DMV record, including his address and registered vehicles. DAVID […]

4 mins read

OpenAI says ChatGPT outage causes image generation errors

OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. According to hundreds of user reports on the outage tracking platform DownDetector, ChatGPT hangs and freezes when users try to upload a file and displays errors on image generation prompts. This outage started more than an hour ago, when the company […]

1 min read

August updates trigger 0xc0000409 errors on Windows Server 2016

Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. On affected systems, users will see the CompatTelRunner.exe (Compatibility Appraiser Telemetry Runner) process crashing. Microsoft Compatibility Appraiser, which controls CompatTelRunner and is a Windows Compatibility Telemetry component, is a background system […]

2 mins read

SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability

SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library. Successful exploitation lets unprivileged threat actors run […]

2 mins read

OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the “Critical level” for cybersecurity capabilities. This is part of the company’s Preparedness Framework for cybersecurity and is evaluated when OpenAI releases more capable models. Under OpenAI’s own framework, a model reaches the Critical cybersecurity threshold if it can “identify […]

3 mins read

Adobe fixes critical Magento zero-day exploited to backdoor servers

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. E-commerce security company Sansec discovered that the flaw has beenĀ leveraged in attacksĀ since at least September 4 to plant a backdoor on vulnerable websites. The backdoor disguised its command-and-control (C2) host […]

2 mins read

Hackers build AI frameworks for widescale credential theft

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. Drawing on telemetry from Mandiant’s incident response engagements, threat actor tracking, and live platform defenses, the Google Threat Intelligence Group (GTIG) observed AI agents coordinating multiple attack tasks, troubleshooting failures, and adapting their actions with minimal […]

2 mins read