Security news

Latest security news

Mon, 14 Sept 2026

  1. Why Patch Automation Needs Brakes, Not Just an Accelerator

    Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control.

    BleepingComputer
  2. AI Changed the Exposure Problem. Validation Needs to Change With It.

    There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49% more than in the

    The Hacker News
  3. Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

    The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.

    SecurityWeekWindows
  4. CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

    Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API with a CVSSv3.1 score of 10.0 . According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions. On September 11, 2026, CVE-2026-85706 was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. CISA set a remediation due date of September 14, 2026, for affected Federal Civilian Executive Branch agencies and marked the vulnerability as subject to forensic triage requirements under Binding Operational Directive 26-04. Organizations running affected self-managed GitLab instances should remediate CVE-2026-85706 on an emergency basis, outside of normal patch cycles. Mitigation guidance A vendor-supplied update is available to remediate CVE-2026-85706. Organizations running affected self-mana

    CriticalUsed in attacksRapid7 BlogGitLab
  5. Hackers Exploit Maximum Severity Flaw in GitLab

    CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0

    Infosecurity MagazineGitLab
  6. Microsoft: September updates cause RDS failures on Windows Server

    Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems.

    BleepingComputerMicrosoft, Windows
  7. Microsoft: September updates break audio on some Windows PCs

    Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates.

    BleepingComputerMicrosoft, Windows
  8. CISA: Hackers now exploit max severity GitLab flaw in attacks

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks.

    BleepingComputerGitLab

Sun, 13 Sept 2026

  1. Hackers exploit Tencent app flaw to deploy GrayRabbit malware

    Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.

    BleepingComputerWindows

About this news

1,259
Stories
33
Added in the last 24 hours
17
Critical in the last 7 days
4
Reported by several outlets