ZeroHour

Search: “os-release”

26 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

iPadOS 27.0 (24A437)

Apple released iPadOS 27.0 (build 24A437) with no security fixes detailed in the announcement.

Apple published iPadOS 27.0 (24A437) on its developer news feed. The notice only links to downloads and release notes without describing security updates. Security content should be verified in the full release notes.

Apple software releases · 1d agoAdvisory 3 sources

macOS 27.0 RC (26A428)

Apple seeded the macOS 27.0 Release Candidate (build 26A428) to developers ahead of the final public release.

Apple published a Release Candidate build of macOS 27.0, labeled 26A428, on its developer release page. The notice only provides download and release-notes links and includes no security content, CVEs, or threat information. RC builds typically precede the general availability of the final operating system version.

Apple software releasesupdated · 1d agofirst · 6d agoAdvisory 2 sources

iPadOS 27.0 RC (24A435)

Apple seeded iPadOS 27.0 release candidate build 24A435 to developers ahead of the general release.

Apple released the iPadOS 27.0 release candidate (build 24A435) via its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releases · 6d agoAdvisory 2 sources

macOS 26.6.2 (25G83)

Apple released macOS 26.6.2 (build 25G83), a point update delivering security patches for Macs on the macOS 26 line.

Apple published macOS 26.6.2 (build 25G83) on August 17, 2026 via its software releases feed. The listing offers downloads and release notes only, without disclosing CVE identifiers or exploitation status. Security-focused point updates for macOS are relevant to enterprise Mac fleets and should be tested and deployed routinely.

Apple software releases · 29d agoAdvisory

tvOS 27.0 RC (24J360)

Apple seeded tvOS 27.0 release candidate build 24J360 to developers ahead of the general release.

Apple released the tvOS 27.0 release candidate (build 24J360) through its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releases · 6d agoAdvisory

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors

Canonical ships Ubuntu 24.04.5 LTS point release bundling security fixes into fresh install media for desktop, server and nine other flavors.

Canonical released Ubuntu 24.04.5 LTS, a point release for the Noble Numbat series that folds accumulated security corrections and high-severity bug fixes into new installation media. Nine flavors including Kubuntu, Xubuntu, Ubuntu MATE, Ubuntu Studio and Edubuntu also moved to 24.04.5. Existing 22.04 LTS users receive the fixes through the automatic upgrade path at no cost. The release notes name no CVEs or bug IDs, and support timelines still count from the original 24.04 launch date (five years for Desktop/Server/Cloud/Core, three for flavors, extendable with Expanded Security Maintenance).

Help Net Securityupdated · 5d agofirst · 5d agoAdvisory 13 sources

tvOS 27.0 beta 8 (24J5360a)

Apple seeded tvOS 27.0 beta 8 (build 24J5360a) to developers as the annual fall OS release cycle approaches final builds.

Apple released the eighth beta of tvOS 27.0, build 24J5360a, through its developer program on August 31, 2026. The listing contains only download links and release notes with no disclosed security fixes or CVEs. Beta 8 indicates the pre-release cycle is nearing the stable 27.0 rollout.

Apple software releases · 15d agoAdvisory

visionOS 27.0 RC (24M362)

Apple seeded visionOS 27.0 release candidate build 24M362 to developers ahead of the general release.

Apple released the visionOS 27.0 release candidate (build 24M362) through its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releasesupdated · 1d agofirst · 6d agoAdvisory 2 sources2

tvOS 27.0 (24J361)

Apple released tvOS 27.0 (build 24J361) with no security fixes detailed in the announcement.

Apple published tvOS 27.0 (24J361) on its developer news feed. The notice contains only download and release-note links with no security content described. Any security fixes would be listed in the full release notes.

Apple software releases · 1d agoAdvisory

macOS 27.0 beta 8 (26A5425a)

Apple seeded macOS 27.0 beta 8 (build 26A5425a) to developers with no security fixes disclosed ahead of the final release.

Apple released macOS 27.0 beta 8, build 26A5425a, through its developer program on August 31, 2026. The listing contains only download links and release notes with no vulnerability or CVE information. It is the eighth beta seed in the macOS 27.0 pre-release cycle.

Apple software releases · 15d agoAdvisory

iPadOS 26.7 (23H24)

Apple released iPadOS 26.7 (build 23H24) on September 9, 2026; the notice lists downloads without describing security fixes.

Apple shipped iPadOS 26.7, build 23H24, made available through its developer downloads page on September 9, 2026. The release announcement provides no description of changes, vulnerabilities, or CVEs. Apple point releases frequently bundle security patches, but none are confirmed in the available text.

Apple software releases · 6d agoAdvisory

iPadOS 26.6.2 (23G90)

Apple released iPadOS 26.6.2 (build 23G90), a minor software update listed on its developer releases page without vulnerability details.

Apple released iPadOS 26.6.2, build 23G90, listed on its developer software releases page dated September 8, 2026. The available page content only provides download links, with no published vulnerability details, CVEs, or change notes in the source text.

Apple software releases · 7d agoAdvisory 2 sources

Re: Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more

oss-security thread discusses newly disclosed Linux kernel local privilege escalations, including ZcopyReaper (CVE-2026-43502) and about 20 more flaws.

An oss-security mailing list thread discusses newly disclosed Linux kernel local privilege escalation (LPE) issues, headlined by ZcopyReaper (CVE-2026-43502) along with roughly 20 more. Discussants ask whether the many reports could be summarized and note that locking kernel module loading after boot has repeatedly proven an effective mitigation. The visible discussion does not state whether any of the flaws are exploited in the wild or give specific patch guidance beyond the individual reports.

oss-security · 7d agoVulnerabilityCVE-2026-43502

Xcode 27 RC (27A266a)

Apple released the Xcode 27 release candidate (build 27A266a) via its developer releases page.

Apple has published a release candidate of Xcode 27, build 27A266a, on its developer releases page. The listing contains no security notes, CVEs, or vulnerability details in the available text. This is a routine vendor software release ahead of the final Xcode 27 version.

Apple software releasesupdated · 1d agofirst · 6d agoAdvisory 2 sources

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Malicious LiteLLM 1.82.7/1.82.8 PyPI releases tied to the Trivy TeamPCP campaign harvested cloud, SSH, and database credentials, potentially exposing 2,500+ organizations.

CloudSEK reported that two malicious LiteLLM releases on PyPI (versions 1.82.7 and 1.82.8, live about 40 minutes on March 24) harvested cloud keys, SSH keys, Kubernetes tokens, and database passwords, with captured loot files mapping potential exposure to more than 2,500 organizations including NVIDIA, Cisco, Deloitte, Volkswagen, FedEx, Siemens, and X Corp. The campaign is part of TeamPCP (tracked by Google as UNC6780), linked to the Aqua Security Trivy scanner compromise tracked as CVE-2026-33634 and added to CISA's Known Exploited Vulnerabilities catalog on March 26. The payload used a litellm_init.pth file executed at Python interpreter startup and exfiltrated secrets to models.litellm[.]cloud; the FBI's FLASH-20260702-01 advisory urged rotation of CI/CD, publishing, and cloud credentials.

The Hacker News · Aug 12, 2026Data breach in the wildCVE-2026-33634

watchOS 27.0 RC (24R363)

Apple seeded watchOS 27.0 release candidate build 24R363 to developers ahead of the general release.

Apple released the watchOS 27.0 release candidate (build 24R363) through its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releases · 6d agoAdvisory

TPMSpy: Validation of Measured Boot Systems by Low-Level Tracing of TPM Usage

Researchers present TPMSpy, a platform-agnostic method validating TPM Measured Boot via low-level tracing, finding inconsistent Linux systemd measurements that break remote attestation and LUKS decryption.

An arXiv paper (2609.05011) introduces TPMSpy, a method that analyzes virtualized system–TPM interactions to independently reconstruct and validate TPM Event Logs without relying on the quoting mechanism, applicable to open and closed systems and demonstrated on Linux and Windows. A longitudinal analysis of Linux systems running systemd versions 245–258 (2020–2025) found wide divergence in Measured Boot usage, undocumented behavioral changes, and no common usage pattern. The authors report inconsistent measurement of user-space systemd services, which prevents reliable remote attestation and LUKS disk decryption on affected systems.

arXiv cs.CR · 12d agoResearch

[webapps] CorgetGpsDget 2_3.2 - OS Command Injection

Exploit-DB publishes OS command injection exploit for the obscure CorgetGpsDget 2_3.2 web application.

A public exploit demonstrates OS command injection in CorgetGpsDget version 2_3.2. The flaw could allow attackers to execute arbitrary operating system commands on the hosting server. The product appears to have limited deployment, reducing real-world exposure.

Exploit-DB · Aug 10, 2026Exploit / PoC

Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws

Jellyfin 12.0 fixes unauthorized file access and web client XSS flaws, but requires careful upgrades due to breaking database migrations and plugin changes.

The open-source media server release prevents crafted requests from reading files outside designated directories, blocks unauthorized re-runs of the setup wizard, rejects plugin packages with unsafe names, strengthens parental control enforcement, and fixes cross-site scripting vulnerabilities in browser-based administration and media access workflows. Upgrades require a manual backup because the database schema migration is irreversible; supported paths start from version 10.10.7 or 10.11.x, and duplicate case-insensitive usernames will break migration. The release also retires legacy /emby/ and /mediabrowser/ routes, disables deprecated authentication by default, and targets .NET 10, requiring plugin rebuilds.

GBHackers · 8d agoVulnerability1

Re: Vulnerability fixes in util-linux-2.42.3

util-linux 2.42.3 includes vulnerability fixes, with a commit link shared for downstream tracking but no CVEs cited.

An oss-security post links a util-linux commit (286dd3ff41526b582ef48830de239dffbaa61f90) as part of the 2.42.3 vulnerability fix release. No CVE identifiers, flaw descriptions, or exploitation details are provided. The item is a routine open-source fix notification for downstream distributors.

oss-security · 11d agoVulnerability1

Backdoor Xz Utils Linux Open Source

Infosecurity Magazine covers the XZ Utils open-source backdoor, a malicious implant in liblzma that targeted OpenSSH on major Linux distributions.

The article covers the XZ Utils backdoor, a malicious implant introduced into the widely used open-source compression library. The compromised liblzma code manipulated functions used by OpenSSH, nearly reaching stable releases of major Linux distributions before discovery. The incident is a prominent example of software supply chain compromise targeting critical open-source infrastructure.

Infosecurity Magazine · Aug 17, 2026VulnerabilityCVE-2024-3094

TestFlight Update

Apple released an update to TestFlight, its beta app testing platform, with release notes published on the developer portal.

Apple published a software release notice for TestFlight, the company's beta testing platform for iOS, iPadOS, and other Apple platforms. The release notes are available through Apple's developer releases page. No security content or vulnerability details are provided in the notice.

Apple software releases · 21d agoAdvisory

Package Manager Trends

Sixteen-week roundup finds package managers converging on release-age cooldowns, install-script blocking, malware scans, and recurring path-traversal and credential-leak fixes.

The author aggregates supply-chain security trends from sixteen weeks of This Week in Package Management, built from about 80 RSS feeds. Release-age cooldown gates shipped in Deno 2.8, Bundler, npm, Yarn, mise, Hex, Mamba, and Cargo, with Dependabot making a three-day cooldown default in August. npm 12 and Bun 1.4 now block lifecycle install scripts by default, and Composer 2.10 and uv added install/publish-time malware checks, while npm's registry began scanning at publish time. Path traversal on archive extraction was fixed in 14 of 16 weeks across tools including uv, pnpm, Docker, and Composer, and credential-misdirection bugs affected Cargo, ORAS, Composer, and Renovate.

Lobsters · security · 6d agoResearch1

pcre2 version 10.48 released with security fixes

PCRE2 10.48 released with security fixes; none have CVE IDs assigned yet, details limited to release notes.

The PCRE2 project released version 10.48 including security fixes, announced on the oss-security mailing list. As of publication, none of the fixes had CVE identifiers assigned, and specifics are only available via the project's release notes and security advisories page.

oss-security · 11d agoVulnerability

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle's August 2026 Critical Patch Update fixes 943 vulnerabilities; Oracle Fusion Middleware and Hyperion received the most patches at 262.

Oracle released its August 2026 Critical Patch Update, addressing 943 security vulnerabilities across multiple product families, including third-party components bundled in Oracle products. Oracle Fusion Middleware and Oracle Hyperion received the highest number of fixes with 262 patches. Several of the addressed vulnerabilities impact more than one product.

Qualys ThreatPROTECT · 27d agoAdvisory2

iPadOS 26.6.1 (23G83)

Apple released iPadOS 26.6.1 (build 23G83), a maintenance update applying security fixes to iPads on the iPadOS 26 line.

Apple listed iPadOS 26.6.1 (build 23G83) on August 17, 2026. The release entry contains only download links and release notes, with no CVE identifiers or exploitation details in the announcement. The matching build number with iOS 26.6.1 indicates shared core components updated in tandem across Apple platforms.

Apple software releases · 29d agoAdvisory