11 Sep, 2026

August updates trigger 0xc0000409 errors on Windows Server 2016

Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. On affected systems, users will see the CompatTelRunner.exe (Compatibility Appraiser Telemetry Runner) process crashing. Microsoft Compatibility Appraiser, which controls CompatTelRunner and is a Windows Compatibility Telemetry component, is a background system […]

2 mins read

SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability

SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library. Successful exploitation lets unprivileged threat actors run […]

2 mins read

OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the “Critical level” for cybersecurity capabilities. This is part of the company’s Preparedness Framework for cybersecurity and is evaluated when OpenAI releases more capable models. Under OpenAI’s own framework, a model reaches the Critical cybersecurity threshold if it can “identify […]

3 mins read

Adobe fixes critical Magento zero-day exploited to backdoor servers

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. E-commerce security company Sansec discovered that the flaw has been leveraged in attacks since at least September 4 to plant a backdoor on vulnerable websites. The backdoor disguised its command-and-control (C2) host […]

2 mins read

Hackers build AI frameworks for widescale credential theft

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. Drawing on telemetry from Mandiant’s incident response engagements, threat actor tracking, and live platform defenses, the Google Threat Intelligence Group (GTIG) observed AI agents coordinating multiple attack tasks, troubleshooting failures, and adapting their actions with minimal […]

2 mins read

Microsoft: Windows Server 2025 changes causing app crashes

Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. This known issue affects apps that use Address Windowing Extensions (AWE), a set of extensions that lets an application use more than 4GB of physical memory within a 32-bit virtual address space. “Applications running on […]

2 mins read

220 million traveler records exposed in Vietnam-linked APIS leak

An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it. Advance Passenger Information Systems are used worldwide to collect […]

4 mins read

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. The first exploitation incident was recorded on September 4 on a target running the latest security updates. E-commerce security company Sansec says that Adobe Enterprise Support confirmed earlier today that it was working […]

2 mins read

Mathspace discloses data breach affecting over 1 million people

Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in […]

3 mins read