Live
BusyBox 1.38.0 Heap Overflow Puts Routers, Containers, and IoT at Risk—Here’s How to Respond·MSFT +2.1%CVE-2026-63882: A Missing Check in AMD’s Linux Kernel Driver Can Crash Your System·NVDA +0.2%Patch Now: AMDGPU Kernel Race Condition (CVE-2026-63879) Opens Linux Systems to Local Attacks·GOOGL +1.7%Fix Your WSL 2 Kernel Now: Linux Ebtables Flaw CVE-2026-64077 Scores High Severity·AMZN +1.1%Encforge Ransomware Encrypts AI Models and Datasets—Here’s How to Protect Your ML Pipeline·MSFT +2.1%AMD Helios to Power Azure AI Inference: Microsoft's Multi-Silicon Bet Shakes Up Nvidia Rivalry·NVDA +0.2%A Zero-Length I/O Request Just Became a Critical Linux Kernel Vuln—Here’s What to Patch·GOOGL +1.7%AMD iGPU/GPU Linux Kernel Flaw Threatens System Security — Dual-Booters Must Act·AMZN +1.1%BusyBox 1.38.0 Heap Overflow Puts Routers, Containers, and IoT at Risk—Here’s How to Respond·MSFT +2.1%CVE-2026-63882: A Missing Check in AMD’s Linux Kernel Driver Can Crash Your System·NVDA +0.2%Patch Now: AMDGPU Kernel Race Condition (CVE-2026-63879) Opens Linux Systems to Local Attacks·GOOGL +1.7%Fix Your WSL 2 Kernel Now: Linux Ebtables Flaw CVE-2026-64077 Scores High Severity·AMZN +1.1%Encforge Ransomware Encrypts AI Models and Datasets—Here’s How to Protect Your ML Pipeline·MSFT +2.1%AMD Helios to Power Azure AI Inference: Microsoft's Multi-Silicon Bet Shakes Up Nvidia Rivalry·NVDA +0.2%A Zero-Length I/O Request Just Became a Critical Linux Kernel Vuln—Here’s What to Patch·GOOGL +1.7%AMD iGPU/GPU Linux Kernel Flaw Threatens System Security — Dual-Booters Must Act·AMZN +1.1%

Rbac Security

The latest Rbac Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

13 stories in view AI assisted desk updated 7:49 AM
Latest Most Read Breaking
Sort
CVE-2026-63882 · AMD KFD

CVE-2026-63882: A Missing Check in AMD’s Linux Kernel Driver Can Crash Your System

CVE-2026-63882 is a Linux kernel vulnerability in AMD’s KFD compute driver that can cause a NULL pointer dereference and system crash when an SVM ioctl is called before the required VM acquisition step. The fix has been backported to multiple stable kernels (6.1.176, 6.6.143, 6.12.93, 6.18.35, 7.0.12, and 7.1). Most affected are shared GPU servers and containerized workloads; home users with standard AMD graphics are unlikely to be impacted unless they actively use ROCm or HIP.

Security

BusyBox 1.38.0 Heap Overflow Puts Routers, Containers, and IoT at Risk—Here’s How to Respond

CVE-2026-38755 is a heap overflow vulnerability in BusyBox 1.38.0's ash shell that can cause denial of service on routers, embedded devices, and containers. While remote code execution has not been confirmed, the widespread use of BusyBox makes asset discovery and vendor patch verification urgent. The article provides a practical multi-step response plan for IT and security teams.

Security Desk·now ·5 min
Security

Fix Your WSL 2 Kernel Now: Linux Ebtables Flaw CVE-2026-64077 Scores High Severity

CVE-2026-64077 is a high-severity Linux kernel vulnerability in ebtables that affects kernels from 5.15 onward. Windows users with WSL 2, Docker Desktop, or Linux VMs must update their Linux kernels immediately. The fix is available upstream in Linux 6.18.34, 7.0.11, and 7.1. Follow our step-by-step guide to patch WSL, Docker, and VMs without delay.

Security Desk·4m ago ·5 min
Security

Patch Now: AMDGPU Kernel Race Condition (CVE-2026-63879) Opens Linux Systems to Local Attacks

A high-severity vulnerability (CVE-2026-63879) in the Linux kernel's AMDGPU driver allows local attackers to exploit a race condition in GPU memory management, potentially compromising system memory. The flaw, rated 7.8 CVSS, affects kernel versions 6.2 through 7.0.11 and has been fixed in 7.0.12 and 7.1. All AMD Radeon and Instinct users on Linux should update and reboot immediately, with extra urgency for shared GPU servers and compute clusters.

Security Desk·4m ago ·5 min
Advertisement
CVE-2026-64097 · AMD GPU

AMD iGPU/GPU Linux Kernel Flaw Threatens System Security — Dual-Booters Must Act

A high-severity Linux kernel flaw (CVE-2026-64097) in AMD’s VBIOS parsing can be exploited locally to access kernel memory. Windows systems are not directly affected, but dual-booters must update their Linux kernels immediately. Patching is simple and available for all major distributions.

SE Security Desk·9m ago
CVE-2026-63940 · Linux Kernel

A Zero-Length I/O Request Just Became a Critical Linux Kernel Vuln—Here’s What to Patch

A critical vulnerability (CVE-2026-63940, CVSS 9.3) in the Linux kernel’s KVM AMD SEV code allows guests to trigger memory arithmetic flaws via zero-length I/O requests. Patched kernels are available for 6.12.95, 6.18.35, 7.0.12, and 7.1. Windows machines are not directly affected, but Windows VMs on unpatched AMD KVM hosts are at risk. Administrators must inventory SEV-enabled hosts and apply the host-level fix promptly.

SE Security Desk·10m ago
CVE-2026-3842 · QEMU Vulnerability

Host-Crashing QEMU Bug Hits Windows Guests: Patch CVE-2026-3842 Now

A vulnerability in QEMU’s Hyper‑V synthetic debugger (CVE-2026-3842) allows a Windows guest to crash the host process via an out‑of‑bounds write. The flaw is in the virtual machine monitor, not in Windows. QEMU maintainers have released a fix, and major Linux distributions are now shipping updated packages. Administrators must update QEMU, restart affected VMs, and review whether the optional synthetic debugger feature is enabled.

SE Security Desk·15m ago
CVE-2026-64133 · Linux Kernel

High-Severity Linux Audio Driver Flaw Fixed — Here’s Who Needs to Act

CVE-2026-64133 is a high-severity out-of-bounds read vulnerability in the Linux kernel's ALSA driver for AudioScience ASI professional sound cards. Fixed in recent stable kernel releases, it poses no direct risk to Windows users but requires immediate patching on Linux-based broadcast and audio production systems. The flaw, which scored 7.8 on the CVSS scale, could allow local attackers to compromise kernel memory, but only on machines with the specific hardware.

SE Security Desk·15m ago
OpenSSL · CVE-2026-42770

OpenSSL’s Key-Leaking DHX Flaw Puts Windows Apps at Risk: Here’s How to Respond

CVE-2026-42770 is a newly patched OpenSSL vulnerability that can leak private Diffie-Hellman keys under specific conditions. While Windows itself is not affected, many third-party Windows applications bundle vulnerable OpenSSL libraries, requiring administrators to inventory and update their software. The fix is available in OpenSSL 3.0.21, 3.4.6, 3.5.7, 3.6.3, and 4.0.1.

SE Security Desk·24m ago
Microsoft Teams · Boss Scam

Teams Impersonation Scam Costs Pune Firm ₹56 Lakh, Call Saves ₹1.5 Crore

A Pune CFO lost ₹56 lakh after a fake CEO on Microsoft Teams triggered an urgent payment, but a phone call blocked a ₹1.5 crore follow-up demand. The scam exposes how criminals exploit collaboration platforms to bypass scepticism, and it forces a rethink of payment controls, identity checks, and Teams security settings across businesses.

SE Security Desk·54m ago
Microsoft 365 · Sharepoint

Microsoft Finally Forces Internal SharePoint Links to Expire — What Admins Must Do Now

Microsoft launched expiration policies for internal “People in your organization” sharing links in SharePoint and OneDrive, giving admins control to set maximum and recommended lifetimes. The change closes a governance gap but requires careful rollout to avoid breaking permanent navigation links, automations, and user workflows. This service-journalism piece explains what the policy does, practical impacts for employees, site owners, and IT pros, and provides a step-by-step implementation guide.

SE Security Desk·8h ago
Hollowgraph · Graph Api Abuse

Microsoft 365 Calendar Hijacked as C2 Channel in New HOLLOWGRAPH Malware

HOLLOWGRAPH, a newly discovered Windows malware, abuses Microsoft 365 calendar events via Microsoft Graph API to covertly receive commands and exfiltrate data, while using DNS tunneling to refresh stolen credentials. Discovered by Group-IB, the implant has targeted a handful of Israeli entities, blending into legitimate Microsoft 365 traffic to evade traditional security controls.

SE Security Desk·13h ago
WSUS · Windows Update

Microsoft Fixes WSUS Sync for New Servers, But Existing Ones Wait for July 2026 Patches

Microsoft fixed a WSUS synchronization outage for new and rebuilt servers on July 18, 2026, but administrators running long‑standing WSUS instances still cannot access July’s security patches. The incident, caused by an accumulation of publishing metadata at Microsoft’s end, disrupted patch deployment pipelines for organizations relying on WSUS and Configuration Manager. Microsoft is preparing guidance to help existing servers safely remove the problematic metadata, but until then, the July updates remain out of reach for many.

SE Security Desk·14h ago