Users

Winsage
April 28, 2026
Microsoft is facing a significant security vulnerability in its Windows operating system known as PhantomRPC, which allows for privilege escalation. Cybersecurity experts have expressed concern over the company's delayed response in issuing a patch for this flaw. The vulnerability resides within the Windows Remote Procedure Call (RPC) architecture and enables processes with impersonation privileges to elevate their permissions to SYSTEM level. Researcher Haidar Kabibo identified five distinct paths for exploitation, which require user interaction, coercion, or compromise of background services. Despite disclosing the vulnerability to Microsoft in September 2025, the company categorized it as moderately severe and did not issue a patch or a Common Vulnerabilities and Exposures (CVE) listing. Microsoft stated that the technique requires an already-compromised machine and emphasized the importance of following security best practices. Experts have criticized Microsoft's lack of action, arguing that it is operationally negligent and places the burden of risk management on users. In the absence of a patch, security professionals recommend focusing on access control and environmental hygiene to mitigate the risks associated with the vulnerability.
AppWizard
April 28, 2026
Starting in the first week of May, Google will remove "phone actions and automations" from its Nest devices, which include features like checking battery levels, toggling Do Not Disturb settings, and adjusting phone volume. While these phone-related actions will be phased out, core home automations will remain functional. Google has introduced a new feature for its Gemini platform called "Continued Conversations," allowing users to engage in extended dialogues without repeating context. Additionally, some Nest Hub users are experiencing a glitch where alarms set for PM are announced as AM.
AppWizard
April 28, 2026
Google introduced Android 12L four years ago, tailored for larger screens on foldable phones and tablets. This led to optimizations in applications, with Google and Samsung enhancing their offerings, and third-party developers creating apps for these devices. The upcoming version 51.2 of Google Play Services will feature a badge identifying apps optimized for big-screen devices, helping users find suitable applications. This badge aims to increase visibility for these apps and encourage developer investment in the big-screen market. Additionally, Google plans to launch an Android-powered version of ChromeOS later this year, further promoting the use of big-screen devices.
Winsage
April 28, 2026
Microsoft has identified an issue affecting the display of security warnings when users open Remote Desktop (.rdp) files across all supported versions of Windows, including Windows 11, Windows 10, and Windows Server. The security warning may not render correctly, making the text difficult to read and buttons misaligned, especially when multiple monitors with different display scaling settings are used. This issue often results in overlapping text or obscured buttons in the warning window. The problem is part of Microsoft's security enhancements introduced with the April 2026 cumulative updates, which aim to mitigate risks associated with malicious RDP connection files. Users receive a one-time educational prompt upon opening an RDP file for the first time, followed by a security dialog that provides information about the file's publisher and resource redirections. RDP files are commonly used in enterprise environments, but their exploitation in phishing campaigns has raised security concerns, particularly by groups like the Russian state-sponsored APT29.
Tech Optimizer
April 28, 2026
Surfshark is offering a VPN service at a discounted price of .49 per month, down from the regular price, with an upfront cost for a two-year commitment being approximately .76, which includes three additional months free. The service supports unlimited devices, provides security for online activities, access to popular streaming services, and offers unlimited data and speeds with over 4,500 servers in 100 countries. It allows unlimited simultaneous connections and comes with a 30-day money-back guarantee. Additionally, Surfshark has introduced an antivirus option for .08 per month, which includes features like dark web monitoring and anonymous browsing. The antivirus plan costs .96 for the initial two-year period, also at an 88% discount. Surfshark maintains a no-logs policy and has been audited by third parties, making it a secure choice for users.
AppWizard
April 28, 2026
Logitech has introduced the G512 X gaming keyboard, which features the ability to switch between analog TMR switches and traditional mechanical switches. It has 39 swappable keyswitch locations, allowing for customization with various switch types. The keyboard supports analog input functions for enhanced gameplay, including dual-actuation points and tactile feedback. It is a wired keyboard with an 8kHz report rate and comes in two form factors: 75% (G512 X 75) and 98% (G512 X 98), with the latter including a numpad. The G512 X features a black and purple design, Lightsync RGB light bar, and backlit keys. It will launch on May 2, priced at 9.99 / £169.99 / €189.99 for the G512 X 75 and 9.99 / £199.99 / €219.99 for the G512 X 98.
Winsage
April 28, 2026
Microsoft is recalibrating its Copilot AI assistant, which enhances productivity across its applications. In Microsoft Word, Copilot assists with drafting, restructuring, and tone adjustment. Excel users receive help with formulas and data analysis, while PowerPoint users get support for presentations. Notepad has rebranded its Copilot features as "Writing Tools," allowing users to generate text, rewrite content, and adjust tone, but the Snipping Tool has removed all AI functionalities. Microsoft plans to introduce AI agents to the Windows taskbar for answering questions, automating tasks, and interacting with files, although this feature is still in testing.
Winsage
April 28, 2026
A new vulnerability in Microsoft Windows, designated as CVE-2026-32202, has been discovered due to an incomplete security patch for a previous flaw (CVE-2026-21510). This new vulnerability allows attackers to execute zero-click attacks by processing specially crafted shortcut files, enabling automatic authentication requests without user interaction. The vulnerabilities are linked to another flaw (CVE-2026-21513) in Microsoft’s MSHTML framework, and cybercriminals, specifically the APT28 group, have exploited these issues in attacks against Ukraine and the European Union. Microsoft has released a fix for the new vulnerability in its April 2026 security updates.
Search