data

Winsage
September 9, 2026
Microsoft's September Patch Tuesday update for Windows 11 introduces several enhancements, including the ability to reposition the taskbar to the top, left, or right sides of the screen. Users can adjust the taskbar's alignment, height, and icon size, though the auto-hide feature is limited to the bottom position. The Start menu now allows users to select between Small and Large sizes, with the Recommended section rebranded as Recent, and options to hide their name and profile picture. The Search window has been streamlined to focus on suggested or recent searches. The update addresses 995 security vulnerabilities, including 121 critical vulnerabilities and two zero-day flaws (CVE-2026-81963 and CVE-2026-85880), which could allow attackers to gain system-level privileges.
Winsage
September 9, 2026
On September 8, 2026, Microsoft disclosed a security vulnerability identified as CVE-2026-69449, related to a heap-based buffer overflow in the Windows BitLocker component, allowing authorized attackers to execute code on compromised machines. The vulnerability is classified as CWE-122, and is assessed as “Exploitation Less Likely.” It affects Windows 10, Windows 11, and Windows Server versions from 2012 to 2025. The fixes are included in cumulative updates KB5124008, KB5124012, KB5122878, and KB5122871. No public disclosure or observed exploitation occurred before the patch's release. The flaw allows for remote code execution through in-network attacks, primarily posing a risk to insiders. Affected systems include various versions of Windows 10, Windows 11, and Windows Server, applicable to both x64 and ARM64 architectures. Administrators should verify installed build numbers to ensure updates have been applied. The advisory does not specify which BitLocker code path is affected or the nature of the input that reaches the vulnerable buffer.
AppWizard
September 9, 2026
Android Auto users are experiencing issues with Google Maps, particularly the disappearance of the speedometer feature after its recent integration. Some users report that the speedometer vanishes when navigation is disabled, while others find it completely absent. Additionally, critical navigation data, such as traffic light indicators, may also be missing. A persistent bug affecting traffic colors in Google Maps further complicates navigation. Users have shared varying experiences, with some finding that exiting beta versions of the apps resolves the issue. Google has not yet addressed these concerns, and an upcoming update for Google Maps is expected to enhance navigation features, including detailed maps and improved turn-by-turn instructions. The update is currently rolling out in the U.S. and Canada, with no timeline for other regions.
Winsage
September 9, 2026
Windows 11 Pro is currently on sale for .97, down from its regular price of 9. It includes features such as BitLocker encryption, Hyper-V and Windows Sandbox for virtual machines, and Azure AD for business connectivity. Additional enhancements include Snap layouts, DirectX 12 Ultimate for gaming, TPM 2.0 for secure logins, and Copilot for assistance. The license is only compatible with PCs that meet Windows 11's minimum specifications, which can be checked using Microsoft's free PC Health Check app.
Winsage
September 9, 2026
Microsoft's September 2026 security update revealed 973 vulnerabilities, with 113 classified as critical. Two actively exploited vulnerabilities are CVE-2026-81963 (Windows Update Stack, elevation of privilege, CVSS 7.8) and CVE-2026-85880 (Windows ALPC, elevation of privilege, CVSS 7.8). Among the 113 critical vulnerabilities, 82 are remote code execution (RCE) vulnerabilities. Notable vulnerabilities include: - CVE-2026-69676: RCE in Windows Kerberos, CVSS 8.8, authentication bypass. - CVE-2026-69852: RCE in Windows RRAS, CVSS 7.5, heap-based buffer overflow. - CVE-2026-72957: RCE in Windows Deployment Services, CVSS 7.8. - CVE-2026-69854: Elevation of privilege in Spring Cloud Azure, CVSS 9.0, improper authentication. - CVE-2026-83501: Information disclosure in Windows VBS, CVSS 5.5. - CVE-2026-69730: RCE in Windows DNS Server, CVSS 9.8. Less likely to be exploited vulnerabilities include: - CVE-2026-69845: RCE in Windows DHCP Server, CVSS 9.8, heap-based buffer overflow. - CVE-2026-65772: Vulnerability in Microsoft Dynamics 365 On-Premises, CVSS 8.8, deserialization of untrusted data. - CVE-2026-66302: RCE in Skype for Business, CVSS 9.8. Additional critical vulnerabilities include: - CVE-2026-62916: Elevation of privilege in Microsoft Entra ID, CVSS 9.1. - CVE-2026-83941: Elevation of privilege in Entra ID, CVSS 9.9. - CVE-2026-80098: Vulnerability in Copilot Studio, CVSS 9.3, improper verification of cryptographic signatures. Talos is releasing a new Snort ruleset to detect attempts to exploit these vulnerabilities, with specific SIDs for Snort 2 and Snort 3 rule coverage.
AppWizard
September 8, 2026
GrapheneOS is an open-source Android-based operating system focused on security and user privacy, appealing to privacy-conscious users. It features an enhanced app sandbox, a privacy-first design for managing app permissions, and regular security updates. The operating system has gained attention on social media platforms like X and Mastodon, where users share tips and experiences, fostering a supportive community. This engagement allows for real-time feedback, collaborative problem-solving, and increased awareness of privacy and security topics.
AppWizard
September 8, 2026
Connecticut's attorney general is investigating Kik, a messaging app popular with teenagers, due to concerns about its age verification, privacy, and content moderation practices, labeling it a “predator’s paradise.” This inquiry is part of a larger effort by the state to examine online platforms that may inadequately protect children. Attorney General William Tong stated a commitment to using enforcement powers to hold Big Tech accountable for minors' safety. Recent actions include a settlement with Meta Platforms Inc. and an ongoing investigation into Roblox Corp. Kik's policies, particularly its lack of stringent age verification and content moderation, have raised alarms about risks to its teenage users. The investigation will assess Kik's management of user data, privacy safeguards, and content moderation practices.
Winsage
September 8, 2026
Microsoft released its September 2026 security updates, addressing two critical Windows elevation-of-privilege vulnerabilities: CVE-2026-85880 and CVE-2026-81963. Both vulnerabilities were exploited before their public disclosure on September 8. CVE-2026-85880 involves a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC), allowing low-privileged attackers to gain SYSTEM privileges. CVE-2026-81963 affects the Windows Update Stack due to improper link resolution and access controls, enabling similar privilege escalation. The September release also includes 974 Common Vulnerabilities and Exposures (CVEs) across various Microsoft products, with 723 affecting Windows. Users of Windows 11 24H2 and 25H2 receive updates via KB5124008, while Windows 11 26H1 receives KB5124012. Windows 11 24H2 Home or Pro editions will reach end of servicing on October 13, 2026. Users are advised to install the updates promptly and back up important data.
AppWizard
September 8, 2026
Ohio residents with Android devices can now integrate their driver's license or state ID into Google Wallet as part of the state's Mobile ID program. This digital credential is a companion to the physical card, and users are encouraged to carry their plastic IDs. To add the credential, users can navigate through the Google Wallet app. The digital ID is accepted for age and identity verification at various businesses, state buildings, TSA checkpoints, and casinos in Ohio. It utilizes specialized readers for presentation and allows users to review shared data. The credentials are encrypted and can be remotely erased if the phone is lost or stolen. Participation in the program is voluntary and free, adhering to privacy and security standards. Governor Mike DeWine highlighted the convenience of this innovation, and vendors are expanding support for mobile driver’s licenses in multiple states.
AppWizard
September 8, 2026
A navigation bug in Waze affects Android Auto users when switching to full-screen mode, causing essential journey information such as estimated time of arrival, arrival time, next navigation instruction, and remaining distance to disappear. The information temporarily reappears with alerts but vanishes again after the alert is dismissed. The cause of the glitch is uncertain, possibly related to a recent update to Android Auto or Waze.
Search