ZeroHour

Search: “update”

20 stories

August updates trigger 0xc0000409 errors on Windows Server 2016

Microsoft says the August 2026 security update causes recurring CompatTelRunner.exe 0xc0000409 crashes on Windows Server 2016 with Compatibility Appraiser enabled; no functional impact.

Microsoft confirmed a known issue in which the August 2026 Windows security update generates recurring Application Error events (Event ID 1000, exception code 0xc0000409) in CompatTelRunner.exe on Windows Server 2016. The issue affects physical and virtual machines, including VMware and Azure environments, and per Microsoft does not affect device functionality. A permanent fix is planned for a future update, and the event log entries can be dismissed temporarily.

BleepingComputer · 8d agoAdvisory

CISA Updates Insider Threat Guide With New Mitigation Advice

CISA updated its Insider Threat Mitigation Guide on September 9 with new case studies and guidance on hybrid work, AI and employee separations.

CISA published a revision of its Insider Threat Mitigation Guide, first issued in 2020, adding case studies, statistics and guidance for security, HR and leadership audiences. New material covers hybrid and remote work changes to physical and digital access, AI used to manipulate or deceive, access control, visitor screening and adverse employee separations. The agency framed the update around growing insider threat impact on critical infrastructure and pointed to preparedness resources for organizations without existing programs.

Infosecurity Magazine · 6d agoAdvisory

CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages

CISA and FBI issued guidance urging service providers to deliver timely, transparent communications during major IT and OT outages.

CISA, with the FBI and international partners, released 'Communicating Under Pressure: Best Practices for Service Providers', urging providers to prepare crisis-communication procedures, provide timely status updates during IT/OT outages, and maintain out-of-band communication channels. The guidance warns that disruptions to telecom, cloud, energy, and water services can cascade across critical infrastructure. It aligns with CISA's CI Fortify initiative supporting IT/OT isolation and recovery.

GBHackers · 6d agoAdvisory

Update your firewall rules: Teams and Copilot are changing address

Microsoft is redirecting Microsoft 365 and Teams web users to new *.cloud.microsoft domains, requiring firewall and proxy rule updates by early October.

Starting September 2026, Microsoft is redirecting M365 web users to copilot.cloud.microsoft and Teams web users to teams.cloud.microsoft, announced via MessageCenter posts MC1465764 and MC1462915. All redirects should complete by early October 2026, with limited Teams exceptions possible until December 31, 2026. Microsoft advises reviewing client, proxy, firewall, and secure web gateway configurations, and suggests using TenantRestrictions to control personal Microsoft account access instead of blocking the new Copilot address.

CSO Online · 5d agoAdvisory1

TestFlight Update

Apple issued a routine TestFlight software update; the release notes contain no security or vulnerability details.

Apple's developer release feed lists a TestFlight update published on September 16, 2026. The available notes contain no listed CVEs, security fixes, or vulnerability information. This appears to be a routine application maintenance release for Apple's beta-testing platform.

Apple software releases · 12h agoAdvisory

App Store Connect Update

Apple issued an App Store Connect update with release notes published on its developer site.

Apple announced an update to App Store Connect, its developer tool for managing App Store submissions. No security fixes, CVEs, or notable changes were described in the announcement.

Apple software releases · 2d agoAdvisory

App Store Connect Update

Apple issued an App Store Connect update on September 9, 2026, with release notes published on its developer site.

Apple published an update to App Store Connect on September 9, 2026, announced via its developer news releases page. The notice links to release notes but does not describe specific changes. No vulnerabilities, CVEs, or security fixes are mentioned in the provided content.

Apple software releases · 7d agoAdvisory

TestFlight Update

Apple released an update to TestFlight, its beta app testing platform, with release notes published on the developer portal.

Apple published a software release notice for TestFlight, the company's beta testing platform for iOS, iPadOS, and other Apple platforms. The release notes are available through Apple's developer releases page. No security content or vulnerability details are provided in the notice.

Apple software releases · 22d agoAdvisory

Windows memory integrity switches on automatically for eligible devices in October 2026

Microsoft's Windows quality updates will automatically enable memory integrity and Virtualization-based Security on eligible devices starting October 2026.

Beginning in October 2026, Windows quality updates will automatically enable memory integrity on eligible devices and turn on Virtualization-based Security where it is not already running. Memory integrity restricts kernel-mode execution to trusted, signed code and drivers, blocking kernel compromise and rootkits. Microsoft said existing administrator decisions remain in effect, and readiness checks weigh hardware capability, compatibility, and performance. Memory integrity also underpins hotpatch updates that install without a reboot, so unprotected devices are excluded from that servicing model.

Help Net Security · 14d agoAdvisory1

AMD security advisory (AV26-879)

Canadian Centre for Cyber Security advisory AV26-879 lists vulnerabilities across AMD EPYC, Ryzen, Threadripper, Instinct, and embedded processors, urging updates.

The September 3, 2026 advisory states AMD is affected by processor vulnerabilities as of September 2, 2026, spanning 2nd-4th Gen EPYC, Ryzen 3000-7045 series, Athlon, Threadripper, Radeon PRO V620, Instinct MI300A, and embedded product lines. It specifies required microcode package versions for each affected family and encourages users and administrators to review AMD's links and apply updates as they become available.

Canadian Centre for Cyber Security · 13d agoAdvisory

Vulnerability & Patch Roundup — August 2026

Sucuri's monthly roundup compiles August 2026 security patches for the WordPress ecosystem to help site owners prioritize updates against automated exploitation.

Sucuri published its August 2026 Vulnerability & Patch Roundup summarizing essential security updates across the WordPress ecosystem. The post notes that most breaches the company observes begin with automated attacks exploiting previously disclosed vulnerabilities. It urges website operators to apply the listed plugin and theme patches promptly to avoid compromise and costly remediation. No specific CVE identifiers are named in the announcement.

Sucuri Blog · 16d agoAdvisory

ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up

ENISA warns frontier AI compresses attack lifecycles to minutes, with exploits possible within 15 minutes of disclosure and median 72-minute breach-to-exfiltration times.

ENISA's July 2026 paper 'ENISA's view on Cybersecurity in the Frontier AI Era' argues AI-assisted attackers may weaponize vulnerabilities within 15 minutes of disclosure and achieve initial-access-to-data-exfiltration in a median 72 minutes, creating a 'negative time-to-exploit' problem. The report cites one organisation whose CVE volume rose from roughly 80 in Q1 2025 to almost 500 in Q1 2026, then about 500 reports per day when frontier-AI tools were used. ENISA recommends machine-speed defence under 'Cybersecurity as Code', EPSS and VEX-based prioritisation, AI-assisted incident response with human oversight, and an assume-breached architecture.

Security Affairs · 2d agoAdvisory

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals

AWS Certificate Manager will phase out email validation for public certificates during 2027, requiring migration to DNS validation before September 30, 2027.

AWS Certificate Manager will stop offering email validation in new Regions on January 1, 2027, discontinue it for new certificate requests on March 31, 2027, and stop renewing email-validated certificates on September 30, 2027. This precedes the CA/Browser Forum's March 15, 2028 deadline ending email-based domain validation for publicly trusted certificates. AWS is updating the UpdateCertificateOptions API so customers can switch to DNS validation in place while retaining the certificate ARN, with Route 53 support for creating required CNAME records.

Help Net Security · Aug 14, 2026Advisory

CISA Releases Guidance on Deploying Cyber Decoys

CISA issued guidance on deploying honeypots, honeytokens, and decoy systems to detect adversaries and gather threat intelligence in critical infrastructure.

CISA released guidance on deploying cyber decoys, including lures, tripwires, decoy artifacts, honeytokens, and honeypots, within critical infrastructure organizations to complement Zero Trust models. The guidance outlines a three-phase operational process of preparation, execution, and understanding, advising decoys be placed where users rarely interact and configured to produce high-fidelity alerts. It aims to help defenders detect adversaries who use legitimate credentials, native tools, and living-off-the-land techniques, while enabling cost-effective threat intelligence collection.

SecurityWeek · 1h agoAdvisory

Using Cyber Decoys to Strengthen Detection and Response

CISA released guidance on cyber decoys—tripwires, breadcrumbs, honeytokens—to help defenders detect adversaries using valid credentials and living-off-the-land techniques.

CISA published guidance to help defensive teams of varying maturity plan and implement cyber decoys—assets that mimic legitimate systems, accounts, or data, such as tripwires, breadcrumbs, and honeytokens—to detect adversaries using legitimate credentials and living-off-the-land techniques. The guidance frames decoys as complementing Zero Trust by producing high-fidelity alerts, reducing alert fatigue, and exposing post-compromise activity like discovery, lateral movement, and data access. It maps decoy operations to the MITRE Engage and MITRE ATT&CK frameworks with low-complexity implementation steps.

CISA Advisories · 21h agoAdvisory

NIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery

NIST released IR 8587 giving agencies and cloud providers recommendations to prevent identity token forgery, theft, and misuse in SSO and API environments.

NIST Internal Report 8587, released September 15, 2026, provides implementation recommendations covering token creation, signing, validation, storage, revocation, and lifecycle management for SAML, OpenID Connect, and OAuth 2.0 environments. It builds on SP 800-53 Rev. 5.1.1 and incorporates lessons from breaches involving stolen signing keys, abused OAuth applications, and replayed federated assertions. Recommendations include strong signing algorithms, strict claim validation, short token lifetimes, token binding, leakage prevention, and monitoring for abnormal token use.

GBHackers · 1d agoAdvisory 2 sources

Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

NIST and CISA publish final interagency report with implementation guidance for protecting tokens and assertions from forgery and misuse.

CISA released a final NIST/CISA interagency report guiding federal agencies and cloud service providers on protecting identity assertions, access tokens, and cryptographic mechanisms underlying modern authentication and authorization. It addresses forgery, theft, and misuse of signed tokens that adversaries use for lateral movement and data access in hybrid and multi-cloud, SSO, federation, and API-based environments. The final version updates token validation, secrets management, and detection-at-scale guidance gathered via the Joint Cyber Defense Collaborative, and supports Executive Order 14306 and Secure by Design principles.

CISA Advisories · 1d agoAdvisory

Best Practices for Good Endpoint Hardening | Huntress

Huntress outlines endpoint hardening best practices, citing exposed RDP, RMM tool abuse, and ClickFix social engineering as common SMB intrusion paths.

Huntress published defensive guidance on endpoint hardening for small and mid-sized businesses, drawing on observations from its SOC. The post describes common intrusion vectors: internet-exposed RDP brute-forced by automated scanners, phishing emails delivering attacker-controlled remote monitoring and management (RMM) tools, with Huntress reporting a 277% spike in RMM abuse in 2025, and ClickFix attacks using fake CAPTCHA pages that trick users into running malicious commands. Recommended controls include scanning for exposed RDP, SSH, and VPN interfaces, removing unneeded local admin rights, enabling Windows Defender tamper protection, disabling SMBv1, and standardizing on one approved remote access tool, guided by CIS and NIST frameworks.

Huntress · 6d agoAdvisory

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Google announced Android 17 will enforce OS-wide Encrypted Client Hello with ECH GREASE, plus Certificate Transparency by default and carrier 2G disablement.

Google announced Android 17 network security protections headlined by OS-wide support for Encrypted Client Hello (ECH), with ECH GREASE enabled by default so connections to non-ECH servers look identical. Google's Jigsaw noted OkHttp has integrated ECH, letting third-party Android apps adopt the standard. The release also enforces Local Network Protection permission prompts, enables Certificate Transparency by default, and lets carriers turn off 2G by default to prevent downgrade attacks, rogue base stations, and SMS blasters. ECH was previously added to Chrome 117 and Firefox 118 at the browser level only.

The Hacker News · 19d agoAdvisory

CISA's logging guidance works beyond government

CISA released its Logging Reference Architecture in August 2026 to help federal agencies meet OMB M-26-14 logging requirements, usable as a benchmark by critical infrastructure operators.

CISA's Logging Reference Architecture (LRA), released in August 2026, helps US federal civilian agencies satisfy logging requirements in OMB Memorandum M-26-14 and explicitly encourages critical infrastructure operators to use it as a benchmark. The framework is organized around continuous event monitoring and threat hunting, investigation, response, and forensics, with a federal baseline of six months searchable and one year retrievable logs. Agencies must submit Agency Logging Plans within 90 days and work toward Advanced maturity within 320 days; the guidance also treats AI outputs as derived data requiring human review and preserved metadata.

Help Net Security · 24d agoAdvisory