Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

PaperCut's August patch failures show zero-day response now measured in hours

PaperCut disclosed active exploitation of PaperCut NG/MF servers on August 27 with no CVE, no available exploit sample, and no patch. An emergency fix issued the next day was bypassed within hours, and a third patch only arrived on September 1, leaving customers exposed for roughly six days while attackers were already using the flaw in live attacks. A security researcher uses the episode to argue that the industry's old assumptions about response timelines no longer hold.

Microsoft rushes out-of-band fix for bugs in record September Windows patch

Microsoft has released an emergency out-of-band update to correct problems introduced by its September Patch Tuesday release, which fixed nearly 1,000 vulnerabilities but broke folder sharing on Hyper-V Linux virtual machines, disrupted Remote Desktop Services sessions, and caused issues with some USB audio devices. The new fix covers Windows 11 versions 26H1, 25H2, and 24H2, along with Windows Server 2025, 2022, and 2012 R2, plus LTSC editions of Windows 10.

Cisco patches actively exploited zero-day in Secure Email Gateway software

Cisco released fixes for CVE-2026-76461, a critical flaw in AsyncOS Software for Secure Email Gateway that lets unauthenticated attackers run root-level commands by sending crafted emails with malicious SQL statements. The company confirmed it detected active exploitation of the bug in September 2026 and issued indicators of compromise for defenders to check mail logs and network traffic. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 17 to patch.

Microsoft's September Windows updates break Remote Desktop, USB audio, and Excel paste

Microsoft has acknowledged that its September security patches are causing Remote Desktop Services to fail across several Windows versions, silencing certain USB Audio Class 1.0 devices, and disrupting the paste function in Excel. Affected users report frozen management tools, unresponsive Windows Update pages, and audio glitches that can sometimes be worked around by switching to two-channel sound.

Android phones hide a separate 'System services' update menu beyond OS patches

Beyond the usual OS and security update settings, Android devices include a distinct, less visible menu for updating individual system services like Google Play services. Depending on the manufacturer, these services may need to be updated separately from the main software update screen, and how they appear can vary between brands such as Google Pixel and others.

Action1 CTO warns fast patch automation can spread failures as quickly as fixes

Gene Moody, Field CTO at Action1, argues that IT teams face an unsustainable mismatch between the growing volume of software patches and the shrinking time available to test them, forcing many organizations to skip review steps and push updates straight to production. He warns that simply automating patch deployment to go faster does not solve the underlying problem, since automation can propagate a bad update across thousands of endpoints just as quickly as a good one.

Microsoft confirms September patches break Remote Desktop Services on Windows Server

Microsoft has verified that its September 2026 security updates are causing Remote Desktop Services failures across Windows Server 2012 and later, plus Windows 10 and 11. Affected systems show RDP connections dropping after a few minutes, sign-in errors, servers stuck loading the Remote Desktop Configuration screen, and related tools like MMC and File Explorer becoming unresponsive.

Ethernet speed limits kick in at 328 feet, not before

Standard Ethernet installations are capped at a maximum total run of 328 feet, a figure set by networking standards to account for signal loss, interference and timing errors rather than an absolute cutoff. That distance typically breaks down into 295 feet of solid-core cable plus up to 33 feet of flexible patch cables at each end. Within that range, Cat5e or Cat6 cabling reliably supports 1 Gbps speeds, and everyday runs of 10 to 100 feet won't cause any slowdown.

Apple IT admins must rethink patch management as AI accelerates threats

Bradley Chambers argues that traditional software update cycles, like quarterly patches or annual macOS releases, are becoming obsolete as AI tools help attackers discover vulnerabilities faster. He outlines that IT teams now need a three-part strategy for patch management, starting with retraining end users to accept more frequent, less optional updates.

GitLab patches maximum-severity path traversal bug in commits API

GitLab issued emergency patches for CVE-2026-85706, a maximum-severity path traversal flaw in its repository commits API that lets unauthenticated attackers read arbitrary files on vulnerable servers. The company also fixed a second critical bug, CVE-2026-87719, an insecure deserialization issue in the GraphQL subscription serializer that could let authenticated Duo Chat users steal credentials and Advanced Search configurations. Both flaws are addressed in versions 19.3.2, 19.2.6, and 19.1.

Microsoft resolves ARM Windows bug crashing Teams and Outlook via September patch

Microsoft has patched a bug that stopped Teams and the new Outlook for Windows from launching on ARM-based devices like the Surface Pro 11 and Surface Laptop 7. The issue, triggered by August 2026 security updates (KB5121003), mainly hit new or freshly imaged PCs without Microsoft Store updates. The fix arrived with the September 8 cumulative update, KB5124012.

Today's top topics: openai apple anthropic qualcomm claude opus 5.5 artificial intelligence iphone 18 pro ai safety motorola signature 27 sam altman
View all today's topics →