Vista elenco
- Tutti i dubbi di LibreOffice su Euro-Office: non usare lo standard ODF aiuta Microsoft ed il lock-in
Tutti i dubbi di LibreOffice su Euro-Office: non usare lo standard ODF aiuta Microsoft ed il lock-in

Cose di cui si potrebbe fare a meno: Microsoft pubblica Coreutils for Windows!

Patch Tuesday, May 2026 Edition
Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used software makers — including Apple, Google, Microsoft, Mozilla and Oracle — fixing near record volumes of security bugs, and/or quickening the tempo of their patch releases.
As it does on the second Tuesday of every month, Microsoft today released software updates to address at least 118 security vulnerabilities in its various Windows operating systems and other products. Remarkably, this is the first Patch Tuesday in nearly two years that Microsoft is not shipping any fixes to deal with emergency zero-day flaws that are already being exploited. Nor have any of the flaws fixed today been previously disclosed (potentially giving attackers a heads up in how to exploit the weakness).
Sixteen of the vulnerabilities earned Microsoft’s most-dire “critical” label, meaning malware or miscreants could abuse these bugs to seize remote control over a vulnerable Windows device with little or no help from the user. Rapid7 has done much of the heavy lifting in identifying some of the more concerning critical weaknesses this month, including:
- CVE-2026-41089: A critical stack-based buffer overflow in Windows Netlogon that offers an attacker SYSTEM privileges on the domain controller. No privileges or user interaction are required, and attack complexity is low. Patches are available for all versions of Windows Server from 2012 onwards.
- CVE-2026-41096: A critical RCE in the Windows DNS client implementation worthy of attention despite Microsoft assessing exploitation as less likely.
- CVE-2026-41103: A critical elevation of privilege vulnerability that allows an unauthorized attacker to impersonate an existing user by presenting forged credentials, thus bypassing Entra ID. Microsoft expects that exploitation is more likely.
May’s Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws. Microsoft was among a few dozen tech giants given access to a “Project Glasswing,” a much-hyped AI capability developed by Anthropic that appears quite effective at unearthing security vulnerabilities in code.
Apple, another early participant in Project Glasswing, typically fixes an average of 20 vulnerabilities each time it ships a security update for iOS devices, said Chris Goettl, vice president of product management at Ivanti. On May 11, Apple shipped updates to address at least 52 vulnerabilities and backported the changes all the way to iPhone 6s and iOS 15.
Last month, Mozilla released Firefox 150, which resolved a whopping 271 vulnerabilities that were reportedly discovered during the Glasswing evaluation.
“Since Firefox 150.0.0 released, they have been on a more aggressive weekly cadence for security updates including the release of Firefox 150.0.3 on May Patch Tuesday resolving between three to five CVEs in each release,” Goettl said.
The software giant Oracle likewise recently increased its patch pace in response to their work with Glasswing. In its most recent quarterly patch update, Oracle addressed at least 450 flaws, including more than 300 fixes for remotely exploitable, unauthenticated flaws. But at the end of April, Oracle announced it was switching to a monthly update cycle for critical security issues.
On May 8, Google started rolling out updates to its Chrome browser that fixed an astonishing 127 security flaws (up from just 30 the previous month). Chrome automagically downloads available security updates, but installing them requires fully restarting the browser.
If you encounter any weirdness applying the updates from Microsoft or any other vendor mentioned here, feel free to sound off in the comments below. Meantime, if you haven’t backed up your data and/or drive lately, doing that before updating is generally sound advice. For a more granular look at the Microsoft updates released today, checkout this inventory by the SANS Internet Storm Center.
Des comptes de messagerie du FMI piratés !
18th March – Threat Intelligence Report
Rapid7 offers continued vulnerability coverage in the face of NVD delays
Dark Web Tool Arms Ransomware Gangs: E-commerce & Aviation Industries Targeted
Patch Tuesday du mois de mars : 59 CVE pour Microsoft
Key MITRE ATT&CK Techniques Used by Cyberattackers
【資安日報】3月18日,國際貨幣基金組織電子郵件帳號傳出遭到挾持
安全事件周报 2024-03-11 第11周
【資安週報】2024年3月11日到3月15日
CERTFR-2024-AVI-0224 : Multiples vulnérabilités dans Microsoft Edge (15 mars 2024)
Akamai ha scoperto una vulnerabilità di Microsoft Themes
- Les pirates peuvent lire les conversations privées avec les assistants d'IA même lorsqu'elles sont chiffrées, une attaque déduit les réponses avec une précision parfaite des mots dans 29 % des cas
【資安日報】3月15日,Windows安全機制SmartScreen弱點在公布前也被用於散布惡意程式DarkGate
CVE-2023-48788: Fortinet и невидимые взломщики в битве за системные привилегии
Пользователи Windows, будьте осторожны: DarkGate использует уязвимость нулевого дня
- Microsoft aborda 61 vulnerabilidades en su última actualización de seguridad: un vistazo a las principales amenazas
Marcowy Wtorek Microsoftu 2024. (P24-083)
Microsoft ออกแพตช์เดือนมีนาคม 2024 อุดช่องโหว่กว่า 60 ตัว
CISA แจ้งเตือนช่องโหว่ใน Microsoft Streaming กำลังถูกใช้ในการโจมตี
¿Tienes un router Ubiquiti EdgeRouter? Estás en peligro por esta amenaza
Kibernoziedznieki izmanto ChatGPT ažiotāžu pasaulē un Latvijā – novērsti jau 650 000 uzbrukumi
Hihetetlen hiba az Outlookban: egyetlen „!" begépelése áttörte a komplett védelmet
พบ Exchange Server กว่า 28,500 ตัวเสี่ยงต่อการถูกโจมตี
bitume - mare crudele - podcast
Bitume, trasmissione radiofonica aperiodica, impreparata e inaspettata, a "cura" di Unit hacklab Milano.

Mercoledì 28 giugno 2023, dallo studio radio di ZAM
Mare crudele
-
IBM aveva una sua AI e la chiamava Watson
-
Aggiornamenti sul sottomarino che scese a visitare il Titanic
-
Viaggi su Marte e altri ambienti scomodi che …