September Windows Server updates break Remote Desktop Services
September 2026 Windows Server cumulative updates cause Remote Desktop Services failures on Server 2019, 2022 and 2025, forcing some admins to roll back.
Admins report Remote Desktop Services failures after installing September 2026 Patch Tuesday updates KB5122876 (Server 2019), KB5122882 (Server 2022), and KB5122871 (Server 2025), with connections hanging, sessions failing after logout, and some systems requiring hard resets. One administrator debugging Server 2022 observed an apparent deadlock between RDP and the Local Session Manager, though Microsoft has not confirmed a root cause. Rolling back the updates restores RDS functionality but removes this month's security fixes. Microsoft had not responded to inquiries at publication time.
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
CERT/CC warns Skullcandy Dime 3 earbuds accept silent Bluetooth pairings via CVE-2025-20701, letting nearby attackers hijack audio and microphone.
CERT/CC reports the Skullcandy Dime 3 (model S2DCW) running firmware 1.0.0.28 is affected by CVE-2025-20701, a high-severity missing-authentication flaw in the Airoha Bluetooth Audio SDK. An attacker in close range can pair without user interaction, then hijack audio playback, access the headset profile, and capture live microphone audio. Skullcandy fixed the issue in firmware 1.0.0.30, but existing units have no consumer-accessible update path via the app. The flaw was discovered by ERNW researchers and affects earbud and headphone products from multiple vendors; Apple patched it for Beats Studio Buds in June.