preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

digital-security devops microsoft windows windows-defender cve vulnerability-management patch-management zero-day europe

Microsoft's Patch for Its Own Antivirus Flaw Has Now Failed Twice

Two hours after Microsoft shipped its September 2026 Patch Tuesday, the researcher behind two earlier Windows Defender zero-days published a third proof of concept, ShieldCrash, that reads SYSTEM-level files on fully patched Windows 10, Windows 11 and Windows Server machines. Microsoft’s own patch for CVE-2026-69414, the ShieldBreak flaw it fixed only after bypass research forced its hand in August, is the fix ShieldCrash is reported to get around, and there is still no confirmed timeline for closing the gap.

digital-security devops mikrotik routeros networking self-hosted cve cisa-kev vulnerability-management patch-management europe

Your MikroTik Router Can Be Hijacked With No Password, and CERT Polska Says It Is Already Happening

Poland’s national CSIRT coordinated disclosure of a two-step attack chain, dubbed MikroTrick, that lets an attacker take full control of a MikroTik RouterOS device over SSH without ever supplying a valid password. CVE-2026-67276, an SSH public-key check that never validates the exponent, combines with CVE-2026-86060 to hand over root. MikroTik shipped fixes on September 3, CISA added the flaws to its Known Exploited Vulnerabilities catalog on September 10 with a September 13 deadline for US federal agencies, and CERT Polska says exploitation from internet-facing devices was already underway from at least September 2.

digital-security devops cve gitlab cicd cisa-kev vulnerability-management patch-management europe supply-chain

GitLab's Perfect-10 Bug Lets a Stranger Read Any File on Your Server, No Login Required

CVE-2026-85706, a maximum-severity path traversal flaw in GitLab’s repository commits API, went from patch to in-the-wild exploitation attempts in a single day. GitLab fixed it on September 10, CISA added it to its Known Exploited Vulnerabilities catalog on September 11 with a September 14 federal deadline, and researchers estimate more than 20,000 self-managed GitLab instances worldwide are still exposed.

email-deliverability dmarc bimi email compliance devops europe

Your Brand Logo Is Not Showing Up in Inboxes, and the Certificate You Bought Is Not the Problem

New research published today by email testing firm MailGenius finds that BIMI projects, the standard that puts a verified brand logo next to authenticated email, almost always stall on DMARC enforcement rather than on the certificate itself. A Certificate Transparency snapshot of over 20,000 BIMI certificates shows adoption growing fast, but the unglamorous work of getting every sending system to authenticate under a single enforced policy is what most teams underestimate.

devops github ci-cd linux supply-chain developer-tools infrastructure europe

A Quiet Key Expiry Just Started Breaking gh Installs Across Linux CI Pipelines

The PGP key signing GitHub CLI’s Linux APT and RPM packages expired on September 5, 2026. Any pipeline, base image, or server that installs or updates gh from those repositories without trusting the replacement key now fails with a signature verification error, often in the least convenient place: a CI job that has run unchanged for years.

compliance eu cyber-resilience-act digital-security regulation europe vulnerability-management devops enisa

The EU Cyber Resilience Act's Reporting Clock Started Today. Most Manufacturers Are Not Ready

From 11 September 2026, manufacturers of any product with digital elements sold in the EU must report actively exploited vulnerabilities within 24 hours through ENISA’s new Single Reporting Platform, which itself only went live today. The obligation and the tool to comply with it launched on the same date, leaving little runway for the testing and dry runs most compliance teams would normally insist on.

digital-security cve vulnerability firewall network cisa-kev malware vulnerability-management europe patch-management

30,000 FortiGate Firewalls Scanned for a Bug Patched Eight Months Ago

Attackers are exploiting CVE-2025-25249, a heap-based buffer overflow in FortiOS and FortiSwitchManager, to plant a custom remote access tool called PivotC2 on internet-exposed FortiGate appliances. Fortinet patched the flaw in January 2026, but researchers have logged scanning against roughly 30,000 IP addresses and confirmed 178 compromised sessions, and CISA only added it to its Known Exploited Vulnerabilities catalog on September 9.

digital-security cve vulnerability firewall network cisa-kev vulnerability-management europe patch-management

A Boot-Time Bug in Cisco's Firewall Manager Gives Attackers Root, No Password Needed

CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center, lets an unauthenticated attacker ride a leftover session from system startup into root access on the box that manages an organisation’s firewalls. Cisco has confirmed active exploitation linked to state-sponsored groups and ransomware operators, and CISA added it to its Known Exploited Vulnerabilities catalog on September 9 with a September 12 deadline for US federal agencies.

digital-security cve browser chrome chromium cisa-kev europe patch-management

Google Patched Its Second Chrome Zero-Day in Under a Week

CVE-2026-87491, an out-of-bounds write in Chrome’s V8 engine, was already being exploited in the wild when Google fixed it in Chrome 153.0.8010.36/.37 on September 8, five days after patching a separate actively exploited V8 flaw, CVE-2026-85046. It is the seventh Chrome zero-day of 2026, and CISA added it to its Known Exploited Vulnerabilities catalog on September 9.

digital-security devops microsoft windows patch-management vulnerability-management cve zero-day europe sharepoint

Microsoft Just Shipped Its Largest Patch Tuesday Ever. Two of the 973 Fixes Cannot Wait

Microsoft’s September 2026 Patch Tuesday fixes 973 vulnerabilities, the largest release on record, including two Windows privilege escalation flaws already being exploited in the wild. Neither zero-day gives an attacker remote entry on its own, but combined with almost any foothold they hand over full SYSTEM control, and a list this size means most patch teams cannot triage the rest of the queue this week.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!