ZeroHour

Search: “oob-update”

30 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

ChiPass Release 2026.09.0

Open-source project ChiPass tagged release 2026.09.0 on Codeberg, though the announcement includes no described changes, features, or fixes.

The ChiPass project published version 2026.09.0 as a tagged release on Codeberg, shared via the Lobsters community. The available announcement text contains no changelog, feature list, or vulnerability fixes, so the scope of changes in this release is unclear.

Lobsters · security · 5d agoTools

libpcap 1.10.7 fixes 7 vulnerabilities

libpcap 1.10.7 fixes seven vulnerabilities, including CVE-2026-31912 affecting the deprecated bpf_filter(), and all users are advised to update.

libpcap 1.10.7 was published on 2026-09-05 with its main focus being fixes for seven vulnerabilities. Maintainer Denis Ovsienko announced the release on the oss-security mailing list, noting that each CVE record contains detailed accounts and links to git commits with further explanation. For the CVE-2026-31912 fix to take effect, applications using the now deprecated bpf_filter() must update their usage. All users are advised to update; no exploitation in the wild is reported.

oss-security · 7d agoVulnerabilityCVE-2026-319121

automatic module_metadata_base.json update

Routine automated Metasploit Framework commit updating module metadata, with no disclosed vulnerability or exploitation activity.

The Metasploit Framework repository received an automatic update to its module_metadata_base.json file. The commit text contains no vulnerability details, CVE references, or new exploit modules. This is routine maintenance activity on the open-source penetration testing framework.

Metasploit Framework commits · 14d agoTools

Campaign Evolution: Darkleech to Pseudo

Unit 42 traces the pseudo-Darkleech campaign, which compromises websites to inject scripts redirecting visitors to exploit kits delivering ransomware.

Palo Alto Networks Unit 42 analyzed the evolution of the pseudo-Darkleech campaign, which injects malicious script into compromised Apache, IIS and WordPress sites to redirect visitors to exploit kits such as Angler and Neutrino. The original Darkleech Apache module infected thousands of servers starting in 2012 and delivered Blackhole EK until that kit disappeared after Paunch's 2013 arrest. From 2015 onward, pseudo-Darkleech delivered ransomware families like CryptoWall and TeslaCrypt, and by early 2016 its injected scripts added obfuscated numeric blocks with frequently changing separator characters. Unit 42 tracks these patterns to help defenders identify compromised websites.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild

Microsoft releases Windows 10 KB5122878 extended security update

Microsoft shipped Windows 10 ESU update KB5122878, delivering the record September 2026 Patch Tuesday fixes, including patches for two actively exploited zero-days.

Microsoft released KB5122878 for Windows 10 Enterprise LTSC and ESU customers, moving builds 19045/19044 to .7725 with security and bug fixes. The update carries this month's record September 2026 Patch Tuesday set, which fixed 966 Microsoft vulnerabilities including two actively exploited zero-day flaws. It also fixes BitLocker recovery-key prompts and Remote Desktop audio redirection, and updates Secure Boot certificate rollout and Morocco time zone data. Microsoft reports no known issues with the update.

BleepingComputer · 8d agoAdvisory in the wild

Identifying a BOLA Vulnerability in Harbor, a Cloud

Unit 42 found a BOLA flaw, CVE-2024-22278 (CVSS 6.4), letting Maintainers improperly alter Harbor project metadata; fixed in versions 2.9.5, 2.10.3, and 2.11.0.

Unit 42 researchers identified a broken object-level authorization flaw, CVE-2024-22278, in Harbor, a CNCF-graduated cloud-native container registry with 1.8 million downloads. The flaw (CVSS 6.4) lets users with the Maintainer role create, update, and delete project metadata, actions reserved for ProjectAdmin, risking data exposure, integrity compromise, and circumvention of vulnerability scanning. Harbor patched the issue in versions 2.9.5, 2.10.3, and 2.11.0. The finding came from Unit 42's automated BOLA detection tool built on generative AI.

Palo Alto Unit 42 · Aug 17, 2026VulnerabilityCVE-2024-22278

Update modules/auxiliary/scanner/http/elasticsearch_tika_xfa_xxe.rb

Rapid7 updated a Metasploit auxiliary scanner module that detects XML external entity injection in Elasticsearch via Apache Tika.

A commit in the Metasploit Framework updated modules/auxiliary/scanner/http/elasticsearch_tika_xfa_xxe.rb, an auxiliary scanner module. The module targets XML external entity (XXE) injection in Elasticsearch through Apache Tika, and was co-authored by jheysel-r7. The terse commit message contains no additional details, CVE references, or exploitation notes.

Metasploit Framework commits · 8d agoTools

automatic module_metadata_base.json update

Automated Metasploit Framework commit updating module_metadata_base.json to reflect newly added or modified exploit modules.

An automated commit updated module_metadata_base.json in the rapid7/metasploit-framework repository. The routine maintenance change reflects newly added or modified Metasploit modules and carries no standalone security significance.

Metasploit Framework commits · 13d agoTools1

Windows 11 cumulative updates KB5124008 & KB5122880 released

Microsoft shipped mandatory September 2026 Patch Tuesday cumulative updates KB5124008 and KB5122880 for Windows 11, fixing vulnerabilities and adding features.

Microsoft released Windows 11 KB5124008 (versions 25H2/24H2) and KB5122880 (23H2) cumulative updates containing the September 2026 Patch Tuesday security patches, described as covering 1,000 vulnerabilities discovered in previous months. The updates are mandatory and add features including movable and resizable taskbars, Start menu customization, a Windows Search option to hide Bing and Store web suggestions, and Administrator Protection, a just-in-time admin privilege feature that is off by default and configurable via Intune OMA-URI or Group Policy.

BleepingComputer · 8d agoAdvisory

AI Tool Identifies BOLA Vulnerabilities in Easy!Appointments

Unit 42's AI-powered tool found 15 BOLA vulnerabilities in Easy!Appointments, rated up to CVSS 9.9, letting low-privileged users escalate privileges; fixed in 1.5.0.

Unit 42's automated BOLA detection tool, built on generative AI, uncovered 15 broken object-level authorization flaws in the open-source scheduling application Easy!Appointments, tracked as CVE-2023-3285 through CVE-2023-3290 and CVE-2023-38047 through CVE-2023-38055. Nine flaws scored CVSS 9.9, letting logged-in customers view or manipulate appointments and accounts of providers and admins, including creating admin users for privilege escalation. The maintainers patched all issues in version 1.5.0. The same tool previously found a BOLA in Grafana (CVE-2024-1313).

automatic module_metadata_base.json update

Automated Metasploit Framework commit refreshes module_metadata_base.json with no new exploit content or vulnerability details.

An automated commit updated module_metadata_base.json in the Rapid7 Metasploit Framework repository. The change reflects routine metadata maintenance and introduces no new modules, exploits, or vulnerability information.

Metasploit Framework commits · 15d agoTools

automatic module_metadata_base.json update

Metasploit Framework pushed an automated update to its module_metadata_base.json module metadata file.

This repository commit is an automated update to the Metasploit Framework's module_metadata_base.json file. No new modules, vulnerabilities or exploit changes are described in the commit message.

Metasploit Framework commits · 14d agoTools

macOS 26.6.2 (25G83)

Apple released macOS 26.6.2 (build 25G83), a point update delivering security patches for Macs on the macOS 26 line.

Apple published macOS 26.6.2 (build 25G83) on August 17, 2026 via its software releases feed. The listing offers downloads and release notes only, without disclosing CVE identifiers or exploitation status. Security-focused point updates for macOS are relevant to enterprise Mac fleets and should be tested and deployed routinely.

Apple software releases · Aug 17, 2026Advisory

automatic module_metadata_base.json update

Metasploit Framework automatically updates its module metadata JSON in routine maintenance commit.

The Metasploit Framework repository received an automatic update to module_metadata_base.json, the metadata file that tracks module information. No specific new vulnerability, exploit module, or feature is described in the commit message. This is routine repository maintenance rather than a notable security event.

Metasploit Framework commits · 13d agoTools

Microsoft Patch Tuesday Update September 2026 – 974 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities across Windows and Office, including two actively exploited Windows privilege-escalation zero-days.

Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities spanning Windows, Office, SQL Server, SharePoint, Exchange, Azure, and developer tools. Two Windows zero-days are confirmed exploited in attacks: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a Windows Update Stack privilege-escalation flaw involving link following. The release also includes Critical fixes for Windows Secure Kernel Mode, VBS Enclave, Excel, and Word.

CryptoBit: Another Ransomware Family Gets an Update

Palo Alto Unit 42 analyzes updated CryptoBit ransomware distributed via the Rig exploit kit, documenting IOCs, eight sample hashes, and disguise tactics from June 2016.

Unit 42 observed an updated CryptoBit ransomware variant (also tracked as CriptoBit or Mobef) delivered through the Rig exploit kit via the gate domain realstatistics.info between June 17-27, 2016. Infections targeted Windows hosts with out-of-date Flash plugins, and post-infection callbacks used fake user-agents and referrers to disguise traffic to laoismacau.com. At least eight samples were collected, and by June 27 the campaign had begun distributing other malware.

Palo Alto Unit 42 · Aug 17, 2026Ransomware in the wild

From Report to Patch, the OpenBSD Errata Process

A talk walks through the OpenBSD errata process, tracing how vulnerability reports become coordinated, tested, and published security patches.

A Lobsters-linked presentation describes the OpenBSD errata process, covering how a security report travels from initial disclosure to a published patch and errata notice. The linked page itself contains no additional technical detail beyond the title.

Lobsters · security · 8h agoResearch

Agnes-AI/Agnes-3.0-Flash — new model trending #30 on Hugging Face

Agnes AI releases open-weight Agnes-3.0-Flash Preview, a 33B multimodal model with 262k-token context under Apache 2.0.

Agnes AI released Agnes-3.0-Flash Preview, an open-weights multimodal checkpoint with 33B parameters and a 262,144-token context window under Apache 2.0. The model supports text, image, and video understanding, tool calling, and adjustable reasoning effort. The repo clarifies this preview checkpoint is distinct from the production/API Agnes 3.0 Flash model, which uses a different configuration with a 1M-token context window. Reported reference results include IFBench 74.20 and SciCode 38.08 against peers such as Qwen3.6-35B-A3B, Kimi K2.5, and MiniMax M3.

Hugging Face trending models · 5d agoModel release

Edge0/Edge0-35B-A3B-preview — new model trending #30 on Hugging Face

Edge0 released a 35B sparse MoE model running in under 3 GiB of memory at 15 tok/s via SSD expert offload and int4 quantization.

Edge0-35b-a3b-preview is a 35B-parameter MoE (256 experts, 4 active per token) built on Qwen3.5-MoE 35B-A3B, shipped as a 4-bit checkpoint with LoRA and prerouter adapters under Apache 2.0. The edge0 framework streams expert weights from SSD on demand, bounding peak active memory at 2.9 GiB and achieving 14.9-17.7 tok/s decode on a Mac mini M4 Pro (MLX backend). Recover-LoRA distillation keeps the int4 model within 3.9 points of its fp16 base (79.2 vs 83.2 average on OpenCompass benchmarks including AIME 2026, HumanEval, GPQA-Diamond, MMLU-Pro, and IFBench).

Hugging Face trending models · 8d agoModel release

The OCUDU dApp Platform: An Open Runtime and E3 Interface for Real-Time AI-RAN

OCUDU open runtime lets third-party signed AI-RAN dApps run inside production 5G distributed units under three timing contracts, released as BSD-3 preview.

The OCUDU dApp platform provides an open runtime and E3 interface for executing signed AI-RAN applications inside a production 3GPP NR distributed unit, where prior dApp frameworks could only observe export streams. Modules run under three typed timing contracts: GPU receive-chain residency (Class A), the scheduler's 100 microsecond deadline (Class B), or non-blocking observer (Class C). On a GB10 gNB, dApps including an out-of-tree neural equalizer ran on a live cell without fallback. Platform, SDK, and a zero-hardware quickstart are public under BSD-3-Clause-Clear as a preview of the OCUDU AI-RAN Working Group 2.

arXiv cs.AI / cs.LG / cs.CL · 9d agoAI tools & infra1

State of Open Models: Summer 2026 Observations

Hugging Face publishes observations on the state of the open-weights model ecosystem as of summer 2026.

A Hugging Face blog post titled 'State of Open Models: Summer 2026 Observations' surveys developments across the open-weights model ecosystem. No article text was available, so specific model releases, benchmarks, and findings are not detailed here.

Hugging Face Blog · Aug 14, 2026AI industry

Microsoft confirms KB5002914 Excel update breaks copy and paste

Microsoft confirms KB5002914 Office security update silently breaks copy-paste, autofill, and formula dragging in Excel 2016 through 2024.

Microsoft confirmed the September 2026 KB5002914 security update breaks copy-and-paste, autofill, and formula dragging in Excel 2024, 2021, 2019, and 2016. Failures occur silently with no beep or error message, leaving the destination unmodified. Uninstalling KB5002914 via OfficeC2RClient or Oarpmany restores functionality while Microsoft investigates.

BleepingComputerupdated · 1d agofirst · 1d agoAdvisory 3 sources1

visionOS 26.6.1 (23O780)

Apple shipped visionOS 26.6.1 (build 23O780), a security and maintenance update for Vision Pro headsets.

Apple listed the visionOS 26.6.1 release (build 23O780) on August 17, 2026. The announcement contains only download and release note links, with no CVE identifiers or exploitation details disclosed in the feed text. Updates to visionOS generally bundle security patches alongside functional improvements for Apple Vision Pro.

Apple software releases · Aug 17, 2026Advisory

tvOS 27.0 beta 8 (24J5360a)

Apple seeded tvOS 27.0 beta 8 (build 24J5360a) to developers as the annual fall OS release cycle approaches final builds.

Apple released the eighth beta of tvOS 27.0, build 24J5360a, through its developer program on August 31, 2026. The listing contains only download links and release notes with no disclosed security fixes or CVEs. Beta 8 indicates the pre-release cycle is nearing the stable 27.0 rollout.

Apple software releases · 16d agoAdvisory

Launching managed CRA Article 14 reporting for open source maintainers

EU Cyber Resilience Act Article 14 reporting obligations begin, requiring 24-hour exploit and incident reports; Patchstack launches managed compliance for open-source maintainers.

Starting 11 September 2026, EU Cyber Resilience Act Article 14 requires manufacturers and open-source stewards to report actively exploited vulnerabilities and severe security incidents to ENISA via the EU Single Reporting Platform, with a 24-hour early warning, 72-hour notification, and final reports within 14 days or one month. Patchstack launched a free managed compliance service, acting as Assigned Representative for open-source maintainers and providing a managed VDP. The obligations apply retroactively to all products available on the European market. Patchstack, which has coordinated over 50% of known WordPress ecosystem vulnerabilities, already serves more than 1,000 open-source projects.

Patchstack · 5d agoPolicy & legal

Severity Is Not a Strategy: What CISA BOD 26-04 Means for the Future of Federal Software Security

CISA's BOD 26-04 replaces severity-based federal patching with risk-based remediation deadlines of 3, 14, or 60 days.

CISA's Binding Operational Directive 26-04, released June 10, 2026, replaces BOD 19-02 and BOD 22-01 for Federal Civilian Executive Branch agencies and shifts remediation prioritization from CVSS scores to risk context. Agencies assess four factors: public exposure, KEV listing, exploit automatability, and whether exploitation grants partial or total asset control, resulting in 3-, 14-, or 60-day remediation windows or next-upgrade fixes. In CISA's first review at a large civilian agency, only 1% of vulnerabilities required three-day remediation while over 60% could wait for future system upgrades. The directive also requires forensic analysis when exploitation is suspected, and Checkmarx argues the same risk-based logic must extend upstream into software development and SBOM-driven exposure management.

Checkmarx · 7d agoPolicy & legal

automatic module_metadata_base.json update

Routine automated Metasploit Framework commit updates module_metadata_base.json with new module metadata.

The Metasploit Framework repository received an automated commit updating module_metadata_base.json, the file that tracks module metadata for the framework. This is routine maintenance accompanying new or updated exploit modules rather than a standalone disclosure. No vulnerability details, CVEs, or exploitation evidence are included.

Metasploit Framework commits · 13d agoTools

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft issued emergency Windows 11 update KB5129195 to fix Patch Tuesday regressions and fully close the CVE-2026-62721 privilege escalation flaw.

Microsoft shipped out-of-band cumulative update KB5129195 for Windows 11 24H2 and 25H2 (builds 26100.9457 and 26200.9457) after the September 8 Patch Tuesday rollup, which addressed over 960 CVEs including two actively exploited flaws, broke Remote Desktop Services, Hyper-V Plan9 folder sharing, and USB audio. The emergency release also strengthens the incomplete fix for CVE-2026-62721, an elevation-of-privilege flaw in the Windows User-Mode Power Service that could let a local attacker gain SYSTEM privileges. Companion patches cover Windows 11 26H1, Windows 10, and Windows Server. Some USB Audio Class 1.0 and AMD Radeon graphics issues remain unresolved.

Cyber Security News · 12h agoVulnerability in the wildCVE-2026-62721

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.

automatic module_metadata_base.json update

Metasploit Framework's automated pipeline refreshed its module metadata file, a routine repository maintenance commit introducing no new modules or exploits.

An automated Metasploit Framework commit updated module_metadata_base.json, the metadata database consumed by module tooling. The change is routine maintenance and contains no new exploit modules or vulnerability content.

Metasploit Framework commits · 13d agoTools1