ZeroHour

Search: “developer-release”

27 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

iOS 27.0 RC (24A437)

Apple issues iOS 27.0 release candidate (build 24A437); notification lists no security fixes or CVEs.

Apple published the iOS 27.0 Release Candidate, build 24A437, on its developer release feed. The notice provides only download and release-notes links without vulnerability or CVE details. Security teams should monitor the accompanying release notes for security fixes ahead of general availability.

Apple software releasesupdated · 2d agofirst · 5d agoAdvisory 3 sources

iOS 26.6.2 (23G90)

Apple released iOS 26.6.2 (build 23G90), a minor software update listed on its developer releases page without vulnerability details.

Apple released iOS 26.6.2, build 23G90, listed on its developer software releases page dated September 8, 2026. The available page content only provides download links, with no published vulnerability details, CVEs, or change notes in the source text.

Apple software releases · 8d agoAdvisory 2 sources

iOS 27.2 beta (24B5084k)

Apple released iOS 27.2 beta build 24B5084k to developers for testing.

Apple has published iOS 27.2 beta build 24B5084k on its developer release portal. The listing includes download access and release notes but discloses no security fixes or CVEs.

Xcode 27.2 beta (27B5019j)

Apple released Xcode 27.2 beta build 27B5019j to developers for testing.

Apple has published Xcode 27.2 beta build 27B5019j on its developer release portal, with downloads and release notes available. The notice contains no security advisories or CVE information.

Apple software releases · 5h agoAdvisory

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors

Canonical ships Ubuntu 24.04.5 LTS point release bundling security fixes into fresh install media for desktop, server and nine other flavors.

Canonical released Ubuntu 24.04.5 LTS, a point release for the Noble Numbat series that folds accumulated security corrections and high-severity bug fixes into new installation media. Nine flavors including Kubuntu, Xubuntu, Ubuntu MATE, Ubuntu Studio and Edubuntu also moved to 24.04.5. Existing 22.04 LTS users receive the fixes through the automatic upgrade path at no cost. The release notes name no CVEs or bug IDs, and support timelines still count from the original 24.04 launch date (five years for Desktop/Server/Cloud/Core, three for flavors, extendable with Expanded Security Maintenance).

Help Net Securityupdated · 1h agofirst · 5d agoAdvisory 15 sources

TestFlight Update

Apple released an update to TestFlight, its beta app testing platform, with release notes published on the developer portal.

Apple published a software release notice for TestFlight, the company's beta testing platform for iOS, iPadOS, and other Apple platforms. The release notes are available through Apple's developer releases page. No security content or vulnerability details are provided in the notice.

Apple software releases · 22d agoAdvisory

iOS 18.7.10 (22H374)

Apple released iOS 18.7.10 (build 22H374), a maintenance update delivering security fixes for iPhones on the iOS 18 line.

Apple published the iOS 18.7.10 release (build 22H374) on August 17, 2026 via its software releases feed. The listing provides download links and release notes but includes no CVE details in the announcement text. Point releases on the legacy iOS 18 branch typically carry security and stability patches for devices not yet on iOS 26.

Apple software releases · Aug 17, 2026Advisory

Xcode 27 RC (27A266a)

Apple released the Xcode 27 release candidate (build 27A266a) via its developer releases page.

Apple has published a release candidate of Xcode 27, build 27A266a, on its developer releases page. The listing contains no security notes, CVEs, or vulnerability details in the available text. This is a routine vendor software release ahead of the final Xcode 27 version.

Apple software releases · 7d agoAdvisory

iOS 27.0 RC (24A435)

Apple seeded iOS 27.0 release candidate build 24A435 to developers ahead of the general release.

Apple released the iOS 27.0 release candidate (build 24A435) through its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releases · 7d agoAdvisory 2 sources

App Store Connect Update

Apple issued an App Store Connect update with release notes published on its developer site.

Apple announced an update to App Store Connect, its developer tool for managing App Store submissions. No security fixes, CVEs, or notable changes were described in the announcement.

Apple software releases · 2d agoAdvisory 2 sources

There Is No Patch Tuesday on the Blockchain: Why Solidity Developers Need Fusion-Grade AppSec Before They Deploy

Checkmarx argues Solidity developers need pre-deployment AppSec because disclosure-to-weaponization time has collapsed from 840 days to 1.6 days.

A Checkmarx write-up contrasts traditional software patch cycles with blockchain development, where there is no Patch Tuesday and fixes require on-chain upgrades. It cites stats that median disclosure-to-weaponization time collapsed from 840 days to 1.6 days and that 80% of exploitations now occur on or before disclosure day. The piece advocates fusion-grade application security for Solidity teams before contracts deploy.

Checkmarx · Aug 17, 2026Research1

Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps

Wiz published a DFIR cheatsheet covering log visibility, incident readiness, and threat hunting across GitHub, GitLab, Bitbucket, and Azure DevOps.

Wiz researchers released a practitioner's guide to version control system forensics, incident response, and threat hunting. The cheatsheet maps log sources, audit capabilities, and hunting workflows across GitHub, GitLab, Bitbucket, and Azure DevOps. It aims to improve incident readiness for source code and CI/CD compromise scenarios.

Wiz Blog · 20d agoResearch1

macOS 27.0 RC (26A428)

Apple seeded the macOS 27.0 Release Candidate (build 26A428) to developers ahead of the final public release.

Apple published a Release Candidate build of macOS 27.0, labeled 26A428, on its developer release page. The notice only provides download and release-notes links and includes no security content, CVEs, or threat information. RC builds typically precede the general availability of the final operating system version.

Apple software releases · 7d agoAdvisory

WordPress 7.0.4 Release

WordPress releases 7.0.4 with a security fix and urges all sites to update immediately.

WordPress.org announced the availability of WordPress 7.0.4, a maintenance release containing a security fix. Because it is a security release, the project recommends updating sites immediately via the dashboard or a download from WordPress.org. The announcement gives no technical details about the flaw being patched.

WordPress.org · Security · Aug 12, 2026Advisory

iPadOS 26.7 (23H24)

Apple released iPadOS 26.7 (build 23H24) on September 9, 2026; the notice lists downloads without describing security fixes.

Apple shipped iPadOS 26.7, build 23H24, made available through its developer downloads page on September 9, 2026. The release announcement provides no description of changes, vulnerabilities, or CVEs. Apple point releases frequently bundle security patches, but none are confirmed in the available text.

Apple software releases · 7d agoAdvisory

Xcode 27 (27A266a)

Apple released Xcode 27 (build 27A266a) with no security fixes detailed in the announcement.

Apple published Xcode 27 (27A266a) on its developer news feed. The notice contains only download and release-note links. No security content is described in the announcement itself.

Apple software releases · 2d agoAdvisory

iOS 26.6.1 (23G83)

Apple released iOS 26.6.1 (build 23G83), a point update with security fixes for iPhones running iOS 26.

Apple published iOS 26.6.1 (build 23G83) on August 17, 2026 through its software releases page. The feed entry provides downloads and release notes only, without enumerating fixed CVEs or noting any active exploitation. Such rapid point releases typically address security vulnerabilities and stability regressions in iOS 26.

Apple software releases · Aug 17, 2026Advisory

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Unit 42 warns attackers increasingly target CI/CD pipelines and developer tools rather than application code, urging full SDLC supply chain visibility.

Palo Alto Networks Unit 42 research argues attackers are shifting focus from application code to overlooked corners of the software development lifecycle supply chain, including CI/CD pipelines and developer tooling. The write-up calls for total SDLC visibility and strict security controls to defend these developer-facing attack surfaces.

Palo Alto Unit 42 · 25d agoResearch in the wild

macOS 27.2 beta (26B5086k)

Apple released macOS 27.2 beta build 26B5086k to developers for testing.

Apple has published macOS 27.2 beta build 26B5086k on its developer release portal with downloads and release notes. The notice contains no security advisories or CVE information.

Apple software releases · 5h agoAdvisory

Closing the Blind Spot: Securing Personal Repositories in the Software Supply Chain

Wiz highlights personal developer repositories as a supply chain blind spot leaking corporate secrets, offering correlation-based risk validation and remediation.

Wiz argues that developers' personal code repositories are a blind spot in software supply chain security where corporate secrets quietly escape. The company describes an approach that correlates personal repositories to specific developers, validates the actual risk, and drives remediation. No specific incident or vulnerability is disclosed in the announcement.

Wiz Blog · Aug 13, 2026Tools2

Fwd: Tor Project Forum: Security Release 0.4.9.12

Tor released 0.4.9.12 with several high-severity fixes, some found via LLMs, plus recommended protocol updates and removal of TAP key acceptance.

The Tor Project shipped version 0.4.9.12, a security release containing several high-severity fixes, some reportedly discovered with the help of LLMs. The release recommends new protocol versions (41316) for both clients and relays. Directory authorities will no longer accept relay descriptors containing TAP keys.

oss-security · 8d agoVulnerability

macOS 26.6.2 (25G83)

Apple released macOS 26.6.2 (build 25G83), a point update delivering security patches for Macs on the macOS 26 line.

Apple published macOS 26.6.2 (build 25G83) on August 17, 2026 via its software releases feed. The listing offers downloads and release notes only, without disclosing CVE identifiers or exploitation status. Security-focused point updates for macOS are relevant to enterprise Mac fleets and should be tested and deployed routinely.

Apple software releases · Aug 17, 2026Advisory

Package Manager Trends

Sixteen-week roundup finds package managers converging on release-age cooldowns, install-script blocking, malware scans, and recurring path-traversal and credential-leak fixes.

The author aggregates supply-chain security trends from sixteen weeks of This Week in Package Management, built from about 80 RSS feeds. Release-age cooldown gates shipped in Deno 2.8, Bundler, npm, Yarn, mise, Hex, Mamba, and Cargo, with Dependabot making a three-day cooldown default in August. npm 12 and Bun 1.4 now block lifecycle install scripts by default, and Composer 2.10 and uv added install/publish-time malware checks, while npm's registry began scanning at publish time. Path traversal on archive extraction was fixed in 14 of 16 weeks across tools including uv, pnpm, Docker, and Composer, and credential-misdirection bugs affected Cargo, ORAS, Composer, and Renovate.

Lobsters · security · 6d agoResearch1

visionOS 27.0 RC (24M362)

Apple seeded visionOS 27.0 release candidate build 24M362 to developers ahead of the general release.

Apple released the visionOS 27.0 release candidate (build 24M362) through its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releases · 7d agoAdvisory2

"They don't care about this": A Systematic Study of TEE Build Reproducibility in the Wild

91% of 115 surveyed TEE deployments across Intel SGX, TDX, and AMD SEV fail to provide reproducible builds needed for verifiable remote attestation.

A systematic study of 115 TEE deployments found 91% were not reproducible and 80% lacked both source code and a reference build, undermining remote attestation guarantees. Interviews with 12 developers of 50 Intel SGX projects confirmed that only one participant treats reproducibility as a development priority. The authors identify technical barriers such as embedded timestamps plus ecosystem-level issues like lack of build-environment control in multi-stakeholder projects, and call for holistic, committed reproducibility practices.

arXiv cs.CR · 6d agoResearch

Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers

SpecterOps released CDP-Enable-BOF, a Beacon Object File that enables Chrome DevTools Protocol in live Chrome or Edge processes on Windows for session hijacking.

SpecterOps released CDP-Enable-BOF, an x64 Beacon Object File that activates Chrome DevTools Protocol inside running chrome.exe or msedge.exe processes on Windows, exposing cookies, history, saved passwords, and authenticated sessions without administrator rights. It calls Chromium's StartRemoteDebuggingServer on the browser UI thread to stay reliable under CFG, TLS, and CET, and was tested on Chrome 147 and Edge 147. The technique builds on work by DeathFlamingo and Cedric Van Bockhaven; Google had hardened remote debugging in Chrome 136 after attackers used it to steal cookies post-App-Bound Encryption. Defenders can watch Sysmon Event IDs 8 and 10 for injection into browser processes.

The Hacker News · 22d agoResearch2

Upcoming C-tor security release - 0.4.9.12

Tor Project announces an upcoming C-tor security release 0.4.9.12 addressing a security flaw.

The Tor Project forum posted a heads-up for an upcoming security release of the C implementation of Tor, version 0.4.9.12. The post text contains no additional details about the vulnerability, affected versions, or exploitation status. The announcement signals that users should prepare for a patch.

Lobsters · security · 13d agoAdvisory