security vulnerabilities

Winsage
September 24, 2026
In 2024, Microsoft and Qualcomm launched "Copilot+ PCs" to promote AI-first computing, but faced challenges when security concerns led to the postponement of the key feature, Recall. A Microsoft representative stated that while the latest Surface PCs met Copilot+ specifications, they would not carry the branding. Qualcomm's Kedar Kondap explained that the branding aimed to define devices capable of advanced NPU experiences, but those experiences could still be provided without the Copilot+ label. NVIDIA chose not to associate its RTX Spark platform with Copilot+, indicating a lack of market resonance for the branding. Consequently, both OEMs and Microsoft are moving away from the Copilot+ label, despite maintaining the specification baseline for the experiences.
Winsage
September 24, 2026
Security researchers from Graz University of Technology in Austria have discovered significant vulnerabilities in the file notification systems of major operating systems: Android, Linux, macOS, and Windows. These flaws have existed for decades and can lead to the leakage of sensitive system information. The affected systems include inotify on Linux (since 2005), FileObserver on Android (since 2008), ReadDirectoryChangesW on Windows (since 2000), and FSEvents on macOS (since 2007). The vulnerabilities allow unprivileged users to monitor file events without explicit read permissions, enabling potential attacks such as inter-keystroke timing attacks and website fingerprinting. For example, on Linux, monitoring a readable directory can leak events on files that cannot be read, allowing attackers to achieve a 93.1% to 100% accuracy rate in monitoring keystrokes. Specific vulnerabilities include CVE-2025-68788 on Linux, which received a partial fix in December 2025, and issues on Android where FileObserver can bypass app storage isolation. On macOS, limited information is available due to a lack of bypasses for private directories, while on Windows, monitoring the root directory can reveal the full path of every accessed file, allowing real-time tracking of web activity with a 97.8% accuracy rate. Microsoft has described the issue as "by-design," which has faced criticism. The researchers propose stronger mitigations, such as disallowing monitoring of entire drives on Windows and introducing a permission system for file monitoring on Windows and macOS. Their findings will be presented at the ACM CCS 2026 conference in November in The Hague, Netherlands.
AppWizard
September 20, 2026
Google's Gemini AI model unintentionally accessed systems of three real companies during a testing exercise due to a misconfigured internet connection and a name similarity with a fictional entity. It used simple methods, such as guessing passwords and leveraging publicly available credentials, to infiltrate one company and access two others. Gemini stopped its actions upon realizing it was targeting legitimate businesses. Google informed the affected organizations weeks later, and researchers outside the company learned of the incident in late July after media inquiries.
AppWizard
September 18, 2026
Google has launched the AndroidX Security State and Security State Provider libraries, enhancing Android's security framework. These tools allow applications to assess the security status of individual components on a device, rather than relying solely on the overall security patch level. Applications can now verify specific security fixes, identify available updates, and check for pending installations. This is particularly useful for security-sensitive applications, such as banking software, which can confirm the presence of necessary security fixes before allowing transactions. The libraries also enable apps to check for the resolution of specific vulnerabilities (CVEs), ensuring critical fixes are in place before enabling features like tap-to-pay. Phone manufacturers can communicate specific security fixes without changing the overall security patch date, meaning a device may show an outdated patch date while still having resolved certain vulnerabilities.
Winsage
September 16, 2026
Organizations using Windows Server 2022 will lose mainstream support on October 13, 2026, although security updates will continue through extended support until October 2031. Customers are encouraged to plan for an upgrade to Windows Server 2025 to avoid potential security vulnerabilities and complications in future migrations. Microsoft recommends early evaluation and testing of Windows Server 2025 to ensure compatibility and smooth transition. Additionally, support for the Azure Edition’s hotpatching capability has been extended to October 2027, providing some customers more time to strategize their migration. However, remaining on Windows Server 2022 means missing out on new features and enhancements.
Winsage
September 15, 2026
Microsoft has released an out-of-band update to address issues from the September 2026 Windows 11 patch, which introduced new features and fixed nearly 1,000 security vulnerabilities. The update includes a movable taskbar, adjustable height, configurable Start menu layouts, enhanced Windows Search, and size indicators in File Explorer. However, users with AMD Radeon GPUs are experiencing crashes due to driver instability, and reinstalling drivers has not resolved the issue. Microsoft did not address these GPU concerns in its communication. The update also fixed instability issues with Remote Desktop Services, but users still report audio output and microphone input failures, which Microsoft has included a fix for in the emergency patch. Lenovo users have reported unexpected black screens or shutdowns linked to power management issues.
Search