Advisories, vulnerabilities and threat intelligence for third-party risk management.
Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. [...]
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81984.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81977.
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]
Roughly 261 Employees Face Cuts as Vendor Redirects Spending Toward Growth Zscaler will cut 3% of its global workforce and redirect spending to specialized sales, channel and enterprise teams as it seeks more new customers and positions its go-to-market strategy around rising AI, data security and cloud demand.
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA LocalDiscoveryServer (LDS) Execution with Unnecessary Privileges Background Critical Infrastructure Sectors: Chemical, Energy, Food and Agriculture, Water and Wastewater, Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-77477 An attacker can intercept a high-privilege console window launched during installation of the LDS. The attacker must be able to launch an installer with elevated privileges and have access to the keyboard and display while the installation is taking place. View CVE Details Affected Products OPCFoundation OPC UA LocalDiscoveryServer (LDS) Vendor: OPCFoundation Product Version: OPCFoundation UA-LDS-Installers: <1.04.420 Product Status: known_affected Remediations Mitigation OPCFoundation recommends users update to OPC UA LDS Installers 1.04.420 or later. Mitigation For more information about this vulnerability and its mitigation, see the OPCFo...
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. [...]
Google introduced a batch of network security changes coming in Android 17, aimed at making it harder for network operators, snoops, and scammers to track what you do on your phone. “When you visit a website or use an app, even if the connection is encrypted by HTTPS, the domain names of the sites you visit are still visible to network operators and eavesdroppers. This unencrypted data can be used to build user profiles or, … More → The post Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping appeared first on Help Net Security .
Ring’s new TAKE encryption limits video-key retention while keeping cloud AI features, Ring Verify, and optional end-to-end encryption in play. The post Ring’s New TAKE Encryption Deletes Video Keys Without Giving Up AI Features appeared first on TechRepublic .
The offer is open to subscribers on any tier, but it is location-based.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-13129.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 4.0. The following CVEs are assigned: CVE-2026-19504.
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]
ICE warned employees against using Meta smart glasses on duty as DHS seeks $7.5 million to develop biometric-enabled prototypes for field agents. The post ICE Warns Employees Against Meta Smart Glasses appeared first on TechRepublic .
If you're not happy with the algorithm on your Discover page, you can now tell Google what you want in your own words.
Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]
WhatsApp is testing an on-device Scam Alert feature that flags suspicious messages while keeping analysis local and preserving end-to-end encryption. The post WhatsApp Begins Limited Test of AI Scam Alerts for Unknown Senders appeared first on TechRepublic .
View CSAF Summary A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Desigo DXR and PXC Controllers are affected: Desigo DXR2 vers:intdot/<01.21.233.16-7862 (CVE-2026-59693) Desigo PXC3 vers:intdot/<01.21.233.16-7862 (CVE-2026-59693) Desigo PXC4 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693) Desigo PXC5.E003 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693) Desigo PXC5.E24 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693) Desigo PXC7 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693) CVSS Vendor Equipment Vulnerabilities v3 4.3 Siemens Siemens Desigo DXR and PXC Controllers Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Healthcare and Public Health, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-59693 The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed...
The process of sending someone a file or sharing your information on Android just got a lot simpler.
Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification provides an additional, streamlined way to confirm that there’s no unexpected party between you and the other ‘end’ of an end-to-end encrypted session,” Signal engineer Katherine Yen wrote in a blog post. “It works through a system of verifications performed by … More → The post Signal’s new security feature checks if your encrypted chats were tampered with appeared first on Help Net Security .
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened. The following versions of Medixant RadiAnt DICOM are affected: RadiAnt DICOM <=2025.2 CVSS Vendor Equipment Vulnerabilities v3 4.3 Medixant Medixant RadiAnt DICOM Out-of-bounds Write Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Poland Vulnerabilities Expand All + CVE-2026-17264 Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code. View CVE Details Affected Products Medixant RadiAnt DICOM Vendor: Medixant Product Version: Medixant RadiAnt DICOM: <=2025.2 Product Status: known_affected Remediations Mitigation Users should update to version 2026.1. It is also recommended to open DICOM files only from trusted and reliable sources. Additionally, the application is compiled with exploit mitigation mechanisms enabled, including Control Flow Guard (CFG), Data Execution Prevention (DEP), and Address Space Layout Randomization (ASLR), which significantly reduces the practical exploitability of the issue. https://www.radiantviewer.com/files/RadiAnt-2026...
I create Windows 11 system restore points before most major changes - and you should, too. Here's why.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Simbian has released its autonomous AI Threat Hunt Agent, that investigates potential threats and identifies malicious activity across enterprise environments. The Threat Hunt Agent represents the third pillar of Simbian’s AI-driven security suite. These three Agents eliminate blind spots across the entire threat timeline: The Present: The AI SOC Agent analyzes real-time alerts and neutralizes active threats as they happen. The Future: The AI Pentest Agent probes environments from an attacker’s perspective to uncover vulnerabilities … More → The post Simbian adds AI threat hunting agent to expand autonomous SecOps platform appeared first on Help Net Security .
What you'll get back depends on how much you spent - but don't expect much.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497) CVSS Vendor Equipment Vulnerabilities v3 2.4 Johnson Controls Inc. Johnson Controls OpenBlue Employee Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-21662 The application does not adequately restrict the types of files that can be uploaded, allowing an attacker to submit files with dangerous content types. Uploaded files may be stored in predictable locations and could be leveraged for further exploitation against the application or its users. View CVE Details Affected Products Johnson Controls OpenBlue Employee Vendor: Johnson Controls Inc. Product Version: Johnson Control...
Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. [...]
This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-18283.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-13053.
Google added selfie video recovery for eligible accounts, using encrypted videos and liveness checks to help users regain access when locked out. The post Google Adds Selfie Video Sign-In to Help Users Recover Locked Accounts appeared first on TechRepublic .
View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected: XAAP Android <1.53 CVSS Vendor Equipment Vulnerabilities v3 3.3 Johnson Controls Johnson Controls XAAP Android Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-34490 A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. An attacker with physical access to the device and one able to compromise the device through a separate, unrelated flaw, could potentially read this data in plaintext. Exploitation does not require network access and is limited to the local device environment. View CVE Details Affected Products Johnson Controls XAAP Android Vendor: Johnson Controls Product Version: Johnson Controls XAAP Android: <1.53 Product Status: known_affected Remediations Vendor fix Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability. Mitigation Johnson Controls recommends users restrict ...
An amended Google One storage utilization policy is rolling out now to include your Android device settings in backups, but there's no need to panic. Here are your options.
1Password's new Claude integration lets AI agents sign in to websites without exposing passwords, adding user approval and credential protection. The post 1Password Lets Claude Sign In Without Revealing Passwords appeared first on TechRepublic .
If you skipped Google's phone insurance at checkout, you can now add it again. But should you?
This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13306.
YouTube works well with default settings, but I tighten some privacy controls and enable a few features to make it even better.
Microsoft is now testing a cleaner and faster version of Windows Search that should prioritize relevant results over ads and promotional content. [...]
OpenAI is temporarily relaxing GPT-5.6 Sol usage after demand for the company's most powerful model surged over the past 48 hours. [...]
Anthropic has just extended access to Claude Fable 5 for paid subscribers until July 19, giving you another week to keep using the most powerful model. [...]
Red Hat's new Long-Life Add-On extends support on a specific release for as long as you're willing to pay for it.
DuckDuckGo’s web browser, often referred to as the DuckDuckGo Privacy Browser, can now block video ads, including in-video ads on YouTube. The post DuckDuckGo Now Blocks Most Video Ads on Windows, Mac, iPhone appeared first on TechRepublic .
Microsoft has announced plans to disable Outlook Web Access (OWA) Light, the lightweight version of the Outlook Web App email client, in a future Exchange Server update. [...]
Frontier AI Developer Says Enterprise Customers Could Mistake the Two Brands Anthropic alleges Abnormal's 2025 rebrand unlawfully mirrors its visual identity as both companies increasingly compete for enterprise AI security customers, while Abnormal denies any likelihood of customer confusion and says its branding predates Anthropic's claims.
DNSFilter has launched an Original Equipment Manufacturing (OEM) program that lets external ISPs, cybersecurity firms, device makers, and other consumer app developers to embed their DNS threat protection, domain analysis, and privacy solutions into their own platforms and solutions. Partners can choose between two product paths: DNSFilter Protective DNS, for DNS-layer filtering and threat blocking, and/or DNSFilter Guardian Firewall and VPN services, for full-device traffic encryption and privacy or bundle both. The program offers partners … More → The post DNSFilter makes its DNS threat protection available to OEM partners appeared first on Help Net Security .
DuckDuckGo announced that its browser can now block most video ads on YouTube, including those shown before the video starts playing and during playback. [...]
Owners of the Flipper Zero, the pocket-sized wireless testing tool, spent recent weeks worried that its official firmware had gone quiet. Pavel Zhovner, CEO of Flipper Devices, moved to settle that concern with word that the company has set aside staff to keep the firmware maintained and to support outside contributions. The work will run under a fresh set of rules covering feature requests, code submissions, and testing. How the quiet period began The firmware … More → The post Flipper Zero firmware development gets a fresh set of community rules appeared first on Help Net Security .
Learn how AI startups use global hiring, EOR partners, and remote systems to access talent, stay compliant, and extend runway efficiently for sustainable growth.