ZeroHour

Search: “release-notes”

25 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

App Store Connect Update

Apple issued an App Store Connect update with release notes published on its developer site.

Apple announced an update to App Store Connect, its developer tool for managing App Store submissions. No security fixes, CVEs, or notable changes were described in the announcement.

Apple software releases · 1d agoAdvisory 2 sources

iOS 27.0 (24A437)

Apple released iOS 27.0 (build 24A437) with no security fixes detailed in the announcement.

Apple published iOS 27.0 (24A437) on its developer news feed. The notice only links to downloads and release notes with no security content described. iOS major-version drops commonly bundle security fixes, so release notes should be reviewed.

Apple software releases · 1d agoAdvisory 3 sources2· 1 read

iOS 26.6.2 (23G90)

Apple released iOS 26.6.2 (build 23G90), a minor software update listed on its developer releases page without vulnerability details.

Apple released iOS 26.6.2, build 23G90, listed on its developer software releases page dated September 8, 2026. The available page content only provides download links, with no published vulnerability details, CVEs, or change notes in the source text.

Apple software releases · 7d agoAdvisory 2 sources

macOS 27.0 (26A428)

Apple released macOS 27.0 (build 26A428) with no security fixes detailed in the announcement.

Apple published macOS 27.0 (26A428) on its developer news feed. The notice only links to downloads and release notes without describing security updates. macOS major releases typically include security fixes detailed in separate notes.

Apple software releases · 1d agoAdvisory 2 sources

Xcode 27 RC (27A266a)

Apple released the Xcode 27 release candidate (build 27A266a) via its developer releases page.

Apple has published a release candidate of Xcode 27, build 27A266a, on its developer releases page. The listing contains no security notes, CVEs, or vulnerability details in the available text. This is a routine vendor software release ahead of the final Xcode 27 version.

Apple software releasesupdated · 1d agofirst · 6d agoAdvisory 2 sources

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors

Canonical ships Ubuntu 24.04.5 LTS point release bundling security fixes into fresh install media for desktop, server and nine other flavors.

Canonical released Ubuntu 24.04.5 LTS, a point release for the Noble Numbat series that folds accumulated security corrections and high-severity bug fixes into new installation media. Nine flavors including Kubuntu, Xubuntu, Ubuntu MATE, Ubuntu Studio and Edubuntu also moved to 24.04.5. Existing 22.04 LTS users receive the fixes through the automatic upgrade path at no cost. The release notes name no CVEs or bug IDs, and support timelines still count from the original 24.04 launch date (five years for Desktop/Server/Cloud/Core, three for flavors, extendable with Expanded Security Maintenance).

Help Net Securityupdated · 4d agofirst · 5d agoAdvisory 13 sources

TestFlight Update

Apple released an update to TestFlight, its beta app testing platform, with release notes published on the developer portal.

Apple published a software release notice for TestFlight, the company's beta testing platform for iOS, iPadOS, and other Apple platforms. The release notes are available through Apple's developer releases page. No security content or vulnerability details are provided in the notice.

Apple software releases · 21d agoAdvisory

Package Manager Trends

Sixteen-week roundup finds package managers converging on release-age cooldowns, install-script blocking, malware scans, and recurring path-traversal and credential-leak fixes.

The author aggregates supply-chain security trends from sixteen weeks of This Week in Package Management, built from about 80 RSS feeds. Release-age cooldown gates shipped in Deno 2.8, Bundler, npm, Yarn, mise, Hex, Mamba, and Cargo, with Dependabot making a three-day cooldown default in August. npm 12 and Bun 1.4 now block lifecycle install scripts by default, and Composer 2.10 and uv added install/publish-time malware checks, while npm's registry began scanning at publish time. Path traversal on archive extraction was fixed in 14 of 16 weeks across tools including uv, pnpm, Docker, and Composer, and credential-misdirection bugs affected Cargo, ORAS, Composer, and Renovate.

Lobsters · security · 5d agoResearch1

iOS 26.6.1 (23G83)

Apple released iOS 26.6.1 (build 23G83), a point update with security fixes for iPhones running iOS 26.

Apple published iOS 26.6.1 (build 23G83) on August 17, 2026 through its software releases page. The feed entry provides downloads and release notes only, without enumerating fixed CVEs or noting any active exploitation. Such rapid point releases typically address security vulnerabilities and stability regressions in iOS 26.

Apple software releases · 29d agoAdvisory

The August 2026 Security Update Review

ZDI's August 2026 review covers a smaller-but-still-huge Microsoft and Adobe patch batch, with Adobe shipping 51 CVEs across five bulletins.

The Zero Day Initiative's August 2026 Security Update Review covers the latest Adobe and Microsoft patches. Adobe released five bulletins addressing 51 unique CVEs. The release is smaller than July's but still large by historical standards, which ZDI notes reflects a 'new normal' in patch density.

Zero Day Initiative Blog · Aug 11, 2026Vulnerability1

SAP September 2026 Security Update Fixes 4 Critical Vulnerabilities and 15 Other Flaws

SAP's September 2026 Patch Tuesday ships 19 security notes, including four criticals led by a CVSS 10.0 memory-corruption flaw in Extended Passport Processing.

SAP released 19 new Security Notes plus one update, fixing four critical vulnerabilities and 15 additional flaws. The most urgent is CVE-2026-44756 (CVSS 10.0), memory corruption in Extended Passport (EPP) Processing affecting many SAP Kernel and Web Dispatcher releases. Other criticals include CVE-2026-58240 (NetWeaver Message Server missing authentication, 9.8), CVE-2026-76969 (credential disclosure in CAP sap/cds-mtxs, 9.4), and CVE-2026-66768 (improper access control in SAP GUI for Java, 9.0). High-severity fixes cover XXE in Integration Suite Trading Partner Management, deserialization in NetWeaver Business Client, and memory corruption in NetWeaver AS for ABAP.

Release Notes: Faster TI Investigations, Fresh Threat Research, and 650+ Threat Coverage Updates

ANY.RUN August release adds TI Lookup connections view, 81 behavior signatures, 16 YARA rules, 559 Suricata rules, and three new threat intelligence reports.

ANY.RUN released August product updates expanding its Threat Intelligence Lookup with a Connections block for pivoting between related observables (domains, IPs, URLs), JSON export for retrohunting and SIEM/NDR integration, and hidden whitelisted data by default. Detection coverage grew with 81 new behavior signatures, 16 YARA rules, and 559 Suricata rules covering malware execution, phishing, and C2 traffic. Three new Threat Intelligence Reports cover a US-focused RMM phishing campaign across 46 countries, the Mirage2FA phishing-as-a-service targeting Microsoft 365 (1,249 sandbox sessions, 9,332 potential compromise events), and a threat brief on OVERLORD RAT, CRPX0, and TRIBACK loader.

ANY.RUN · 12d agoTools1

macOS 26.6.2 (25G83)

Apple released macOS 26.6.2 (build 25G83), a point update delivering security patches for Macs on the macOS 26 line.

Apple published macOS 26.6.2 (build 25G83) on August 17, 2026 via its software releases feed. The listing offers downloads and release notes only, without disclosing CVE identifiers or exploitation status. Security-focused point updates for macOS are relevant to enterprise Mac fleets and should be tested and deployed routinely.

Apple software releases · 29d agoAdvisory

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

Cisco will publish security advisories with fixed software on September 16, 2026, covering BroadWorks, ISE, Nexus Dashboard, ASA, FMC, FTD and ThousandEyes.

Cisco PSIRT announced advance notification for security advisories to be published on September 16, 2026, along with fixed software releases. Affected products include BroadWorks CommPilot Application Software, Identity Services Engine (ISE), Nexus Dashboard, Secure Firewall ASA, Secure Firewall Management Center (FMC), Secure Firewall Threat Defense (FTD), and ThousandEyes Virtual Appliance. ISE, Nexus Dashboard and the Secure Firewall products receive security hardening releases, and the ASA, FMC and FTD advisories will be included in the same combined release.

Cisco Security Advisories · 6d agoAdvisory

iOS 27.0 RC (24A435)

Apple seeded iOS 27.0 release candidate build 24A435 to developers ahead of the general release.

Apple released the iOS 27.0 release candidate (build 24A435) through its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releases · 6d agoAdvisory 2 sources

iOS 18.7.10 (22H374)

Apple released iOS 18.7.10 (build 22H374), a maintenance update delivering security fixes for iPhones on the iOS 18 line.

Apple published the iOS 18.7.10 release (build 22H374) on August 17, 2026 via its software releases feed. The listing provides download links and release notes but includes no CVE details in the announcement text. Point releases on the legacy iOS 18 branch typically carry security and stability patches for devices not yet on iOS 26.

Apple software releases · 29d agoAdvisory

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Malicious LiteLLM 1.82.7/1.82.8 PyPI releases tied to the Trivy TeamPCP campaign harvested cloud, SSH, and database credentials, potentially exposing 2,500+ organizations.

CloudSEK reported that two malicious LiteLLM releases on PyPI (versions 1.82.7 and 1.82.8, live about 40 minutes on March 24) harvested cloud keys, SSH keys, Kubernetes tokens, and database passwords, with captured loot files mapping potential exposure to more than 2,500 organizations including NVIDIA, Cisco, Deloitte, Volkswagen, FedEx, Siemens, and X Corp. The campaign is part of TeamPCP (tracked by Google as UNC6780), linked to the Aqua Security Trivy scanner compromise tracked as CVE-2026-33634 and added to CISA's Known Exploited Vulnerabilities catalog on March 26. The payload used a litellm_init.pth file executed at Python interpreter startup and exfiltrated secrets to models.litellm[.]cloud; the FBI's FLASH-20260702-01 advisory urged rotation of CI/CD, publishing, and cloud credentials.

The Hacker News · Aug 12, 2026Data breach in the wildCVE-2026-33634

iPadOS 26.7 (23H24)

Apple released iPadOS 26.7 (build 23H24) on September 9, 2026; the notice lists downloads without describing security fixes.

Apple shipped iPadOS 26.7, build 23H24, made available through its developer downloads page on September 9, 2026. The release announcement provides no description of changes, vulnerabilities, or CVEs. Apple point releases frequently bundle security patches, but none are confirmed in the available text.

Apple software releases · 6d agoAdvisory

pcre2 version 10.48 released with security fixes

PCRE2 10.48 released with security fixes; none have CVE IDs assigned yet, details limited to release notes.

The PCRE2 project released version 10.48 including security fixes, announced on the oss-security mailing list. As of publication, none of the fixes had CVE identifiers assigned, and specifics are only available via the project's release notes and security advisories page.

oss-security · 11d agoVulnerability

Re: Vulnerability fixes in util-linux-2.42.3

util-linux 2.42.3 includes vulnerability fixes, with a commit link shared for downstream tracking but no CVEs cited.

An oss-security post links a util-linux commit (286dd3ff41526b582ef48830de239dffbaa61f90) as part of the 2.42.3 vulnerability fix release. No CVE identifiers, flaw descriptions, or exploitation details are provided. The item is a routine open-source fix notification for downstream distributors.

oss-security · 10d agoVulnerability1

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

Microsoft's September 2026 Patch Tuesday delivers a record patch count, fixing two exploited zero-days and a wormable DNS flaw dubbed a SigRed successor.

Microsoft's September 2026 Patch Tuesday sets another record patch count, fixing two vulnerabilities exploited as zero-days: CVE-2026-81963, a Windows Update Stack low-privilege-to-SYSTEM escalation reported by MSTIC, and CVE-2026-85880, a Windows Advanced Local Procedure Call escalation reported by Proofpoint. Zero Day Initiative's Dustin Childs urges priority on a cluster of 20 potentially wormable bugs including DNS RCE CVE-2026-69730, described as a spiritual successor to SigRed, plus Kerberos authentication bypass CVE-2026-69676 that could give any authenticated domain user RCE on domain controllers, and Exchange RCE CVE-2026-55007 via a malicious Visio attachment. All Windows fixes are bundled in cumulative updates, and experts stress prioritizing exploitable, reachable flaws over raw patch counts.

Help Net Security · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69730+4 CVEs

Fwd: Tor Project Forum: Security Release 0.4.9.12

Tor released 0.4.9.12 with several high-severity fixes, some found via LLMs, plus recommended protocol updates and removal of TAP key acceptance.

The Tor Project shipped version 0.4.9.12, a security release containing several high-severity fixes, some reportedly discovered with the help of LLMs. The release recommends new protocol versions (41316) for both clients and relays. Directory authorities will no longer accept relay descriptors containing TAP keys.

oss-security · 7d agoVulnerability

Patch Tuesday - August 2026

Rapid7 counts 421 vulnerabilities in Microsoft's August 2026 Patch Tuesday, with one exploited in the wild and two others publicly disclosed.

Rapid7 counts 421 vulnerabilities published in Microsoft's August 2026 Patch Tuesday, including 236 in Windows — below last month's record but still among the largest totals ever. Microsoft is aware of exploitation in the wild for one published vulnerability and public disclosure of two others, though the Security Update Guide's Notable CVEs section omits one of these. Browser vulnerabilities are excluded from the published count, and Microsoft unusually does not appear to have addressed some expected items.

Rapid7 Blog · Aug 11, 2026Vulnerability in the wild

WordPress 7.0.4 Release

WordPress releases 7.0.4 with a security fix and urges all sites to update immediately.

WordPress.org announced the availability of WordPress 7.0.4, a maintenance release containing a security fix. Because it is a security release, the project recommends updating sites immediately via the dashboard or a download from WordPress.org. The announcement gives no technical details about the flaw being patched.

WordPress.org · Security · Aug 12, 2026Advisory

Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps

Wiz published a DFIR cheatsheet covering log visibility, incident readiness, and threat hunting across GitHub, GitLab, Bitbucket, and Azure DevOps.

Wiz researchers released a practitioner's guide to version control system forensics, incident response, and threat hunting. The cheatsheet maps log sources, audit capabilities, and hunting workflows across GitHub, GitLab, Bitbucket, and Azure DevOps. It aims to improve incident readiness for source code and CI/CD compromise scenarios.

Wiz Blog · 19d agoResearch1