Live
Apple's Genius Bar AI Pilot Records Your Repair Chat: How It Works and How to Opt Out·MSFT +0.1%Edge 152 Will Update Every Two Weeks Starting August 27—Here’s Your Action Plan·NVDA +3.0%Linux TIPC Decrypt Bug CVE-2026-63801: How a Missing Net Reference Left Systems Open to Use-After-Free Since Kernel 5.5·GOOGL +1.2%Linux Kernel’s Qualcomm Wi-Fi Double-Free Bug Gets Patched—Here’s What Windows Users Need to Know·AMZN +2.9%That Linux Kernel Bug Can Crash Your WSL 2 — Here’s How Microsoft Wants You to Fix It·MSFT +0.1%Microsoft's Project Perception: Multi-Model AI Seeks to Automate Vulnerability Remediation·NVDA +3.0%JPMorgan Chief Sounds ‘Ballistic Missile’ Alarm Over AI Bug-Hunting Model — Windows Defenders Must Act·GOOGL +1.2%Linux Kernel Bug in AMD Video Engine Fixed: What It Means for Your PC, Windows or Otherwise·AMZN +2.9%Apple's Genius Bar AI Pilot Records Your Repair Chat: How It Works and How to Opt Out·MSFT +0.1%Edge 152 Will Update Every Two Weeks Starting August 27—Here’s Your Action Plan·NVDA +3.0%Linux TIPC Decrypt Bug CVE-2026-63801: How a Missing Net Reference Left Systems Open to Use-After-Free Since Kernel 5.5·GOOGL +1.2%Linux Kernel’s Qualcomm Wi-Fi Double-Free Bug Gets Patched—Here’s What Windows Users Need to Know·AMZN +2.9%That Linux Kernel Bug Can Crash Your WSL 2 — Here’s How Microsoft Wants You to Fix It·MSFT +0.1%Microsoft's Project Perception: Multi-Model AI Seeks to Automate Vulnerability Remediation·NVDA +3.0%JPMorgan Chief Sounds ‘Ballistic Missile’ Alarm Over AI Bug-Hunting Model — Windows Defenders Must Act·GOOGL +1.2%Linux Kernel Bug in AMD Video Engine Fixed: What It Means for Your PC, Windows or Otherwise·AMZN +2.9%

Cgi Vulnerability

The latest Cgi Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.

13 stories in view AI assisted desk updated 7:52 AM
Latest Most Read Breaking
Sort
CVE-2026-63801 · Linux Kernel Vulnerability

Linux TIPC Decrypt Bug CVE-2026-63801: How a Missing Net Reference Left Systems Open to Use-After-Free Since Kernel 5.5

A newly disclosed Linux kernel vulnerability, CVE-2026-63801, is a use-after-free in TIPC’s encrypted receive path that mirrors a previously fixed encrypt-side bug. Affecting kernels since version 5.5, the flaw occurs when a network namespace is torn down while an asynchronous decryption callback is still pending. Patches have been backported to all stable branches, requiring only a kernel update and reboot. Windows systems are not directly affected; the primary risk is to Linux workloads running TIPC with crypto enabled, including WSL custom kernels, Hyper-V guests, and container hosts.

Advertisement
CVE-2026-63829 · Linux Kernel Vulnerability

Linux Kernel CVE-2026-63829 Exposes GRE Tunnels to Cross-Namespace Hijacking—What WSL 2 Users Must Patch Now

A newly disclosed Linux kernel vulnerability, CVE-2026-63829, allows a process with networking privileges in one container to reconfigure GRE or ERSPAN tunnels in another namespace, breaking container isolation. While Windows does not run the vulnerable code natively, its widespread use of WSL 2, Docker Desktop, and Hyper-V Linux guests means millions of systems may be exposed. Fixed kernels (6.12.95, 6.18.38, 7.1.3, and 7.2-rc1) are available, and patching through WSL updates, Docker Desktop updates, or Linux guest package managers is urgently recommended for environments using these tunneling protocols.

SE Security Desk·23m ago
Amd Kfd · Cve-2026-53376

AMD GPU Compute Bug Patched in Latest Linux Kernels: Here’s Why WSL 2 Users Should Pay Attention

A newly disclosed Linux kernel vulnerability (CVE-2026-53376) in the AMD KFD compute driver can be exploited by a local attacker to send oversized requests, but there's no active exploitation or severity score yet. The fix is available in stable kernels 6.6.140, 6.12.90, 6.18.32, and 7.0.9. Windows users are only affected if they run WSL 2 with GPU acceleration or dual-boot a Linux distro with an AMD GPU—updating the Linux kernel eliminates the risk.

SE Security Desk·28m ago
Amdgpu Driver · Cve 2026 53374

AMDGPU GART Table Flaw (CVE-2026-53374) Gets Linux Kernel Patch – Update Now

CVE-2026-53374 is a flaw in the Linux kernel's AMDGPU driver that can cause the GPU to use stale memory mappings from an uninitialized GART table. Patched kernels are available (6.1.175, 6.6.140, 6.12.90, 6.18.32, 7.0.9), and Linux users with AMD graphics should update immediately. Windows systems are not affected, but mixed environments and Linux GPU compute nodes need attention.

SE Security Desk·33m ago
Dell Devices · Intel Ipf

Out-of-Band Fix KB5121767 Unlocks July Patch for Affected Dell PCs Running Windows 11

Microsoft’s out-of-band cumulative update KB5121767, released July 18, 2026, resolves a compatibility issue between Windows 11 and Intel IPF drivers on specific Dell PCs. Home users should check for the update if they missed the July Patch Tuesday; IT admins need to target only affected devices. The fix lifts a hold without requiring fleet-wide deployment.

SE Security Desk·1h ago
Secure Boot · Certificate Update

The 2026 Secure Boot Shake-Up: What Windows Users and Admins Must Do Now

Microsoft has set an October 19, 2026 deadline for the expiration of the 2011 Secure Boot Production PCA certificate. While devices will still boot, they may lose future boot-level protections. IT admins must actively verify certificate updates on their fleets, especially on devices with older firmware or BitLocker encryption, to avoid potential boot failures and recovery loops. Home users will likely receive the update automatically through Windows Update but can manually check their status.

SE Security Desk·2h ago
Windows Server 2012 · ESU Deadline

Windows Server 2012/R2 Patching Ends October 2026: What Every IT Team Must Do Now

Microsoft's Extended Security Updates for Windows Server 2012 and 2012 R2 end on October 13, 2026, leaving un-migrated workloads permanently exposed. This article outlines a practical five-path migration strategy—retire, rehost, rebuild, upgrade, or isolate—along with inventory and dependency checks to help IT teams move before support vanishes.

SE Security Desk·2h ago
Microsoft Teams · External Domains

Microsoft Teams Now Flags Unusual External Contacts—Here’s How to Use the Report

Microsoft has introduced an External Domain Anomalies report in the Teams admin center that flags domains with unusual spikes in first-time external contact. The report uses behavioral baselines to highlight potential security risks, but it is not a threat detector—administrators must investigate each anomaly against business context. Practical guidance is provided on interpreting the report, setting up alerts, and integrating it with existing external access policies.

SE Security Desk·3h ago
KB5121767 · Windows 11 Update

Microsoft’s Emergency Windows 11 Update Fixes Dell Shutdowns, Unlocks July Security Patch

Microsoft released an out-of-band update, KB5121767, to fix a driver conflict that caused performance issues, battery drain, and shutdowns on certain Dell Windows 11 PCs. The patch also removes a block that prevented those machines from receiving the July security update, restoring the normal patching cycle.

SE Security Desk·5h ago
Microsoft Intune · Rbac Security

Intune’s Scoped Permissions Are a One-Way Trip: How to Audit Before You Opt In

Microsoft Intune's Scoped permissions preview is a one-way switch that prevents silent merging of admin rights across scope tags. Organizations must run the Permissions Assessment Report to identify and reconcile access reductions before enabling the irreversible setting.

SE Security Desk·7h ago