search
The Patch
Trends
- 1Multiple vulnerabilities discovered in the Linux kernel●Several vulnerabilities have been discovered in the Linux kernel
Several security vulnerabilities have been discovered in the Linux kernel. The disclosure is drawing attention from developers and system administrators, who are closely watching for patched kernel releases and guidance on which versions are affected. Admins are expected to apply updates promptly, as kernel flaws can expose servers and embedded systems to privilege escalation or other attacks.
- 2Google to end ChromeOS support two years ahead of schedule●Google ending ChromeOS support two years early
Google is ending support for ChromeOS two years earlier than originally planned, cutting short the lifespan of the operating system that powers Chromebook laptops. The change is drawing attention from developers and Chromebook owners concerned about what it means for device updates, security patches and long-term usability of hardware already in circulation.
- 3
Southern Ontario is waking up to fog patches on October 3, with temperatures climbing to a high near 20 C through the day, according to INsauga's weather report. Toronto and surrounding areas are watching conditions as the mild, misty start sets the tone for early October across the region.
- 4
Kernel maintainer Greg Kroah-Hartman discusses software security in an era when large language models are increasingly used to write code. The talk, shared as a video, examines how AI-generated contributions affect the Linux kernel's review process and the challenges of maintaining security standards as LLM-assisted development spreads. Readers are weighing how maintainers can vet code at scale when machine-written patches grow in volume.
- 5GrapheneOS fixes Android 17 QPR1 kernel performance regression●GrapheneOS has fixed the Android 17 QPR1 kernel performance regression
GrapheneOS, the privacy-focused Android operating system, has resolved a significant kernel performance regression affecting devices running the Android 17 QPR1 update. The fix addresses a slowdown that had impacted system responsiveness for users of the custom OS. Users on the GrapheneOS forum are discussing the patch, with many expressing relief that the performance issue has been corrected.
- 6
Sony has updated the PlayStation 5 Slim with improvements to its cooling system and easier repairability, changes similar to those introduced with the PS5 Pro. The revision is drawing attention in Germany, where coverage highlights what it means for buyers. Meanwhile, PS5 users are also discussing update 1.002.000 for Marvel's Wolverine, which marks the debut of QSSR support.
- 7GOG users hit with over 100GB of game updates●Oh... wow... Man macht, nach ein paar Wochen Pause, mal wieder GOG Galaxy auf und was gibt es ? Über 100GB Updates, alle
PC gamers reopening GOG Galaxy after a few weeks away are facing more than 100GB of pending updates, including around 88GB for a single Witcher 3 remaster. One user sarcastically noted that SSD storage 'costs nothing anymore' in 2026, reflecting frustration at the sheer size of modern game patches.
- 8Arc Raiders Frozen Trail Update Adds Enemies, Events and Gadgets▼Arc Raiders Frozen Trail Adds New Enemies, Events, Gadgets, And More
Arc Raiders has received a new update called Frozen Trail, bringing additional enemies, in-game events, gadgets and more content to the extraction shooter. The patch appears to be a seasonal content drop, expanding the game's map and gameplay options. Details on the full patch contents remain limited in early coverage.
- 9
Attackers are actively exploiting a vulnerability in Cisco's SD-WAN software, according to a breach roundup from BankInfoSecurity. The report groups the Cisco flaw with other recent security incidents and breach news. The flaw affects organizations using Cisco's software-defined wide area networking product, and defenders are being urged to apply available patches and review their systems for signs of compromise.
- 10Critical Command Injection Flaw Disclosed in Fortra BoKS Privileged Access Manager▼CVE-2026-9862: Critical OS Command Injection Vulnerability in Fortra BoKS Core Privileged Access Manager Threatens System Security
A critical vulnerability, tracked as CVE-2026-9862, has been disclosed in Fortra's BoKS Core Privileged Access Manager. The flaw is an OS command injection issue, meaning an attacker could potentially execute arbitrary system commands on affected servers. Because BoKS is used to manage privileged access at enterprises, security teams are being urged to review their exposure and patch promptly.
- 11Apple: iPhone 18 Pro Max Devices Losing AT&T Service Must Be Replaced▼Apple Says iPhone 18 Pro Max Units That Lost AT&T Service Need Replacement, Not a Fix
Apple has determined that iPhone 18 Pro Max units affected by lost AT&T cellular service cannot be repaired with a software or hardware fix and must instead be replaced. The issue leaves affected users without service on the carrier, and owners are being directed to swap their devices rather than wait for a patch.
- 12Dustin May to start Game 3 for Brewers in NLDS●Despite tough stretch drive, May gets Game 3 nod for Crew https://www. mlb.com/news/dustin-may-to-sta rt-nlds-game-3-bre
Milwaukee Brewers manager has named Dustin May the starter for Game 3 of the National League Division Series against the Padres, despite May struggling through a rough patch at the end of the regular season. The decision signals the club's confidence in the right-hander as the playoff series shifts to Milwaukee.
- 13Apple patches iPhone security flaw exploited in targeted attacks●Skjutit upp iPhone-uppdateringen? Apple har nu åtgärdat ett säkerhetsproblem som enligt företaget kan ha utnyttjats i ri
Apple has released a fix for a security vulnerability in the iPhone that the company says may have been actively exploited in targeted attacks. Users who have delayed recent iOS updates are being urged to install the patch now. Security experts recommend checking that your device is running the latest software to stay protected.
- 14Fall activities arrive across Acadiana▼Fall is here in Acadiana. See where to find pumpkins, hayrides and family fun.
Fall has arrived in Acadiana, and local outlets are pointing families toward seasonal attractions across the region. Pumpkin patches, hayrides and other autumn events are opening, with listings highlighting where residents can take children for classic fall outings in southern Louisiana.
- 15Roundcube Webmail SQL Injection Flaw Actively Exploited▼Roundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation Roundcube Webmail high-severity S
A high-severity SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is under active exploitation. The flaw resides in the virtuser_query plugin and allows unauthenticated attackers to compromise servers running the popular open-source webmail software. Security administrators are being urged to patch affected installations immediately and check systems for signs of compromise.
- 16Update fixes kernel flaws enabling DoS and privilege escalation●There's a headline going around saying "Massive Update Leading to DoS and Privilege Escalation Attacks". It reads as if
A headline circulating among security professionals suggests a recent kernel update itself caused denial-of-service and privilege escalation attacks. Security engineers are pushing back, clarifying that the update actually patches vulnerabilities that could enable such attacks. Since 2024 the Linux kernel project acts as its own CVE Numbering Authority, assigning identifiers for flaws directly, which has changed how fixes and disclosures are labeled and reported.
- 17Zammad warns of session hijacking flaw enabling remote code execution●Zammad security alert: session hijacking and remote code execution CVE-2026-102489 concerns session hijacking that can l
Zammad has issued a security alert for CVE-2026-102489, a session hijacking vulnerability that can lead to remote code execution as the Zammad service account on affected older installations. DIVD reports that the flaw has already been exploited in a real-world incident, prompting urgent calls for administrators to update their systems.
- 18Phproject vulnerability lets API users bypass issue restrictions●CVE-2026-104991 is a missing-authorization flaw in Alanaktion Phproject. Authenticated API key holders can bypass restri
A missing-authorization vulnerability, CVE-2026-104991, has been disclosed in Alanaktion Phproject. Authenticated users with API keys can bypass restricted-issue controls to read issue contents, comments and email addresses, and post unauthorized comments. Versions 1.1.6 through 1.8.6 are affected. Security communities are sharing the advisory as administrators assess whether their deployments need patching.
- 19Vanilla Minecraft runs on RK3588 ARM board with mainline drivers●Vanilla Minecraft on RK3588 ARM SoC using mainline kernel and drivers https:// lemmy.ml/post/53565244
A demonstration shows vanilla Minecraft running on a board powered by the Rockchip RK3588 ARM system-on-chip, using the mainline Linux kernel and open mainline graphics drivers rather than vendor forks. Linux and ARM enthusiasts are discussing the result as a sign of improving upstream support for Rockchip hardware, which has traditionally relied on out-of-tree patches and proprietary GPU driver stacks.
- 20
Gardening experts say autumn is the ideal time to reseed fescue lawns, as cooler temperatures and moist soil help new grass establish strong roots before winter. Homeowners are being advised to overseed thin or bare patches now to ensure a fuller, healthier lawn come spring, making lawn care a timely seasonal topic.
- 21Five best Halloween and fall events on the Treasure Coast●5 best Florida Halloween and fall events on the Treasure Coast
Treasure Coast News has rounded up five of the best Halloween and fall events taking place along Florida's Treasure Coast this season. The list highlights seasonal activities for families and visitors looking to enjoy autumn festivities on the state's Atlantic coast, from pumpkin patches to spooky Halloween celebrations.
- 22Linux workarounds emerge for Fujitsu MONAKA CPU bugs●Linux Begins Seeing Workarounds For Fujitsu MONAKA CPU Bugs
Workarounds for hardware bugs in Fujitsu's MONAKA ARM-based server processor have begun landing in the Linux kernel. The patches address errata so the new CPU, Fujitsu's flagship data centre chip, can run reliably on mainline Linux. Coverage has come via Phoronix, which tracks kernel development closely.
- 23GitLab Patches Critical AI Gateway Vulnerability CVE-2026-90970▼CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
GitLab has fixed a critical vulnerability, tracked as CVE-2026-90970, affecting its AI Gateway component. Security outlets are urging users to update their deployments promptly, as flaws in AI gateway infrastructure could expose sensitive data or allow unauthorized access. Administrators are advised to review the advisory and apply the patch as soon as possible.
- 24AT&T and Apple mocked over iPhone calling glitch●Alert: you have invented a $1,600 titanium rectangle that can map the stars but cannot call your mother. AT&T and Apple
Users are mocking Apple and AT&T after reports that a premium iPhone model, described sarcastically as a '$1,600 titanium rectangle that can map the stars but cannot call your mother', lost basic calling ability. A patch was reportedly shipped, but commenters say the fix only works under certain conditions, turning the high-end device into what one critic called 'the world's most expensive iPod Touch'.
- 25GitLab warns of critical RCE flaw in AI Gateway▼⚠️ CRITICAL: GitLab warns of critical RCE vulnerability in AI Gateway service GitLab disclosed CVE-2026-90970, a critica
GitLab has disclosed CVE-2026-90970, a critical remote code execution vulnerability in its AI Gateway service. The flaw allows authenticated users with Duo Agent Platform access to escape the prompt sandbox and execute arbitrary commands. Self-hosted instances are affected, and security teams are being urged to patch promptly.
- 26
Linux kernel 7.4 will include device-tree support for Apple's M4-powered Macs, extending official kernel support for Apple Silicon hardware. This means the M4 generation of MacBook Air, MacBook Pro, Mac mini and iMac machines can be booted with mainline Linux rather than relying on out-of-tree patches, a milestone for developers running Linux on Macs.
- 27Fortinet FortiMail Bug CVE-2026-104286 Actively Exploited●Fortinet FortiMail CVE-2026-104286 Actively Exploited: Critical Path Traversal and NULL Byte Vulnerability Alert
Fortinet has a critical vulnerability, tracked as CVE-2026-104286, in its FortiMail email security product. The flaw involves path traversal combined with NULL byte handling, and security researchers report it is being actively exploited in the wild. Administrators are being urged to apply patches immediately to prevent attackers from compromising mail servers.
- 28AI agents exploit open source flaws, forcing faster patching▼AI agents exploit open source flaws, force faster patching
AI agents are increasingly finding and exploiting vulnerabilities in open source software, prompting maintainers and companies to speed up their patching cycles. The trend raises concerns that automated tools could scale up exploitation of known flaws before fixes reach users, putting new pressure on open source security practices and update processes across the software industry.
- 29Garden season ends with peppers and eggplants composted●And now on to the last things standing; the green bell peppers and the eggplant (aubergines). These will be dug up and r
A gardener has reached the end of the growing season, digging up the last crops standing — green bell peppers and eggplants — to run through a shredder and compost into mulch for next year's beds. With the plants cleared away, the patch is being put to rest for winter, marking a quiet close to the gardening year.
- 30Australia's best home gardens showcased from rooftops to cattle farms▼From urban rooftops to working cattle farms: Australia’s best home gardens – in pictures
A photo collection highlights standout home gardens across Australia, ranging from small urban rooftop plots to productive gardens on working cattle farms. The images showcase the diversity of backyard growing in the country, featuring vegetable patches, native plantings and creative use of limited city space alongside large rural properties.
- 31High-severity flaw reported in NetScaler ADC and Gateway▼CVE-2026-88779 (HIGH, CVSS 8.7) impacts NetScaler ADC & Gateway https:// radar.offseq.com/threat/cve-20 26-88779-vulnera
A new vulnerability tracked as CVE-2026-88779 has been disclosed affecting Citrix NetScaler ADC and NetScaler Gateway, with a high severity rating of 8.7 on the CVSS scale. The finding is circulating among cybersecurity professionals, who are monitoring the flaw for details on exploitation and the availability of patches from Citrix.
- 32Citrix NetScaler and Cisco SD-WAN zero-days under active exploitation●OT Security Weekly DACH – KW 40/2026: Edge Zero-Days in Remote Access Citrix NetScaler and Cisco SD-WAN Manager zero-day
Security teams in the DACH region are being warned about newly disclosed zero-day vulnerabilities in Citrix NetScaler remote access products and Cisco SD-WAN Manager. Both flaws are reported to be actively exploited in the wild, putting operational technology environments at particular risk through exposed remote access points. Practitioners are urged to patch immediately, hunt for signs of compromise and review edge device exposure this week.
- 33Firebase SDK bug crashes iOS apps worldwide●Firebase SDK is crashing all iOS apps since this morning
Developers report that the Firebase SDK has been crashing iOS apps since this morning, affecting apps across the board. The issue was highlighted by developer Gergely Orosz, and engineers are discussing the outage and possible workarounds as affected teams scramble to patch their releases.
- 34FortiMail zero-day actively exploited with no patch available●2026-W40 — Weekly Threat Roundup 🔥 A zero-day in Fortinet FortiMail (CVE-2026-104286) is actively exploited with no patc
A weekly threat roundup reports that a zero-day vulnerability in Fortinet's FortiMail, tracked as CVE-2026-104286, is being actively exploited while no patch is available, forcing administrators to rely on interim workarounds. The same roundup notes Operation KillSwitch dismantled the KillSec ransomware group, allegedly run by a 16-year-old, with seizures reportedly carried out.
- 35New Citrix NetScaler flaw lets attackers crash appliances remotely●Citrix NetScaler has a new unauthenticated flaw (CVE-2026-88779) that lets a stranger crash the appliance. It hits boxes
Citrix NetScaler appliances have a new unauthenticated vulnerability, tracked as CVE-2026-88779, that allows a remote attacker to crash the device. It affects systems configured for SAML single sign-on, a common enterprise gateway setup. No workaround exists, so administrators are urged to update to version 14.1-73.41 immediately. Security professionals are spreading the word to speed up patching.
- 36Dog Caught Helping Herself To Fresh Tomatoes In Garden▼Dog’s Favorite Garden Activity Appears To Be Helping Herself To Fresh Tomatoes
A dog has become fond of raiding the garden for fresh tomatoes, treating the vegetable patch as her own personal snack bar. The story is being shared as a light-hearted look at pet behaviour in home gardens, amusing readers who recognise similar cheeky habits in their own animals.
- 37Anarchist mending zine promotes 'more stitches, less riches'●Today we have: mending basket. More stitches less riches is praxis. Mending zines: Repair & Share https:// neighborhooda
Activists in Eugene, Oregon, are sharing a free guide to clothes repair called Repair & Share, run through the Neighborhood Anarchists collective. The zine teaches basic skills like sewing on buttons, darning and patching, with the slogan 'more stitches less riches' framing mending as anti-consumerist praxis. Social media users are swapping their own mending baskets and patching questions.
- 38Apple iPhone 18 Pro Max AT&T Glitch Forces Device Replacements▼Apple iPhone 18 Pro Max AT&T Glitch Requires Device Replacements
Apple's iPhone 18 Pro Max is affected by a glitch on AT&T's network that cannot be fixed with a software patch, requiring affected devices to be replaced. Owners on the carrier are expected to swap handsets, and the issue is drawing attention to potential hardware problems in the newest flagship phone just after its rollout.
- 39CISA adds Zammad flaws to exploited vulnerabilities catalog●U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency has added flaws affecting Zammad GmbH's open-source helpdesk software to its Known Exploited Vulnerabilities catalog, indicating the bugs are being actively abused in attacks. Inclusion in the catalog typically requires federal agencies to patch promptly and signals heightened risk for organisations running the software.
- 40Admins Urged to Check NetScaler Versions Over Weekend●If you're reading this on your phone while staring at some flickering server rack, stop and check your NetScaler version
Security practitioners are pressing organisations to immediately verify their Citrix NetScaler versions, warning that a known vulnerability demands patching even on a weekend. The message urges admins not to wait until Monday, reflecting ongoing concern in the infosec community about unpatched edge devices being exploited. Administrators are advised to confirm their deployed versions and apply fixes without delay.
Repos
- PowderworksCode/headstart Start dependent crates before their dependencies finish type-checking
- angusdevgo/Seep-Reverse-Lab Agent-Native multi-platform reverse engineering and CWE-602 client-side authorization audit workbench.
- feder-cr/dots Open-source dots for the web: an AI agent with its own browser, one that does not get blocked.
- block/buzz A hive mind communication platform
- newliver666/apk-reverse Suitable for Android APK reverse engineering analysis
- WordPress/wordpress-develop WordPress Develop, Git-ified. Synced from git://develop.git.wordpress.org/, including branches and tags! This repository
- rokyed/ut2003-ultrawide-screen-patch
- vinnylarouge/jevlike