fix

Winsage
September 10, 2026
Microsoft acknowledged an issue with the KB5120998 August 2026 preview update for Windows 11, where mouse settings related to cursor personalization were altered or reset. This problem affected non-English Windows installations, causing personalized settings to fail to load and revert to standard configurations. The issue was resolved in the subsequent KB5124008 September 2026 cumulative update, which users were encouraged to install. KB5120998 was an optional update, potentially limiting the number of affected users. Additionally, Microsoft has been addressing various mouse-related issues in recent months, including problems with the Windows Recovery Environment and disappearing mouse pointers in Outlook.
Winsage
September 10, 2026
Microsoft announced that the September 2026 Patch Tuesday updates resolved an issue affecting desktop settings on certain Windows devices, which caused desktop wallpapers to revert to a solid black background after the installation of the KB5120998 August 2026 preview update. This bug impacted Windows 11 24H2 and 25H2 systems, preventing the correct loading of desktop settings and also affecting mouse settings. Microsoft recommended users update their devices to the latest security update released on September 8, 2026 (KB5124008) to benefit from the fix.
Winsage
September 9, 2026
Recent investigations have identified the BlueMoon exploit kit, used by espionage-driven threat activity clusters, particularly linked to APT31, a China-aligned state-sponsored group, since August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046 (a type confusion vulnerability in Google Chrome's V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC). Google and Microsoft have released patches for these vulnerabilities, which were exploited as "patch-gap" zero-days. The attack vectors typically begin with phishing emails that lead victims to malicious URLs, triggering the vulnerabilities for code execution and privilege escalation. Variants of BlueMoon have been detected, featuring modifications for specific campaigns. Notable attack chains include: - APT31 targeting NGOs and mining firms in the U.S. with a malicious browser add-on called GemStone. - UNK_LateNight targeting U.S. aerospace companies, deploying BlueMoon alongside the ShadowPad backdoor. - UNK_DoubleCheck targeting a Vietnamese manufacturer, using DLL sideloading to execute a Rust binary. - UNK_QuietRacket targeting government and financial organizations in Indonesia and Singapore, modifying BlueMoon to execute a .NET assembly. CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026, requiring federal agencies to apply patches by September 18, 2026. Indicators of compromise include specific process trees, files, folders, scheduled tasks, mutexes, and registry keys. Proofpoint has released detection rules to help organizations identify and mitigate these threats.
Winsage
September 9, 2026
On September 8, 2026, Microsoft disclosed a security vulnerability identified as CVE-2026-69449, related to a heap-based buffer overflow in the Windows BitLocker component, allowing authorized attackers to execute code on compromised machines. The vulnerability is classified as CWE-122, and is assessed as “Exploitation Less Likely.” It affects Windows 10, Windows 11, and Windows Server versions from 2012 to 2025. The fixes are included in cumulative updates KB5124008, KB5124012, KB5122878, and KB5122871. No public disclosure or observed exploitation occurred before the patch's release. The flaw allows for remote code execution through in-network attacks, primarily posing a risk to insiders. Affected systems include various versions of Windows 10, Windows 11, and Windows Server, applicable to both x64 and ARM64 architectures. Administrators should verify installed build numbers to ensure updates have been applied. The advisory does not specify which BitLocker code path is affected or the nature of the input that reaches the vulnerable buffer.
AppWizard
September 8, 2026
A navigation bug in Waze affects Android Auto users when switching to full-screen mode, causing essential journey information such as estimated time of arrival, arrival time, next navigation instruction, and remaining distance to disappear. The information temporarily reappears with alerts but vanishes again after the alert is dismissed. The cause of the glitch is uncertain, possibly related to a recent update to Android Auto or Waze.
AppWizard
September 8, 2026
Google's Android division acknowledged a messaging glitch on September 2, 2026, affecting both RCS and SMS messaging, which is linked to the data transfer process during the setup of new Android devices. This issue has raised privacy concerns as sensitive information may be shared with unintended recipients. Google released updates to its Messages app on September 3 and 4 in response to the problem, but a comprehensive solution for all users has not yet been implemented.
Tech Optimizer
September 8, 2026
Microsoft has acknowledged a software bug causing persistent Windows Security pop-ups that incorrectly indicate antivirus protection is disabled. These notifications began appearing after the latest Microsoft Defender Antivirus updates, but the antivirus is functioning correctly. The issue affects various versions of Windows and Windows Server with the latest Defender updates. Microsoft has committed to resolving the issue in a future update, though no timeline has been provided. Users are advised to verify the status of their antivirus through the Windows Security app and disregard the notifications until a fix is released.
AppWizard
September 8, 2026
A recent update to Android Auto, version 17.5, has caused a glitch in the Waze navigation app, preventing users from seeing essential trip information such as estimated time of arrival (ETA), distance to destination, and remaining travel time when Waze is displayed in full-screen mode. The information is visible when Waze is shown in the Coolwalk screen alongside other applications. Some users have noted that the journey information briefly reappears during Waze alerts but disappears after the alert is dismissed. There is currently no identified workaround, but users are considering reverting to a previous version of Android Auto or Waze to resolve the issue. Google has not officially acknowledged the glitch, but a Community Specialist has requested additional information from users to assist in diagnosing the problem. Meanwhile, Google Maps remains a reliable alternative for navigation.
Search