Meta has patched a serious security vulnerability found in its Muse AI assistant. The flaw could have let attackers seize control of Muse and exploit its permissions to access a user's connected apps and devices.
A developer working on a project to run Linux on the PlayStation 5 has dropped the effort after Sony patched the underlying exploit, which had reportedly been surfaced with the help of AI tools. The fix closed off the vulnerability the project relied on to gain low-level access to the console.
Google has released stable versions of its AndroidX Security State and Security State Provider libraries, giving apps a way to check the security status of individual Android components rather than relying solely on the device's overall security patch date. Apps can now determine which specific fixes are installed, which updates are pending, and whether known vulnerabilities have been addressed, even if the broad patch level hasn't changed.
Microsoft released an out-of-band update this week for Windows 11 versions 26H2, 25H2, and 24H2 to fix an audio bug that broke sound on older USB devices using the legacy Audio Class 1.0 driver. The flaw, introduced by the September 8 security update, left affected headsets and speakers silent, with unresponsive volume controls or a Device Manager error. The new patch also resolves several other recent issues alongside a couple of security flaws.
Microsoft's latest Patch Tuesday addressed close to 1,000 vulnerabilities, but the scale of the update introduced new problems for some users. The company has since issued out-of-band emergency patches to correct issues caused by the original round of fixes.
PaperCut disclosed active exploitation of PaperCut NG/MF servers on August 27 with no CVE, no available exploit sample, and no patch. An emergency fix issued the next day was bypassed within hours, and a third patch only arrived on September 1, leaving customers exposed for roughly six days while attackers were already using the flaw in live attacks. A security researcher uses the episode to argue that the industry's old assumptions about response timelines no longer hold.
Microsoft has released an emergency out-of-band update to correct problems introduced by its September Patch Tuesday release, which fixed nearly 1,000 vulnerabilities but broke folder sharing on Hyper-V Linux virtual machines, disrupted Remote Desktop Services sessions, and caused issues with some USB audio devices. The new fix covers Windows 11 versions 26H1, 25H2, and 24H2, along with Windows Server 2025, 2022, and 2012 R2, plus LTSC editions of Windows 10.
Gene Moody, Field CTO at Action1, argues that IT teams face an unsustainable mismatch between the growing volume of software patches and the shrinking time available to test them, forcing many organizations to skip review steps and push updates straight to production. He warns that simply automating patch deployment to go faster does not solve the underlying problem, since automation can propagate a bad update across thousands of endpoints just as quickly as a good one.
Microsoft has verified that its September 2026 security updates are causing Remote Desktop Services failures across Windows Server 2012 and later, plus Windows 10 and 11. Affected systems show RDP connections dropping after a few minutes, sign-in errors, servers stuck loading the Remote Desktop Configuration screen, and related tools like MMC and File Explorer becoming unresponsive.
Standard Ethernet installations are capped at a maximum total run of 328 feet, a figure set by networking standards to account for signal loss, interference and timing errors rather than an absolute cutoff. That distance typically breaks down into 295 feet of solid-core cable plus up to 33 feet of flexible patch cables at each end. Within that range, Cat5e or Cat6 cabling reliably supports 1 Gbps speeds, and everyday runs of 10 to 100 feet won't cause any slowdown.
Bradley Chambers argues that traditional software update cycles, like quarterly patches or annual macOS releases, are becoming obsolete as AI tools help attackers discover vulnerabilities faster. He outlines that IT teams now need a three-part strategy for patch management, starting with retraining end users to accept more frequent, less optional updates.
Microsoft has patched a bug that stopped Teams and the new Outlook for Windows from launching on ARM-based devices like the Surface Pro 11 and Surface Laptop 7. The issue, triggered by August 2026 security updates (KB5121003), mainly hit new or freshly imaged PCs without Microsoft Store updates. The fix arrived with the September 8 cumulative update, KB5124012.