Agregátor RSS

Microsoft’s Patch Tuesday updates: Keeping up with the latest fixes

Computerworld.com [Hacking News] - 14 Září, 2026 - 12:23

Long before Taco Tuesday became part of the pop-culture vernacular, Tuesdays were synonymous with security — and for anyone in the tech world, they still are.  Patch Tuesday, as you most likely know, refers to the day each month when Microsoft releases security updates and patches for its software products — everything from Windows to Office to SQL Server, developer tools to browsers.

The practice, which happens on the second Tuesday of the month, was initiated to streamline the patch distribution process and make it easier for users and IT system administrators to manage updates. Like tacos, Patch Tuesday is here to stay.

Patch Tuesday coverage has long been a staple of Computerworld’s commitment to provide critical information to the IT industry. That’s why we’ve gathered together this collection of recent patches, a rolling list we’ll keep updated each month.

In case you missed a recent Patch Tuesday announcement, here are the latest six months of updates.

September Patch Tuesday: 963 CVEs, 2 exploited flaws, 1 message

September’s Patch Tuesday is Microsoft’s biggest of 2026, with 963 CVEs, two exploited flaws and a clear message: prioritize Windows, Office and SQL Server.

Two vulnerabilities are already exploited: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Advanced Local Procedure Call. Nothing in this release was publicly disclosed ahead of the patch. Readiness recommends a Patch Now scheduling for Windows, Office, SQL Server and the developer tooling, and standard patch release for Exchange.

Get more info on the September 2026 Microsoft security updates.

August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw

Microsoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but not exploited.

This security-only release earns Patch Now for Windows, Office and Exchange; no SQL Server updates this month. Unfortunately, several critical issues affect server roles: Windows DNS Server carries a cluster of critical RCEs; Windows DHCP Server is the most-populated Microsoft product family at 14 entries. Testing should lead with printing and fonts and the Remote Desktop client, then a WinSock smoke test given the exploited afd.sys flaw.

Get more info on the August 2026 Microsoft security updates.

July’s Patch Tuesday sees an end-of-support collision amidst a massive, record-setting patch wave

Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in Active Directory Federation Services (CVE-2026-56155), and an elevation of privilege in SharePoint Server (CVE-2026-56164). A third, a BitLocker security feature bypass (CVE-2026-50661) is publicly disclosed but not yet exploited.

The July 2026 Patch Tuesday earns Patch Now recommendations for Windows, Office, Exchange, and SQL Server. SharePoint has two critical RCEs on top of its exploited zero-day, and Exchange Server returns with a critical on-premises spoofing flaw. Adding to our (dear) administrator’s efforts, SharePoint Server 2016/2019 and SQL Server 2016 all reach end of support today.

More info is available here on Microsoft Security updates for July 2026.

For June, Patch Tuesday means an IT scramble

Microsoft this month released 206 updates affecting Windows, Office, Exchange Server, and its developer tools — including three Windows vulnerabilities already publicly disclosed. That trio includes an elevation of privilege in the Collaborative Translation Framework (CVE-2026-45586), a denial of service in HTTP.sys (CVE-2026-49160), and a BitLocker security feature bypass (CVE-2026-50507). At the moment, none appear to be under active exploitation, but all three are rated “Exploitation More Likely.” 

Even without an exploited zero-day, the June 2026 Patch Tuesday release requires Patch Now recommendations for Windows, Office, and Exchange. The latter is back in the patch picture with a consolidated security update that Microsoft recommends installing “as soon as possible.”

More info is available here on Microsoft Security updates for June 2026.

For May, Patch Tuesday means 139 updates — but no zero-days

Microsoft this month released 139 updates affecting Windows, Office, .NET, and SQL Server (though there were no updates for Microsoft Exchange Server). Despite the absence of zero-days, the May Patch Tuesday update still requires Patch Now recommendations for Windows and Office. 

The combination of three unauthenticated network RCEs (Netlogon, DNS Client, and SSO Plugin for Jira and Confluence), four Word Preview Pane RCEs, the large TCP/IP vulnerability cluster, and the carry-over BitLocker recovery condition (still active on Windows 10 and Windows Server) warrants an accelerated deployment release schedule. 

More info is available here on Microsoft Security updates for May 2026.

Microsoft’s Patch Tuesday release for April is a whopper

Windows admins are going to be busy this month, dealing with the largest Patch Tuesday cycle in memory. The April release involves 165 updates and roughly 340 unique CVEs from Microsoft — including two zero-days, one of which is already being actively exploited in the wild. 

The Readiness team recommends “Patch Now” schedules for nearly every major product family: Windows, Office (with a zero-day), Microsoft Edge (Chromium), SQL Server, and Microsoft Developer Tools (.NET). April also brings Phase 2 of Microsoft’s Kerberos RC4 hardening with full enforcement set for July. There is a lot to cover, so here’s a useful infographic mapping the deployment risk for each platform.

More info is available here on Microsoft Security updates for April 2026.

Kategorie: Hacking & Security

Linux nativně na ESP32-S3 – bez emulace a rovnou s 9,7″ e-paperem

AbcLinuxu [zprávičky] - 14 Září, 2026 - 12:05
Linux může běžet nativně na ESP32-S3 – bez emulace a rovnou s 9,7″ e-paperem.
Kategorie: GNU/Linux & BSD

Microsoft: September updates cause RDS failures on Windows Server

Bleeping Computer - 14 Září, 2026 - 11:50
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. [...]
Kategorie: Hacking & Security

UK.gov begins killing off passwords for 23 million users

The Register - Anti-Virus - 14 Září, 2026 - 11:16
The UK government is giving more than 23 million people the chance to ditch passwords for passkeys – and could save itself a tidy sum on authentication texts in the process. Passkeys are being rolled out more widely across GOV.UK One Login following a trial involving more than 300,000 users, allowing people to sign in using a fingerprint, Face ID, or device PIN instead of entering a password and waiting for a two-factor authentication (2FA) code. The government says nearly one in ten daily One Login sign-ins are already being made using passkeys, which it claims are up to eight times faster than logging in with a username, password and 2FA code. There is also a less glamorous incentive for Whitehall: text messages cost money. The switch is already saving taxpayers nearly £600 a day in SMS costs, according to the government. Passkeys are designed to resist phishing. Rather than relying on a password that can be stolen, reused, or handed over to a convincing fake login page, a passkey uses cryptographic credentials tied to the website or app for which it was created. The biometric data or PIN used to unlock it remains on the user's device and isn't seen or stored by GOV.UK One Login. "Cyber criminals often look for the easiest route to access important accounts, which means login details remain a common target," said Jonathon Ellison, director for national resilience at the UK's National Cyber Security Centre (NCSC). "But passkeys offer a highly phishing-resistant alternative to passwords, frustrating attackers and saving the public time." The NCSC is encouraging users to switch, although passwords aren't disappearing just yet. Passkeys remain optional, and anyone who would rather continue signing in the old-fashioned way can do so. GOV.UK One Login is intended to provide a single account for accessing government services rather than requiring users to navigate a collection of separate sign-in systems. It is already used for services including checking State Pension details, managing tax services, and accessing childcare support. Digital Government Minister Stephanie Peacock said the rollout was intended to make government services both easier to access and harder for fraudsters to exploit. "Nobody enjoys hunting for a forgotten password or waiting for a text message code just to check their tax return or renew a document," she said. Whether Britain's 23 million One Login users share Whitehall's enthusiasm for replacing passwords is unclear. But with passkeys already accounting for almost 10 percent of daily logins – and every authentication text adding to the government's phone bill – there are at least a couple of reasons to keep nudging them in that direction. ®
Kategorie: Viry a Červi

Samsung si rýpl do Applu jako nikdy předtím. Hvězdou reklamy na Galaxy Z Fold8 je Tim Cook

Živě.cz - 14 Září, 2026 - 11:15
Samsung odpovídá na iPhone Duo vlastní marketingovou kampaní • Pozval si do ní Tima Cooka z Nového Zélandu • Používá stejné fráze i podobné oblečení jako Tim Cook z Applu
Kategorie: IT News

Revolut discloses data breach exposing financial info, passports

Bleeping Computer - 14 Září, 2026 - 10:48
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]
Kategorie: Hacking & Security

LibreOffice 26.8 vylepšuje sazbu textu a rychleji načítá velké dokumenty

Živě.cz - 14 Září, 2026 - 10:45
LibreOffice 26.8 nativně podporuje OpenType Font Variations. • Writer rychleji otevírá velké dokumenty s obrázky. • Nástroje jsou barevně odlišené s některými typy uživatelského prostředí.
Kategorie: IT News

Microsoft: September updates break audio on some Windows PCs

Bleeping Computer - 14 Září, 2026 - 10:08
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. [...]
Kategorie: Hacking & Security

S čínskými HBM to nepůjde rychle, brzdou je výtěžnost

CD-R server - 14 Září, 2026 - 10:00
Poslední dobou to vypadá, že na co CXMT sáhne, to se jí podaří. Zdá se však, že to má jednu výjimku. S HBM to nejde až tak hladce, jak se mohlo podle počátečních informací zdát…
Kategorie: IT News

Nejlevnější OLED TV už stojí méně než 16 tisíc. LG se hodí na filmy i hry a lze ji využít také jako PC monitor

Živě.cz - 14 Září, 2026 - 09:45
Televizor LG OLED42C57 zlevnil na historicky nejnižších 15 743 Kč. • Nabízí skvělý obraz, čtyři HDMI 2.1 a frekvenci až 144 Hz. • Vzhledem k úhlopříčce poslouží i jako velký počítačový monitor.
Kategorie: IT News

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

The Hacker News - 14 Září, 2026 - 09:24
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store - Chrome - Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Porovnali jsme iPhone Duo, Galaxy Z Fold8 a Xiaomi 18 Fold. Která skládačka je nejlepší?

Živě.cz - 14 Září, 2026 - 09:15
Samsung, Apple a Xiaomi se sešli u jednoho stolu • Všichni giganti nabízejí vzájemně si konkurující skládací knížky • Každá je zaměřená na trochu jinou cílovou skupinu
Kategorie: IT News

CISA: Hackers now exploit max severity GitLab flaw in attacks

Bleeping Computer - 14 Září, 2026 - 09:06
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. [...]
Kategorie: Hacking & Security

Postřehy z bezpečnosti: pomozte likvidovat phishing

ROOT.cz - 14 Září, 2026 - 08:00
Strážci internetu, lákavý early access u škodlivých aplikací, phishing, který vidíte jedině vy, tučný balík falešných e-shopů, insecure secure boot, ruské útoky na Signál a řada dalších postřehů.
Kategorie: GNU/Linux & BSD

Íránci zajali americkou ponorku. Naštěstí byla jen bezpilotní a prý už nějaký čas mimo provoz

Živě.cz - 14 Září, 2026 - 07:45
Íránské Islámské revoluční gardy zkraje září oznámily, že poblíž ústí Hormuzského průlivu „zajaly“ americkou bezpilotní ponorku Dive-LD od Andurilu. V reakci na to Americké velitelství CENTCOM uvedlo, že se dotyčný podvodní dron porouchal během průzkumné mise a zůstal více než 24 hodin nefunkční. ...
Kategorie: IT News

Intel: Vyrobili jsme milion waferů s High-NA EUV. TSMC: Do roku 2030 nemá smysl

CD-R server - 14 Září, 2026 - 07:40
Zatímco Intel se chlubí léty práce na nasazení technologie High-NA EUV a vyrobení miliontého waferu s jejím využitím, TSMC nic nemění na svém názoru, že praktický přínos bude ještě dlouho mizivý…
Kategorie: IT News

Homebrew 7.0.0

AbcLinuxu [zprávičky] - 14 Září, 2026 - 00:16
Homebrew (Wikipedie), správce balíčků pro macOS a od verze 2.0.0 také pro Linux, byl vydán ve verzi 7.0.0. Pro sandboxing se na Linuxu nově používá Landlock místo Bubblewrap. Na stránce Homebrew Formulae lze procházet seznamem balíčků. K dispozici jsou také různé statistiky.
Kategorie: GNU/Linux & BSD

Nic neuděláte špatně a stejně přijdete o peníze aneb Jak útočníci vykradli peněženky, které měly být nedobytné

Lupa.cz - články - 14 Září, 2026 - 00:00
Nástrahy kryptosvěta spočívají i v tom, že ačkoli se chováte vzorově a děláte vše, jak máte, cizí chybou můžete přijít o úspory. A kromě žaloby s tím neuděláte nic.
Kategorie: IT News

FreeBSD pracuje na novém správci služeb, pracovní stanice Thelio Mira AI

ROOT.cz - 14 Září, 2026 - 00:00
Baptiste Daroussin pracuje na správci služeb pro FreeBSD s názvem rcd. KaOS Linux 2026.09 je nově k dispozici a přináší několik významných aktualizací. System76 představilo novou linuxovou pracovní stanici Thelio Mira AI.
Kategorie: GNU/Linux & BSD
Syndikovat obsah