customers

Winsage
September 9, 2026
The September 2026 security cycle revealed a bifurcated approach to vulnerability management by Microsoft, focusing on cloud-side identity services with silent mitigations and traditional Patch Tuesday updates for on-premises Windows infrastructure. On September 3, Microsoft addressed nine cloud-side vulnerabilities, including two with a CVSS score of 10.0: CVE-2026-83711 (Azure AD B2C elevation of privilege) and CVE-2026-70352 (Azure AI Language Authoring missing authentication). Additionally, CVE-2026-83941 (Entra ID elevation of privilege, rated 9.9) and CVE-2026-80098 (Copilot Studio cryptographic flaw) were noted. On September 8, the Patch Tuesday update addressed 70 CVEs, including critical issues in the on-premises stack, such as CVE-2026-83939 (Windows Secure Kernel Mode elevation of privilege). CVE-2026-69414 (ShieldBreak), an elevation of privilege vulnerability in the Defender Malware Protection Engine, was patched out-of-band on September 3 after being publicly exposed for three weeks. Microsoft is shifting its Self-Service Password Reset (SSPR) enforcement to default to passkeys as of September 7, with plans to phase out SMS and voice-based authentication by February 2027. This aims to enhance security by moving away from legacy credentials.
Winsage
September 9, 2026
Microsoft's September 2026 security update revealed 973 vulnerabilities, with 113 classified as critical. Two actively exploited vulnerabilities are CVE-2026-81963 (Windows Update Stack, elevation of privilege, CVSS 7.8) and CVE-2026-85880 (Windows ALPC, elevation of privilege, CVSS 7.8). Among the 113 critical vulnerabilities, 82 are remote code execution (RCE) vulnerabilities. Notable vulnerabilities include: - CVE-2026-69676: RCE in Windows Kerberos, CVSS 8.8, authentication bypass. - CVE-2026-69852: RCE in Windows RRAS, CVSS 7.5, heap-based buffer overflow. - CVE-2026-72957: RCE in Windows Deployment Services, CVSS 7.8. - CVE-2026-69854: Elevation of privilege in Spring Cloud Azure, CVSS 9.0, improper authentication. - CVE-2026-83501: Information disclosure in Windows VBS, CVSS 5.5. - CVE-2026-69730: RCE in Windows DNS Server, CVSS 9.8. Less likely to be exploited vulnerabilities include: - CVE-2026-69845: RCE in Windows DHCP Server, CVSS 9.8, heap-based buffer overflow. - CVE-2026-65772: Vulnerability in Microsoft Dynamics 365 On-Premises, CVSS 8.8, deserialization of untrusted data. - CVE-2026-66302: RCE in Skype for Business, CVSS 9.8. Additional critical vulnerabilities include: - CVE-2026-62916: Elevation of privilege in Microsoft Entra ID, CVSS 9.1. - CVE-2026-83941: Elevation of privilege in Entra ID, CVSS 9.9. - CVE-2026-80098: Vulnerability in Copilot Studio, CVSS 9.3, improper verification of cryptographic signatures. Talos is releasing a new Snort ruleset to detect attempts to exploit these vulnerabilities, with specific SIDs for Snort 2 and Snort 3 rule coverage.
Tech Optimizer
September 7, 2026
Intego ONE Complete has launched the Intego ONE: VPN & Wi-Fi Security app for iPhone, available at no extra charge to Complete subscribers. The app provides VPN protection, Wi-Fi security assessments, and checks on built-in iPhone security settings but does not function as antivirus software. It enhances existing Apple security measures by addressing vulnerabilities related to insecure Wi-Fi connections and unprotected internet access. The app is accessible to both new and existing subscribers, and Intego is currently offering a 50% discount on subscriptions until September 30, 2026. Intego ONE is available in three tiers: Essential, Advanced, and Complete, with the Complete tier including the new iPhone app. The app features a VPN that encrypts internet connections on public Wi-Fi, Wi-Fi security checks, and assessments of iPhone security settings. While traditional viruses are rare on iPhones, threats like spyware and exploits still exist. The app does not replace Apple's malware protection but complements it. Intego ONE Complete is recommended for Mac and iPhone owners, particularly those who travel frequently or connect to public Wi-Fi. The pricing includes various deals, with a 50% discount currently available and a subsequent 35% discount after the promotional period.
AppWizard
September 5, 2026
Google has introduced Gemini, an advanced platform that enhances user interaction with devices by integrating with Google Assistant. Key features include enhanced contextual understanding for accurate responses, multi-modal interaction allowing voice, text, or visual inputs, and personalized recommendations based on user preferences. The platform aims to provide a cohesive experience across Google services, facilitating tasks like managing schedules and controlling smart home devices. For businesses, Gemini offers opportunities to improve customer service through instant support and personalized interactions, potentially increasing customer satisfaction and loyalty.
Winsage
September 4, 2026
Microsoft is addressing an issue (TM1466820) causing delays or preventing some users from accessing the Microsoft Teams desktop client on Windows systems, acknowledged on Thursday at 16:45 EDT. Affected users may experience loading failures or delays of up to two minutes and are advised to use the web or mobile versions of Teams as a temporary workaround. Microsoft is analyzing service logs and telemetry data to identify the root cause and has contacted some affected users for more information. Additionally, there is a separate issue (TM1466659) affecting Mac users, preventing them from joining Teams calls and meetings, confirmed on Sunday at 08:32 EDT. Microsoft is reassessing the cause of this disruption. Earlier this year, Microsoft resolved an issue blocking some Teams Free users from chats and calls. The company also confirmed a bug causing crashes and launch failures for Teams and New Outlook users after recent Windows security updates. Furthermore, there is an ongoing Exchange Online issue affecting multiple mailboxes, resulting in "Server busy" errors and delays in email communications with external domains.
Tech Optimizer
September 4, 2026
Organizations are increasingly aiming to establish their own governed AI and data platforms, with 95% of enterprises planning to develop such platforms within the next three years, though only 13% have done so. EDB has reported significant traction for its EDB Postgres® AI (EDB PG AI) platform, which unifies transactional, analytical, and agentic workloads into a single system. PAC 2000A Conad has revamped its data infrastructure using EDB PG AI to support over 1,600 stores and 7,000 connected devices, ensuring compliance with NIS2 regulations. C Platform in Korea is experiencing a surge in demand for hybrid and on-premises capabilities, driven by significant investment in sovereign AI and the AI Basic Act mandating governance for AI deployment. Notable adopters of EDB PG AI include the Industrial Bank of Korea, Shinhan EZ Insurance, NTT East, MNTN, Euronext FX, and Kyobo Book Centre.
Tech Optimizer
September 4, 2026
EnterpriseDB (EDB) has reported advancements in the adoption of its EDB Postgres AI (EDB PG AI) platform, which integrates transactional, analytical, and AI workloads. While 95% of enterprises aspire to become their own AI and data platforms within three years, only 13% have achieved this. EDB PG AI supports existing systems and prepares enterprises for future AI capabilities. A case study highlights PAC 2000A Conad, which restructured its data infrastructure with EDB PG AI, serving over 1,600 stores and 7,000 devices. In Korea, over billion has been invested in the sovereign AI market, with organizations seeking hybrid and on-premises solutions despite challenges from fragmented data environments. Notable users of EDB PG AI include the Industrial Bank of Korea and Shinhan EZ Insurance. EDB PG AI is built on Postgres and allows enterprises to optimize data and AI capabilities with governance at the data layer.
Search