Breaking Windows & Microsoft News
Real-time, AI-assisted coverage of the stories moving fastest across Windows, security, and the Microsoft cloud.
New Linux LM90 Driver Flaw: What Windows and WSL Administrators Should Do Right Now
On July 19, 2026, CVE-2026-64038 landed in the National Vulnerability Database, detailing a use-after-free race condition in the Linux kernel’s lm90 hardware-monitoring driver. The bug can corrupt...
BusyBox 1.38.0 Heap Overflow Puts Routers, Containers, and IoT at Risk—Here’s How to Respond
A newly disclosed vulnerability in BusyBox’s ash shell can be triggered by crafted input to cause a denial of service, potentially crashing routers, embedded appliances, and containerized systems....
CVE-2026-63882: A Missing Check in AMD’s Linux Kernel Driver Can Crash Your System
Linux kernel maintainers have patched a newly cataloged flaw in AMD’s GPU compute stack that can trigger an instant system crash. The vulnerability, tracked as CVE-2026-63882, was published on July...
Patch Now: AMDGPU Kernel Race Condition (CVE-2026-63879) Opens Linux Systems to Local Attacks
On July 19, 2026, the Linux kernel security team disclosed CVE-2026-63879, a high-severity vulnerability in the AMDGPU driver that could let a local attacker read or corrupt sensitive memory. The...
Fix Your WSL 2 Kernel Now: Linux Ebtables Flaw CVE-2026-64077 Scores High Severity
A high-severity Linux kernel vulnerability (CVE-2026-64077) was published on July 19, 2026, and it’s not just a problem for Linux admins. With a CVSS score of 7.8, the bug targets the ebtables...
Encforge Ransomware Encrypts AI Models and Datasets—Here’s How to Protect Your ML Pipeline
The threat actor behind the first fully autonomous ransomware operation has resurfaced with a new weapon that locks up model weights, training datasets, embedding indexes, and other machine-learning...
A Zero-Length I/O Request Just Became a Critical Linux Kernel Vuln—Here’s What to Patch
On July 19, 2026, kernel.org disclosed CVE-2026-63940, a critical flaw in the Linux kernel’s KVM handling for AMD Secure Encrypted Virtualization. The vulnerability—a failure to reject Port I/O...
AMD iGPU/GPU Linux Kernel Flaw Threatens System Security — Dual-Booters Must Act
On July 19, 2026, the Linux kernel project disclosed CVE-2026-64097, a local vulnerability in the AMD Display Core that allows an attacker with a crafted GPU firmware image to read sensitive kernel...
High-Severity Linux Audio Driver Flaw Fixed — Here’s Who Needs to Act
A lingering oversight in the Linux kernel’s ALSA audio framework has been patched after years of dormancy, addressing a vulnerability that could compromise specialized audio hardware used in...
Host-Crashing QEMU Bug Hits Windows Guests: Patch CVE-2026-3842 Now
A virtualization vulnerability tracked as CVE-2026-3842 lets a Windows guest on a QEMU/KVM host trigger an out-of-bounds memory write that crashes the host process, Microsoft confirmed in an advisory...
BusyBox 1.38.0 DoS Flaw Strikes Embedded Shells — Here’s How Windows Admins Should Respond
A newly disclosed vulnerability in the BusyBox 1.38.0 ash shell can be exploited remotely to crash devices and infrastructure critical to many Windows-centric networks. CVE-2026-38754, published by...
OpenSSL’s Key-Leaking DHX Flaw Puts Windows Apps at Risk: Here’s How to Respond
On June 9, 2026, a low-severity rating masked a serious cryptographic bug: OpenSSL’s DHX key validation could let an attacker reconstruct your private Diffie-Hellman key if the conditions are...