22 Sep, 2026

Microsoft: Windows Server 2025 changes causing app crashes

Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. This known issue affects apps that use Address Windowing Extensions (AWE), a set of extensions that lets an application use more than 4GB of physical memory within a 32-bit virtual address space. “Applications running on […]

2 mins read

220 million traveler records exposed in Vietnam-linked APIS leak

An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it. Advance Passenger Information Systems are used worldwide to collect […]

4 mins read

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. The first exploitation incident was recorded on September 4 on a target running the latest security updates. E-commerce security company Sansec says that Adobe Enterprise Support confirmed earlier today that it was working […]

2 mins read

Mathspace discloses data breach affecting over 1 million people

Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in […]

3 mins read

Trezor data breach impact now reaches 81,000 customers

Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. In total, the breach has affected 81,000 customers after Trezor initially disclosed on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone […]

2 mins read

ChatGPT can now connect to your personal apps to mimic writing style

OpenAI appears to be testing a new “Writing Style” feature for ChatGPT that can learn how you write by looking at examples from your connected apps. The feature is currently available to a small group of users, and an onboarding screen says, “ChatGPT will write in your voice by referencing examples from your connected apps.” […]

1 min read

Hackers exploit new MikroTik RouterOS flaws to hijack routers

Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. One of the security issues, tracked as CVE-2026-67276, is an SSH authentication bypass flaw in MikroTik RouterOS caused by incomplete validation of RSA public keys. An attacker who knows a […]

3 mins read

ConnectWise warns of new ScreenConnect flaw without patch

ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. ScreenConnect is an on-premises or cloud-hosted remote access platform typically used by managed service providers (MSPs), IT departments, and support teams for troubleshooting, patching, and system maintenance. The security flaw affects both cloud and […]

2 mins read

N-able patches max severity N-central flaw amid ongoing attacks

N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. IT departments and managed service providers (MSPs) use the N-central platform to monitor, manage, and maintain client networks and devices from a centralized web-based console. Tracked as CVE-2026-86218, this RCE vulnerability allows threat […]

2 mins read