Help Net Security reports that Microsoft has pushed out an out-of-band security update…

Help Net Security reports that Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity flaw, CVE-2026-96940. The bug may let authenticated attackers read emails and attachments of other users in the same organization, so Exchange Server admins should install the update as soon as possible.

Help Net SecurityWeek in review: FortiBleed is still active, Patch Tuesday forecast

Source: helpnetsecurity.com

More in this rubric
all →

The Register reports that researchers found two characters that can trick Chromium browsers into showing lookalike URLs as genuine web addresses. The issue affects Chromium-based browsers such as Chrome and Edge, and the fake domains can bypass browser safety checks. Windows users should update their browser when a fix is available and be careful with links that look like familiar sites but use unusual characters.

The RegisterTwo characters open up a world of typosquatting opportunities in Chromium browsers

Source: theregister.com

SecurityWeek reports that Citrix is urging immediate patching of a critical NetScaler vulnerability that could lead to remote code execution or denial of service. The flaw affects NetScaler ADC and NetScaler Gateway appliances in specific SAML configurations, as well as Secure Private Access Hybrid deployments. Citrix says it is not aware of unmitigated exploits, but users should update to the fixed versions as soon as possible.

SecurityWeekCitrix Urges Immediate Patching of Critical NetScaler Vulnerability

Source: securityweek.com

SecurityWeek reports that TP-Link has disclosed five vulnerabilities in its Aginet line of ISP-managed mesh systems, routers and modems. The bugs can let an attacker on the same network take over an affected device, create a super-administrator account, enable SSH access, or recover passwords and Wi-Fi credentials from configuration files. TP-Link says firmware updates are distributed by ISPs, so users should check the device management interface or app for updates and contact their ISP if none are available.

SecurityWeekTP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

Source: securityweek.com

5,465 members already hereReading, writing, commenting and voting. 0 verified · 190 joined this year