Author: Gary Behan

Software engineer and video game uber-nerd.

Plex has urged all users to update immediately, warning that Plex Media Server vulnerabilities affect version 1.43.2 and earlier, with patched releases now available for both the server software and desktop client. The company has taken the unusual step of emailing customers directly to press the point home.The fixed versions are Plex Media Server 1.43.3, released on 19 May, and Plex Desktop 1.115.0, released on 13 August. Both can be downloaded from the official downloads page or the server management page. ‘We recommend all server owners and Desktop users update to the latest version as soon as possible,’ the company…

Read More

A Teams and Outlook ARM crash affecting Surface Laptop 7 and Surface Pro 11 owners has been traced to Windows security updates released on or after 11 August 2026. Microsoft confirmed the issue in a Windows release health update and has marked its status as ‘Mitigated’, though a permanent fix is still in development.The affected update is KB5121003, which applies to Windows 11 24H2 and 25H2. According to WinTips.org, users running Windows 11 26H1 encounter the same behaviour through a separate update, KB5121000. That detail is worth noting for IT teams managing a mixed fleet: the symptoms are identical across…

Read More

Sangoma Switchvox CVE-2026-9586, an unauthenticated SQL injection flaw capable of leading to remote code execution, is being actively exploited in the wild, with Horizon3 warning that most internet-exposed Switchvox systems have already been targeted or will be shortly. CISA moved quickly: it added the vulnerability to its Known Exploited Vulnerabilities catalogue on 2 September 2026 and set a 5 September remediation deadline for federal civilian agencies under Binding Operational Directive 26-04, according to Cyber One Solutions. What makes CVE-2026-9586 so easy to exploit Switchvox is a VoIP-based unified communications platform built on the open-source Asterisk engine and aimed at small…

Read More

A critical authentication bypass flaw in JFrog Artifactory is being actively exploited in a JFrog Artifactory admin token exploit campaign, with attackers forging their own administrative tokens on unpatched, self-managed instances. The vulnerability, tracked as CVE-2026-82329, carries a Shattered.io-confirmed CVSS score of 9.8 out of 10, placing it firmly in the critical category.Artifactory is a repository manager used to store, organise, secure, and distribute software packages. Because it sits upstream of build and deployment pipelines, access to it is far more consequential than access to most enterprise applications: whatever an attacker can plant in a trusted repository will, in many…

Read More

Defender for Office 365 Safe Links spent part of the day treating perfectly ordinary Google search URLs as a threat, prompting Microsoft to open an investigation under incident ID MO1465962 after first acknowledging the problem at 10:30 AM UTC.Affected users were met with an ‘Opening this website might not be safe’ warning whenever they tried to follow a blocked link. Worse, the usual workaround of copying a link and pasting it directly into a browser did nothing to sidestep the warning, the classification applied regardless of how the URL was accessed.What Defender for Office 365 Safe Links actually doesSafe Links…

Read More

The Aktulaev TVRAT malware indictment has moved into federal custody after Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, was extradited to the United States on 28 August 2026 following his arrest at Larnaca Airport in Cyprus in May 2025. A California federal grand jury had indicted him on charges stemming from a phishing campaign that infected roughly 80,000 freelancers with remote-access malware between 2016 and 2017.Court documents, filed in June 2021 and unsealed this week, allege that Aktulaev exploited the messaging platform of an unnamed freelance employment technology company based in the Northern District of California. Using 255 fake user…

Read More

A Faronics Deploy phishing attack campaign has been abusing the legitimate cloud-based endpoint management platform to silently enrol victim machines into attacker-controlled deployments, then use that foothold to push ConnectWise ScreenConnect as a secondary remote-access channel. Huntress, a managed detection and response (MDR) company, observed the activity running from 21 July to 20 August, during which Faronics-themed lures reached more than 457 endpoints via emails disguised as invoices, tax documents, or other routine business files.How the Faronics Deploy phishing attack actually worksFaronics Deploy is a cloud-based platform that allows IT administrators to remotely enrol and manage computers, deploy software, and…

Read More

A new technical publication compiling 18 scientific articles on waste reduction in some of the planet’s most extreme research environments has landed at the centre of an expanding international climate partnership, as Türkiye positions its polar science programme alongside London’s climate action network ahead of COP31. The Zero Waste Foundation launched the book “Zero Waste in the Polar Regions” on 7 August, produced with TÜBİTAK’s (Scientific and Technological Research Council of Türkiye) Polar Research Institute. Rather than treating waste management as an afterthought, the publication documents how zero waste principles can be engineered directly into the planning and logistics of…

Read More

Attackers are actively exploiting the Langflow RCE vulnerability tracked as CVE-2026-0768, using it to harvest AWS secrets, OpenAI API keys, and administrative credentials from exposed instances of the open-source AI application framework. The flaw carries a CVSS score of 9.8, according to Qualys ThreatPROTECT, placing it at the top of the critical severity band.The vulnerability resides in the code validator inside Langflow’s custom component editor. It allows an unauthenticated attacker to execute arbitrary Python code with root privileges by supplying a crafted string to the validate endpoint, no login required, no prior foothold needed.From honeypot to 360 attacks: how the…

Read More

A Virtualizor BGP hijacking attack allowed an unknown threat actor to intercept software update requests and push a malicious package to a number of installations between 20:57 UTC on 28 August and 06:10 UTC on 30 August. What makes this incident stand out from a routine supply-chain compromise is the sophistication of the delivery mechanism: the attacker did not need to break any encryption, because they arrived carrying a technically valid TLS certificate.How the Virtualizor BGP Hijacking Attack UnfoldedBGP (Border Gateway Protocol) is the routing protocol that tells the global internet how to direct traffic between networks. When an operator…

Read More