ZeroHour

Search: “product-release”

28 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

iOS 26.6.2 (23G90)

Apple released iOS 26.6.2 (build 23G90), a minor software update listed on its developer releases page without vulnerability details.

Apple released iOS 26.6.2, build 23G90, listed on its developer software releases page dated September 8, 2026. The available page content only provides download links, with no published vulnerability details, CVEs, or change notes in the source text.

Apple software releases · 8d agoAdvisory 2 sources

iOS 27.0 RC (24A435)

Apple seeded iOS 27.0 release candidate build 24A435 to developers ahead of the general release.

Apple released the iOS 27.0 release candidate (build 24A435) through its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releases · 7d agoAdvisory 2 sources

TestFlight Update

Apple released an update to TestFlight, its beta app testing platform, with release notes published on the developer portal.

Apple published a software release notice for TestFlight, the company's beta testing platform for iOS, iPadOS, and other Apple platforms. The release notes are available through Apple's developer releases page. No security content or vulnerability details are provided in the notice.

Apple software releases · 22d agoAdvisory

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors

Canonical ships Ubuntu 24.04.5 LTS point release bundling security fixes into fresh install media for desktop, server and nine other flavors.

Canonical released Ubuntu 24.04.5 LTS, a point release for the Noble Numbat series that folds accumulated security corrections and high-severity bug fixes into new installation media. Nine flavors including Kubuntu, Xubuntu, Ubuntu MATE, Ubuntu Studio and Edubuntu also moved to 24.04.5. Existing 22.04 LTS users receive the fixes through the automatic upgrade path at no cost. The release notes name no CVEs or bug IDs, and support timelines still count from the original 24.04 launch date (five years for Desktop/Server/Cloud/Core, three for flavors, extendable with Expanded Security Maintenance).

Help Net Securityupdated · 6h agofirst · 5d agoAdvisory 13 sources

iPadOS 26.7 (23H24)

Apple released iPadOS 26.7 (build 23H24) on September 9, 2026; the notice lists downloads without describing security fixes.

Apple shipped iPadOS 26.7, build 23H24, made available through its developer downloads page on September 9, 2026. The release announcement provides no description of changes, vulnerabilities, or CVEs. Apple point releases frequently bundle security patches, but none are confirmed in the available text.

Apple software releases · 7d agoAdvisory

New infosec products of the month: August 2026

August 2026 roundup of security product releases from ServiceNow, Tanium, Snyk, F5, A10, Searchlight Cyber, Intezer, NETSCOUT, Tufin, and Abnormal AI.

Help Net Security's monthly product roundup covers roughly a dozen vendors. Highlights include Snyk's general availability of Evo Continuous Offensive Security with AI-powered pentesting and AI agent red teaming, Searchlight Cyber's PTEM platform combining exposure visibility with attacker intelligence, and A10 and F5 AI gateways to govern enterprise LLM and agent usage. Other updates include Abnormal AI email DLP and phishing training, NETSCOUT outbound DDoS mitigation for service providers, Intezer's native Workflows automation, and Tufin's AI-powered Segmentation Intelligence.

Help Net Security · 19d agoTools

Package Manager Trends

Sixteen-week roundup finds package managers converging on release-age cooldowns, install-script blocking, malware scans, and recurring path-traversal and credential-leak fixes.

The author aggregates supply-chain security trends from sixteen weeks of This Week in Package Management, built from about 80 RSS feeds. Release-age cooldown gates shipped in Deno 2.8, Bundler, npm, Yarn, mise, Hex, Mamba, and Cargo, with Dependabot making a three-day cooldown default in August. npm 12 and Bun 1.4 now block lifecycle install scripts by default, and Composer 2.10 and uv added install/publish-time malware checks, while npm's registry began scanning at publish time. Path traversal on archive extraction was fixed in 14 of 16 weeks across tools including uv, pnpm, Docker, and Composer, and credential-misdirection bugs affected Cargo, ORAS, Composer, and Renovate.

Lobsters · security · 6d agoResearch1

Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates

ANY.RUN August release adds TI Lookup connections view, 81 behavior signatures, 16 YARA rules, 559 Suricata rules, and three new threat intelligence reports.

ANY.RUN released August product updates expanding its Threat Intelligence Lookup with a Connections block for pivoting between related observables (domains, IPs, URLs), JSON export for retrohunting and SIEM/NDR integration, and hidden whitelisted data by default. Detection coverage grew with 81 new behavior signatures, 16 YARA rules, and 559 Suricata rules covering malware execution, phishing, and C2 traffic. Three new Threat Intelligence Reports cover a US-focused RMM phishing campaign across 46 countries, the Mirage2FA phishing-as-a-service targeting Microsoft 365 (1,249 sandbox sessions, 9,332 potential compromise events), and a threat brief on OVERLORD RAT, CRPX0, and TRIBACK loader.

ANY.RUN · 13d agoTools1

macOS 27.0 RC (26A428)

Apple seeded the macOS 27.0 Release Candidate (build 26A428) to developers ahead of the final public release.

Apple published a Release Candidate build of macOS 27.0, labeled 26A428, on its developer release page. The notice only provides download and release-notes links and includes no security content, CVEs, or threat information. RC builds typically precede the general availability of the final operating system version.

Apple software releases · 7d agoAdvisory

Chrome is now shipping updates every 2 weeks as AI changes the security landscape

Google switches Chrome to two-week release cycles starting with Chrome 153, shrinking the N-day patch gap as AI-driven threats accelerate.

Chrome officially moved from a four-week to a two-week release schedule with Tuesday's launch of Chrome 153 on desktop, iOS, and Android. Google ties the change to its evolving security strategy, saying faster releases shrink the N-day patch gap as AI tools and community bug reports increase patch volume. Mozilla, Microsoft, and Brave have already adopted the two-week cadence, and Google is also racing AI-native browsers like Brave, Dia, Opera Neon, and Perplexity's Comet while experimenting with AI features in Chrome.

TechCrunch · Security · 8d agoIndustry

iOS 26.6.1 (23G83)

Apple released iOS 26.6.1 (build 23G83), a point update with security fixes for iPhones running iOS 26.

Apple published iOS 26.6.1 (build 23G83) on August 17, 2026 through its software releases page. The feed entry provides downloads and release notes only, without enumerating fixed CVEs or noting any active exploitation. Such rapid point releases typically address security vulnerabilities and stability regressions in iOS 26.

Apple software releases · Aug 17, 2026Advisory

ChiPass Release 2026.09.0

Open-source project ChiPass tagged release 2026.09.0 on Codeberg, though the announcement includes no described changes, features, or fixes.

The ChiPass project published version 2026.09.0 as a tagged release on Codeberg, shared via the Lobsters community. The available announcement text contains no changelog, feature list, or vulnerability fixes, so the scope of changes in this release is unclear.

Lobsters · security · 5d agoTools

iOS 18.7.10 (22H374)

Apple released iOS 18.7.10 (build 22H374), a maintenance update delivering security fixes for iPhones on the iOS 18 line.

Apple published the iOS 18.7.10 release (build 22H374) on August 17, 2026 via its software releases feed. The listing provides download links and release notes but includes no CVE details in the announcement text. Point releases on the legacy iOS 18 branch typically carry security and stability patches for devices not yet on iOS 26.

Apple software releases · Aug 17, 2026Advisory

Oracle Corporation security advisory (AV26-929)

CCCS relays Oracle's September 2026 Critical Patch Update fixing vulnerabilities across WebLogic, Database, E-Business Suite, PeopleSoft, Siebel, and dozens more products.

The Canadian Centre for Cyber Security (AV26-929) relays Oracle's September 2026 Critical Security Patch Update, which addresses vulnerabilities in dozens of product families as of September 15, 2026. Affected products include Oracle WebLogic Server, Database Server, E-Business Suite, Fusion Middleware, PeopleSoft Enterprise, Siebel Applications, GraalVM, VirtualBox, Coherence, and numerous banking and communications suites. The bulletin lists no CVE identifiers and encourages administrators to review Oracle's advisory and apply patches.

Closing the Blind Spot: Securing Personal Repositories in the Software Supply Chain

Wiz highlights personal developer repositories as a supply chain blind spot leaking corporate secrets, offering correlation-based risk validation and remediation.

Wiz argues that developers' personal code repositories are a blind spot in software supply chain security where corporate secrets quietly escape. The company describes an approach that correlates personal repositories to specific developers, validates the actual risk, and drives remediation. No specific incident or vulnerability is disclosed in the announcement.

Wiz Blog · Aug 13, 2026Tools2

iOS 27.0 RC (24A437)

Apple issues iOS 27.0 release candidate (build 24A437); notification lists no security fixes or CVEs.

Apple published the iOS 27.0 Release Candidate, build 24A437, on its developer release feed. The notice provides only download and release-notes links without vulnerability or CVE details. Security teams should monitor the accompanying release notes for security fixes ahead of general availability.

Apple software releasesupdated · 2d agofirst · 5d agoAdvisory 3 sources

17 draft Cyber Resilience Act standards are open for comment

ETSI publishes 17 draft harmonised standards detailing EU Cyber Resilience Act compliance, open for comment until between mid-September and mid-November 2026.

Seventeen draft standards covering the higher-risk tier of products with digital elements, including password managers, antivirus software, connected toys and wearables, are open for comment. Following a Harmonised Standard grants manufacturers the presumption of conformity with the Cyber Resilience Act, whose obligations apply through the end of 2027 to importers, distributors, service providers and developers. The drafts went to 41 member organisations plus societal partners ANEC, ECOS, ETUC and SBS, with closing dates varying by vertical.

Help Net Security · Aug 14, 2026Policy & legal

LandingAI Releases Agentic Document Extraction Gen2 with DPT-3 Pro and DPT-3 Verity

LandingAI shipped Agentic Document Extraction Gen2 with DPT-3 Pro and DPT-3 Verity parsing models, adding usage-based billing, block-tree outputs, and word-level grounding.

LandingAI has generally released Agentic Document Extraction Gen2, rebuilt around two parsing models: DPT-3 Verity for deterministic transcription of digital documents with per-word bounding boxes and confidence scores, and DPT-3 Pro for layout-aware parsing of scans, handwriting, non-Latin scripts, and LaTeX math. Billing changes from a flat 3 credits per page to a page-plus-output-character model (Pro: 1 credit/page plus 0.5 credits per 1,000 output characters on priority; Verity: 0.3 plus 0.2), with an asynchronous standard tier at 0.5x price and vendor-claimed 25-80% cost reductions. Parse v2 returns a document-page-block tree with semantic IDs, normalized bounding boxes, and line- or word-level atomic grounding, replacing flat chunks; Gen1 client code will not run against Gen2 endpoints. Deployment options include US/EU cloud, VPCs on AWS, Azure, and Google Cloud, Snowflake, and air-gapped on-premises environments, with automated model routing planned for fall 2026.

MarkTechPost · 6d agoAI tools & infra

New infosec products of the week: September 4, 2026

Weekly roundup covers F5's AI-powered WAF enhancements, Ping Identity's personal AI agent access, Superna 2.15 cyberstorage, and BugBase Pentest Copilot Enterprise.

This week's product roundup features releases from BugBase, F5 Networks, Ping Identity, and Superna. F5's WAF for Distributed Cloud adds anomaly detection and agentic threat intelligence for real-time virtual patching, Ping Identity launched Enterprise Personal Agent Access for securing personal AI agents, Superna 2.15 adds guided event-closing workflows for cyberstorage operations, and BugBase's Pentest Copilot Enterprise automates black-box pentesting across 100 vulnerability types using real Chromium browsers.

Help Net Security · 12d agoTools

Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)

Trojanized 3CXDesktopApp installers for Windows and macOS loaded RC4-encrypted shellcode delivering a backdoor to hundreds of thousands of 3CX users.

Threat actors compromised the 3CXDesktopApp build process, adding malicious libraries (ffmpeg.dll, d3dcompiler_47.dll) to installers downloaded from the developer's website. The Windows MSI loader decrypts embedded shellcode with RC4, sleeps for a random 1-4 weeks, then beacons to C2 hidden in icon files on GitHub. Unit 42 fingerprinted 247,277 IPs across 199 countries using 3CX applications and blocked shellcode execution at 127 Cortex XDR customers between March 9-30, 2023.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild1

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

Cisco will publish security advisories with fixed software on September 16, 2026, covering BroadWorks, ISE, Nexus Dashboard, ASA, FMC, FTD and ThousandEyes.

Cisco PSIRT announced advance notification for security advisories to be published on September 16, 2026, along with fixed software releases. Affected products include BroadWorks CommPilot Application Software, Identity Services Engine (ISE), Nexus Dashboard, Secure Firewall ASA, Secure Firewall Management Center (FMC), Secure Firewall Threat Defense (FTD), and ThousandEyes Virtual Appliance. ISE, Nexus Dashboard and the Secure Firewall products receive security hardening releases, and the ASA, FMC and FTD advisories will be included in the same combined release.

Cisco Security Advisories · 7d agoAdvisory

tvOS 27.0 RC (24J360)

Apple seeded tvOS 27.0 release candidate build 24J360 to developers ahead of the general release.

Apple released the tvOS 27.0 release candidate (build 24J360) through its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releases · 7d agoAdvisory

pcre2 version 10.48 released with security fixes

PCRE2 10.48 released with security fixes; none have CVE IDs assigned yet, details limited to release notes.

The PCRE2 project released version 10.48 including security fixes, announced on the oss-security mailing list. As of publication, none of the fixes had CVE identifiers assigned, and specifics are only available via the project's release notes and security advisories page.

oss-security · 11d agoVulnerability

Fwd: Tor Project Forum: Security Release 0.4.9.12

Tor released 0.4.9.12 with several high-severity fixes, some found via LLMs, plus recommended protocol updates and removal of TAP key acceptance.

The Tor Project shipped version 0.4.9.12, a security release containing several high-severity fixes, some reportedly discovered with the help of LLMs. The release recommends new protocol versions (41316) for both clients and relays. Directory authorities will no longer accept relay descriptors containing TAP keys.

oss-security · 7d agoVulnerability

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Unit 42 warns attackers increasingly target CI/CD pipelines and developer tools rather than application code, urging full SDLC supply chain visibility.

Palo Alto Networks Unit 42 research argues attackers are shifting focus from application code to overlooked corners of the software development lifecycle supply chain, including CI/CD pipelines and developer tooling. The write-up calls for total SDLC visibility and strict security controls to defend these developer-facing attack surfaces.

Palo Alto Unit 42 · 25d agoResearch in the wild

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle's August 2026 Critical Patch Update fixes 943 vulnerabilities; Oracle Fusion Middleware and Hyperion received the most patches at 262.

Oracle released its August 2026 Critical Patch Update, addressing 943 security vulnerabilities across multiple product families, including third-party components bundled in Oracle products. Oracle Fusion Middleware and Oracle Hyperion received the highest number of fixes with 262 patches. Several of the addressed vulnerabilities impact more than one product.

Qualys ThreatPROTECT · 28d agoAdvisory2

tvOS 27.2 beta (24K5088l)

Apple seeded tvOS 27.2 beta build 24K5088l to developers with no security details disclosed in the release listing.

Apple released tvOS 27.2 beta (build 24K5088l) to developers on September 16, 2026, per its software release listing. The listing contains only download links and a pointer to release notes, with no security content or vulnerability details. It is a routine developer beta with no reported exploitable issues.

Apple software releases · 4h agoAdvisory