Graz University of Technology researchers used file-change alerts to catch 95.7% of another Windows user's Firefox site visits from an unprivileged account. On shared hosts and on servers that run services under their own accounts, separation between users is weaker than the account model suggests.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
Three exploited flaws, three very different exposure classes. The self-hosted Metabase zero-day is the one with an unpatched population behind it.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
GDB 18.1 adds every type symbol to .gdb_index to fix failed type lookups, and its notes say existing indexes should be regenerated. Teams that pin the debugger in CI should rebuild those indexes with it and retest any script that parses Windows paths.
Reality
- Evidence82
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence80
Opera asked judges in Luxembourg to force Microsoft Edge under the Digital Markets Act and lost, which tells platform teams that crossing the user thresholds only opens a market investigation the gateway argument can still close.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−5
- Incentives55
- Confidence75
Graz University researchers showed unprivileged apps can infer keystroke timing and browsing from file-change notifications on Linux, Android and Windows. The fixes shipped so far are partial, and the keystroke and KDE clickjacking flaws are still present.
Publishers:dev.to · lwn.net Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
CVE-2026-81963 in the Update Stack and CVE-2026-85880 in ALPC each take a low-privilege foothold to SYSTEM, and the remediation guidance asks for verified restarts, which is a harder number to report than install counts.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
Proofpoint says at least four China-linked espionage groups fired the same BlueMoon code at different victims during the four weeks a Chromium fix took to reach stable Chrome, and two more groups probably did too.
Perspective Coverage
9 publishers
- Builder
- Builder 31%
- Operator
- Operator 60%
- Investor
- Investor 9%
Reality
- Evidence80
- Adoption30
- Hype gap+10
- Incentives40
- Confidence76
Volexity attributes September 1 spear-phishing at multiple NGOs to the Chinese cluster UTA0560. The chain used two Chrome flaws and one in Windows ALPC, and a second China-nexus actor ran the same chain.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence62
Graz University of Technology researchers used OS file-change alerts to identify sites another Windows user visited with 97.8% accuracy in Firefox. Every attack needs code already running on the device; on Android, an app that asks for no permissions is enough.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence50
One operator's move of two TrueNAS servers onto a dual-TOR fabric failed at all five storage layers while the change plan reported healthy. Each break was invisible from the layer above it, so each layer needs its own cutover check.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
A file-type detector passed 260 tests and scored 100% on a hand-built benchmark. Pointed at about 8,900 files already sitting on the author's PC, it called thirteen System32 files dangerous and hung for minutes on one .ini.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives58
- Confidence58
Volexity dates UTA0565's exploitation to September 3 and 4, five to six days before it first reported the chain publicly, delivered from typosquats of China Digital Times and the Center for American Progress and ending in a new implant it calls CLEANGULP.
Reality
- Evidence72
- Adoption58
- Hype gap+8
- Incentives52
- Confidence64
The public proof-of-concept watches Defender's update directories, hoards nearly all the free space on C: with delete-on-close files, and hands the space back once the update has already failed. At rest, the disk looks normal.
Reality
- Evidence36
- Adoption12
- Hype gap+34
- Incentives
- Insufficient
- Confidence42
Cisco Talos read CLOSEDQUORUM statically: a Go binary that polls DeepSeek, Qwen, Mistral and Gemini before it touches LSASS. The distributed sample has dummy keys. One answering provider can carry the vote.
Reality
- Evidence58
- Adoption8
- Hype gap+25
- Incentives60
- Confidence55
Veeam Agent for Windows has a local flaw that promotes a standard account to SYSTEM. Exploit code has been public since September 14. Arctic Wolf says there is no official workaround for systems that cannot patch yet.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives65
- Confidence55
Kaspersky says a previously unknown multi-stage loader has spread since mid-August through a compromised public torrent archive. It reaches its command server through the Solana blockchain. Victims include government and transport organisations.
Reality
- Evidence32
- Adoption30
- Hype gap+35
- Incentives85
- Confidence50
A Flask app packaged by PyInstaller kept running after users quit, because os._exit(0) fired from a daemon thread does not reliably kill a frozen build. The cleanup now happens at the next startup.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives20
- Confidence55
A single September 2026 KEV batch produced 1,262,273 GitLab matches and nothing at all for Cisco Secure Firewall Management Center, because the console holding one of the two 10.0 bugs is the one passive scanning cannot fingerprint.
Reality
- Evidence45
- Adoption55
- Hype gap+10
- Incentives70
- Confidence50
A fresh terminal resolves ffmpeg while the IDE on the same machine says the tool is missing. The difference is the environment block each process got when it was created, and Windows sends no update to a process already running.
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap−12
- Incentives18
- Confidence70
The bugs sit in 14 named Azure and Copilot services and Microsoft rated all 18 critical, but the fixes were already running in production when the disclosure went out, so tenants cannot install or verify anything themselves.
Reality
- Evidence45
- Adoption60
- Hype gap+20
- Incentives65
- Confidence45
Earlier coverage
- ASUS general manager says firmware-level access is the missing piece for full IT outsourcing
Leadership · September 17, 2026 · 1 publisher
- CHOSEN BRICK routes its commands through a Telegram bot issued per victim device
Build · September 17, 2026 · 1 publisher
- VectraRAT reaches high integrity by reparenting itself under auto-elevating computerdefaults.exe
Build · September 16, 2026 · 1 publisher
- Five commits in the fixture left a ranking test comparing string lengths
Build · September 15, 2026 · 1 publisher
- A wildcard in the twenty-first field hid CrowdStrike's field-count mismatch for four months
Build · September 15, 2026 · 1 publisher
- Espionage crews exploited a Chrome flaw that Chromium had already fixed in public source
Leadership · September 15, 2026 · 1 publisher
- Python on Windows decodes UTF-8 config files with the ANSI code page
Build · September 12, 2026 · 1 publisher
- Anthropic's most capable model built working exploits from 16 of 39 published patches
Leadership · September 11, 2026 · 1 publisher
- Four espionage crews picked up the same Chrome and Windows exploit chain within days
Product · September 11, 2026 · 1 publisher
- Two Chinese actors hit Chrome with byte-identical shellcode before the Chromium fix shipped
Build · September 11, 2026 · 1 publisher
- Unexplained pending pulls showed up an hour before the antivirus found the fake font
Build · September 10, 2026 · 1 publisher
- BleachBit 6.0.4 repairs a Windows file shredder that skipped scattered clusters
Security · September 9, 2026 · 1 publisher
- Microsoft retracts its root-cause explanation for Teams Mac call failures
Security · September 4, 2026 · 1 publisher
- SpecterOps shows malware getting valid passkey assertions out of Windows itself
Security · September 4, 2026 · 1 publisher
- Perplexity's Windows agent summarized the medical PDFs in a reviewer's Downloads folder
Product · August 31, 2026 · 1 publisher
- TA4922 parks Donut Loader in the same folder as a signed executable
Build · August 28, 2026 · 1 publisher
- Not Responding is a message-loop state, not a fault: get the evidence before the reinstall
Build · August 23, 2026 · 1 publisher
- Parallel coding agents on Windows break at the home directory, not the launcher
Build · August 23, 2026 · 1 publisher
- The suite wrote its own verdict to disk for a week. The CI runner never opened the file.
Build · August 22, 2026 · 1 publisher
- On Windows, a named pipe is a local API: assume everything on the box can knock
Security · August 22, 2026 · 1 publisher
- The malware asks a question and reads its orders off the doormat: PowerShell in FTP banners
Build · August 21, 2026 · 1 publisher
- A 58% flake in a shared disk cache was a real race, found only when Linux-only CI met Windows
Build · August 21, 2026 · 1 publisher
- Short Build Roots Do Not Fix MAX_PATH: Unreal Cook Failures Are a Windows Setting
Build · August 21, 2026 · 1 publisher
- Cursor runs a repository's own git.exe on Windows, and has done for months
Science · August 19, 2026 · 1 publisher
- Your GPU reports 24GB. Only 7.9GB of it loads a model, and half of that is already gone
Build · August 18, 2026 · 1 publisher
- ShieldBreak: a Defender-to-SYSTEM PoC that your last patch cycle did not stop
Build · August 17, 2026 · 1 publisher
- Codex learns to click: the coding agent stops typing patches and starts operating the machine
Build · August 17, 2026 · 1 publisher
- Pass-ta-key breaks Chrome's device trust, not WebAuthn: harden the endpoint, keep the rollout
Build · August 16, 2026 · 1 publisher