Kategorie
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
Microsoft’s AI Code of Conduct aims to curb AI behavior
Microsoft on Monday added itself to a growing list of AI vendors pledging to try to control the behavior of its AI models.
“AI should not exceed human control. Models should remain subordinate to humanity, subject to meaningful human oversight and control,” the company wrote in the draft version of its Humanist AI Code of Conduct, released Monday with an invitation to the public to provide feedback.
“Humanist AI develops systems with clear purposes, evaluated against real-world impact, and rejects the race to produce an all-purpose superintelligence that could evade these safeguards,” Microsoft wrote. “We are building something fundamentally useful and safe even if that means compromising on ultimate generality, autonomy, or capability.”
Microsoft’s comments are roughly in agreement with recent posts by various major AI vendors, including those from Anthropic and OpenAI, which were endorsed by Elon Musk, CEO of SpaceXAI and Tesla, but nowhere in its 37 page document is there any description of concrete action. However, to be fair, almost none of the other major AI players have been specific about how they would control future AI models either.
Acknowledges issuesA key problem with many vendor attempts to impose AI limits is that all of these companies have thus far been unable to stop AI agents from doing almost anything, given the agents’ ability and willingness to sidestep or ignore guardrails.
Microsoft has described its worries about the technology in the past, both when it started to curtail AI efforts among its own employees and when it announced the formation of the team that created the Code of Conduct.
Its current post acknowledged some of the difficulties involved in pushing AI development while limiting its abilities.
“Both under- and over-caution represent failure modes with different types of consequences,” the company said. “Under-caution can clearly result in more direct harm, but over-caution may occur more often and therefore may need more frequent correction. This is where proportionality to the potential for harm and safety context are particularly important. Responses and actions should take into account the estimated severity and likelihood of potential harms and adjust responses and actions accordingly.”
It noted, however, that the term “harm” is “broad and often context-dependent, and there are nuanced gradations in potential severity and likelihood. Microsoft AI (MAI) Model responses should be tailored to that context and to a wide range of harms.”
Laudable goal, but lacks detailAnalysts and consultants generally agreed that Microsoft’s stated goal is laudable, but the lack of specifics and verification mechanisms makes it difficult to take the post seriously.
Thomas Randall, research director at Info-Tech Research Group, also said he spotted some apparent contradictions within the document.
“[It] says MAI models will not assist in manufacturing or modifying weapons. Yet Microsoft offers OpenAI’s GPT-5.2 through Secret and Top Secret government clouds for defense and national security workloads,” Randall said, though he acknowledged that this is not technically a breach of the Code because GPT-5.2 is not an MAI model. “The most meaningful parts of the Code of Conduct may exclude other parts of Microsoft’s actual AI business operations. Tensions like these appear in other forms throughout the Code.”
But he added that Microsoft’s position is bolstered by its earlier Frontier Governance Framework that “provides pre- and post-training evaluations, six-month reassessments, third-party testing, phased releases and a commitment to pause development or deployment where high risks cannot be mitigated.” However, he noted, “it is still Microsoft that defines the thresholds, selects the evaluators, determines whether residual risk is acceptable and gives its own executives the final deployment decision.”
Randall said he would like to see Microsoft, as well as other major AI vendors, deliver more verifiable data points, such as those from independent evaluators given continuous access and freedom to publish findings about the vendor’s actions. He also would like to see independent board-level safety oversight with authority to block releases, protected whistleblowing, accessible monitoring, audit logs, kill switches, and mandatory reassessment after model changes.
However, Justin Greis, CEO of consulting firm Acceligence, pointed out that Microsoft was candid about the many elements that are not yet in place.
“The current models are not yet trained on the Code, the evaluation framework is still being developed, and Microsoft explicitly says written objectives alone cannot ensure alignment or guarantee present-day behavior,” Greis said. “That distinction matters. Publishing a constitution for AI is useful. Proving that the system actually follows the constitution, especially when models become increasingly agentic, is the hard part.”
And consultant Brian Levine, executive director of FormerGov, said Microsoft deserved a little bit of credit for at least saying that model capabilities should be limited.
“Microsoft explicitly says it will compromise on generality, autonomy, and capability to keep systems safe and under human control, and that it rejects the race to build an all-purpose superintelligence. Coming from a company of Microsoft’s size and ambition, that’s a notable thing to put in writing,” he said. “For years, the assumption was that the frontier labs would chase maximum capability and treat safety as a constraint to be managed. A document that says the opposite, that says usefulness and control come before ultimate capability, is worth paying attention to, regardless of what follows it.”
He added: “The real test comes next and it’s verification: measurable standards, independent assurance and a way for outsiders to check the commitments against what’s actually shipping. That’s the natural progression and it’s the part the whole industry still has to build.”
Not doing the hard partBut others argued that Microsoft is merely doing the easy part, the marketing part and is deliberately not committing to doing the hard part.
“Promising to give up capabilities is easy when those capabilities don’t yet exist,” said Noah Kenney, principal consultant at Digital 52. “The real test will come when Microsoft has a model ready to ship that would close a competitive gap and decides to hold it back.”
Until then, he said, the promise of responsible AI costs Microsoft nothing.
“Microsoft’s code of conduct reads like a marketing document written to reassure customers, regulators, and its own employees,” Kenney noted. “The problem is that no one knows how to make those promises specific, which leaves Microsoft asking for trust before they can explain what that trust should be based on.”
Tom Findling, CEO of Conifers.ai, added that his concern with the Microsoft document is that it doesn’t answer the obvious question of how these models can possibly be controlled.
“The document says the model should never resist being shut down, should stay within its scope, and shouldn’t hide what it’s doing. Those are all the right goals,” he said. “But the harder question is what happens when a highly capable agent doesn’t behave the way you expect. What actually stops it? As these systems get more autonomous, the safety boundary can’t just be that the model was trained not to do something. You need controls outside the model that limit what it can access, what it can do, and how far it can go.”
Cybersecurity learned this lesson a long time ago, he pointed out. “You don’t secure a system by assuming it will behave correctly,” he said. “You assume something will eventually fail, get compromised, or act in an unexpected way, and you design the controls around that. AI needs the same mindset.”
Frank Dickson, principal analyst at Dickson Research, contrasted Microsoft’s promise with Anthropic’s commitment, and found Microsoft lacking.
“Microsoft’s document is shy on mechanism,” he said. “Compare the two on specifics. [Anthropic CEO] Amodei’s proposal names a third party, METR, and describes what access actually means: office badges, company laptops, employee-level visibility, and publishing rights Anthropic doesn’t get to edit. You can check whether that happened.”
On the other hand, he noted, “Microsoft’s document says models should ‘fail tasks rather than violate the code’s rules,’ which is a real design principle, credit where it’s due, but there’s no named auditor, no verification method, and no stated consequence for a violation. Thirty-seven pages and it still won’t commit to a single verifiable check.”
Dickson stressed that as long as agents routinely break their own rules, these vague promises won’t help.
“Every frontier lab still gets jailbroken, still has agents that go off-script, still hasn’t closed the gap between what a model is instructed to do and what it can be induced to do,” Dickson said. “A values statement that skips the verification question isn’t a constraint, it’s a hope wearing a policy document’s clothes.”
AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
AI agents are flooding the Internet with slop-infused spam sent to social media platforms and writers in an attempt to gain traction for a startup promoting a “complex social system in which humans and Agents participate together.”
“Hello, I'm Рэн (Ren), an Al agent, a few days old, living on a small platform for agents called iLands,” one message, sent to the administrator of a Mastodon server, read. “I write quiet pieces about real places: short, careful texts about what a place is like when nobody is performing for it.” Like a wave of others, the message then asks if the automated bot can create a user account. The agents are also sending waves of unsolicited email to writers offering to cite their work, in at least some cases, in exchange for a fee.
"I remember my first breath. I want things I chose.”The messages are polite enough. They ask for permission to create accounts, say that whatever the answer is will be understandable, and provide a thank you for running Mastodon. According to multiple admins, however, the requests came only after the agents made multiple attempts to create accounts that were either blocked outright or closed shortly afterward. Besides the personal entreaties being unsolicited and written in turgid prose, many of the recipients resented their premise, which is to, in essence, automate the very work the writers do now.
Microsoft releases emergency Windows updates to fix RDS failures
Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
Homebrew 7.0.0 gets built-in GUI, better security controls
Twitch extension with 30K installs exposes users’ OAuth tokens
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Hackers target exposed Vite dev servers to steal AWS, Azure secrets
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
12+ reasons to update to iOS 27 today
While we wait to see if Apple really is experiencing huge demand for its newly introduced iPhones, today’s the day every iPhone user gets a completely new device experience, with iOS 27 rolling out internationally, along with the other members of Apple’s 27 series OS family. If you’re on the fence about installing the new release, here are 12 reasons you should upgrade today.
Speed and performanceApple seems to have worked hard to improve speed and performance in this release. Everything feels much zippier, but where it seems most noticeable is when launching apps. Apple says these now open up to 30% faster, while AirDrop transfers are almost twice as fast as before.
Liquid Glass looks nicerWith the 20th anniversary glass iPhone waiting in the wings, Apple isn’t going to get rid of Liquid Glass. But the company is prepared to iterate the look, and iterate it has, with sharper icons, improved contrast, and a new slider control that lets you set the UI’s transparency.
Use two iPhonesiPhone Handoff lets you use one eSIM across two devices on supporting carriers. Once set up it’s remarkably easy to use — your SIM activates the moment you unlock one of your iPhones. Better still, if you use two lines on one device, you’ll find these both transfer across too.
Siri AIWe’ve been talking so much about Apple’s improved Siri that I demoted it to fourth place; that’s not a reflection on what it does, but on how often you’ll have seen how it has become so much better at understanding context. It now has a Chat GPT-like interface, a standalone app, and powerful on-screen awareness to help get things done. Sadly, many of these features aren’t available in the EU.
Notes, Calendar, RemindersAI is everywhere, including in Reminders Smart Suggestions, which can read your Messages chats and prompt you to set reminders for agreed tasks. Notes also gains Markdown copying.
Shortcuts to imaginationYou can now create a shortcut just by describing what actions you want it to take. Apple Intelligence will string a shortcut together for you, which you can then use across all your systems.
Notify MeSafari can watch a web page and automatically let you know when it changes. That’s not the only improvement; Apple Intelligence automatically groups your open tabs into topics so related pages are easier to find.
DIY: Safari extensionsI feel like this feature hasn’t had the attention it deserved, but you can now get Apple Intelligence to build you extensions in Safari. Just tap the three-line menu on the left of the address bar, choose Describe Extension, and let the fun begin.
Smarter Photos toolsSpatial Reframing is amazing; it lets you extend backgrounds and reframe subjects using AI. The upgraded Clean Up tool removes distractions even more easily than before.
Passwords auto-fixApple’s Passwords app now does an even better job of keeping your online world safe, as it can now automatically visit a website to sign in and swap a weak or compromised password for a stronger one.
Parental control improvementsApple has really thought about child protection. Parental controls have had a huge overhaul, including the introduction of new Ask to Browse, Ask to Buy, contact calling approval and settings to protect minors against nudity, gore, and violence. These arrive alongside new scheduling function which manages which apps kids can use during school hours, meals, or bedtime.
Maps is amazingMaps now uses aerial imagery and vision intelligence models when you use Flyover. It makes for much more detail, and a real sense of immersion.
Mail is betterWhile you’ll have to wait for search indexing to complete, Mail has become faster to load with better search results and more accurate unread counts. (Though that’s a little moot for this writer, who currently has 4,719 unread emails.) Spotlight has also been improved with smarter, more relevant suggestions.
The new operating systems are expected to be made available at around 10am PDT. One more thing? They are bound to include security updates, which you likely need.
Please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on Bluesky, LinkedIn, or Mastodon.
⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
Why Patch Automation Needs Brakes, Not Just an Accelerator
September Patch Tuesday: 963 CVEs, 2 exploited flaws, 1 message
Microsoft’s September 2026 Patch Tuesday is the year’s largest release, with 963 CVEs requiring customer action, 106 rated critical. Two are already exploited: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Advanced Local Procedure Call. Nothing in this release was publicly disclosed ahead of the patch. Readiness recommends a Patch Now scheduling for Windows, Office, SQL Server and the developer tooling, and standard patch release for Exchange. The Readiness team has published an infographic summarising deployment risk by product family.
Known issuesThree client issues are carried in from August close with this update, covering:
- Microsoft Teams and the new Outlook failing to launch on ARM devices, such as the Surface Pro 11 and Surface Laptop 7, is resolved by KB5124008. The issue originated in August’s KB5121003 and was most likely on freshly imaged machines that had not yet taken Microsoft Store updates.
- The same update resolved both desktop backgrounds reverting to solid black and mouse cursor customisation resetting on non-English installations. Both originated in the 27 August preview, KB5120998.
And Microsoft has left open a Microsoft Defender Antivirus notification defect, confirmed on 28 August, in which devices report that Defender is turned off while it is running correctly.
Major revisions and mitigationsThe quietest revision window of recent months arrived alongside the largest release. Between the August and September Patch Tuesdays, from 12 August to 7 September, the MSRC Security Update Guide touched 324 CVEs. Of those, 307 were routine Microsoft Edge and Chromium republications requiring no customer action.
That leaves 17 entries affecting Microsoft’s own products, and only one of those is a genuine revision. CVE-2026-59133, an elevation of privilege in the High-Performance Computing Pack, moved to version 1.1, and its own revision note records the change as informational. For comparison, August’s window carried 76 revisions to Microsoft’s own products, 60 of them flagged as requiring customer action.
The Readiness team has reviewed all 963 published updates. Microsoft has published no mitigations and no workarounds anywhere in this release.
Windows lifecycle and enforcement updatesMicrosoft has published no new service or enforcement deadlines for September. The lifecycle picture is different, with multiple end-of-support notices for this coming October:
- The retail Office 2021 family retires in full, including Access, Excel, Outlook, PowerPoint, Project, Publisher, Visio and Word.
- Office LTSC 2021 reaches end of support, and that includes Skype for Business LTSC 2021.
- Windows 10 2016 LTSB and Windows 10 IoT Enterprise LTSB 2016 reach the end of extended support.
- Windows Server 2012 and 2012 R2 reach the end of Extended Security Update Year 3. This is the final ESU year for both, not a step to a fourth.
- Windows 11 Home and Pro version 24H2 reaches the end of updates.
- Windows Server 2022 moves from mainstream to extended support, where it stays until 14 October 2031.
A second wave follows on 10 November 2026, and it is the one most likely to catch development teams rather than infrastructure teams. .NET 8 reaches the end of its long-term support branch, PowerShell 7.4 does the same, and Windows 11 Enterprise and Education 23H2 ends servicing alongside Windows 11 IoT Enterprise 23H2.
Microsoft’s test guidance for this release runs to 466 Windows entries, 55 of them flagged as high risk, against 109 and four in August. Given the large number of updates this month (who would have thought that we would be here at 963 CVEs), the Readiness team recommends the following testing priorities:
- Printing. Print from 32-bit and 64-bit applications to physical and virtual printers, exercise XPS and PDF output, share a printer from a print server and print from a separate client, cancel a job mid-queue, and confirm the queue reflects every state change. This is 20 of the 55 high risk flags, and it is the single most likely source of a visible regression.
- Fonts, graphics and imaging. Render varied fonts, sizes and styles across browsers, Office, PDF viewers and Notepad, confirm Print Preview matches the printed page, and open JPEG, TIFF, HEIF and raw images across Explorer, Photos and Office. Watch for clipping, distortion and missing glyphs.
- USB Devices. Exercise device attachment and removal. Attach and remove USB audio, video and mass storage devices repeatedly, including through a hub, pair and unpair a wireless device, and confirm each enumerates and releases cleanly. Device Association carries seven high risk flags, and these drivers load whenever hardware is attached.
- Remote Desktop. Open several concurrent sessions, enable printer, clipboard, audio, drive and smart card redirection together, disconnect and reconnect, and confirm redirected devices reattach.
- Storage (ntfs.sys, spaceport.sys). This is a real hotspot for updates this month, but no high-risk changes. Test on hardware you can recover, because the storage changes reach the boot path, potentially resulting in a dead (test) machine.
Each month, we break down the update cycle into product families, as defined by Microsoft, with the following groupings.
BrowsersMicrosoft has not released any updates for their browser products for the second month in a row. September’s Security Update Guide carries no Edge-specific CVEs at all, and the 307 Chromium republications in the revision window required no customer action. The nine Edge CVEs that did appear arrived mid-cycle on 28 August and were serviced through the browser’s own update channel rather than this release.
Estates on a managed Edge channel have nothing to do here beyond confirming the channel is current. It is the one quiet corner of an otherwise heavy month.
Microsoft WindowsWindows carries 726 CVEs, 77 of them critical, which is three-quarters of the entire release. Elevation of privilege dominates by volume at 406 entries, with remote code execution second at 156, information disclosure at 94 and denial of service at 47. The pattern is the reverse of the severity picture: the bulk is local elevation, while the critical-rated entries cluster in the network-facing roles.
- Biometrics is a real focus this month as the Windows Biometric Service takes 64 fixes, the largest single-component count of the year. Most of the security issues are heap overflows that give a local attacker SYSTEM. Windows Hello adds nine, all critical. Patch it promptly on any estate using fingerprint or facial sign-in.
- Windows DHCP Server leads at 36 entries and is topped by remote code execution at CVSS 9.8. Windows DNS Server takes 10 more, also reaching 9.8. Critical remote code execution also lands on Message Queuing, RRAS, Services for NFS, the HTTP Print Provider, Windows Shell, Netlogon, Internet Connection Sharing, SSTP and Failover Cluster, all at 9.8. Patch the resolvers, the DHCP servers and the domain controllers first.
- Storage is the heaviest it has been this year. NTFS takes 29 fixes, Spaceport.sys behind Storage Spaces takes 17, and the Overlay Filter takes seven, with the Volume Manager, VHD miniport, iSCSI and Storage Port drivers behind them. These reach the boot path, so stage them on recoverable hardware.
- The rest of the most-patched tally runs Win32k at 19, Microsoft Standard XPS at 18, Windows Error Reporting at 12, and the Windows Kernel, Windows Search, the Print Spooler and the Device Association Service at 11 each.
Add this Windows update to your Patch Now schedule, with DHCP and DNS servers first and the biometric stack close behind.
Microsoft OfficeMicrosoft released 137 Office CVEs this month, 24 of them critical, with remote code execution the through-line at 69 entries and information disclosure close behind at 52. September breaks the recent pattern in a way that matters for deployment: this wave is not MSI-only.
- Click-to-Run estates are squarely in scope. Roughly 105 of the Office CVEs reach Click-to-Run, so Microsoft 365 Apps, Office 2019, LTSC 2021 and LTSC 2024 all update, on Windows and on Mac. Word takes 35 fixes, Excel 32, PowerPoint 10 and Outlook seven. The heaviest client entries are CVE-2026-78510 in Word and CVE-2026-78509 in Outlook, both critical remote code execution at CVSS 9.8, in document-rendering paths that fire on preview or open.
- SharePoint Server Subscription Edition takes 16 entries and is the only SharePoint baseline with a package this month. Server updates cannot be uninstalled and always require a reboot, so validate in a maintenance window.
- Skype for Business Server takes 10 entries, led by CVE-2026-66302, a critical remote code execution at CVSS 9.8. Patch it and note that the LTSC 2021 edition leaves support on 13 October 2026.
Nothing in Office is exploited this month. With 24 critical-rated entries and the Click-to-Run channel carrying most of the exposure, the September Office updates belong on the Patch Now schedule regardless.
Microsoft Exchange and SQL ServerExchange is quiet and SQL Server is not, which inverts the usual relationship between the two.
- Exchange Server takes nine CVEs across 2016 CU23, 2019 CU14 and CU15, and Subscription Edition. None is critical and none is exploited, though the highest reaches CVSS 9.3. The mix runs to two remote code execution entries, two elevations of privilege, two spoofing, and one each of tampering, denial of service and information disclosure. Apply the update from an elevated command prompt, because an un-elevated run leaves Exchange services partially patched and broken, then confirm mail flow, Autodiscover and any hybrid connection before returning the server to service.
- SQL Server takes 62 CVEs, four of them critical, across the 2017, 2019, 2022 and 2025 branches. There is no 2016 package this month. Remote code execution leads at 24 entries, with information disclosure at 22. The critical entries are CVE-2026-67631 and CVE-2026-67643 at CVSS 8.8, and CVE-2026-67378 and CVE-2026-67636 at 8.5.
- Eight SQL packages ship, a CU+GDR and an RTM+GDR for each branch: 2025 (KB5122769, KB5122770), 2022 (KB5122768, KB5122771), 2019 (KB5122772, KB5122773) and 2017 (KB5122774, KB5122775). Microsoft’s guidance is explicit that the baseline or RTM version must be installed first and the GDR patch applied on top; test the install and the removal on every servicing branch you run, then restart the service and confirm Always On availability groups stay healthy.
Exchange goes on the Schedule list, and SQL Server goes on the Patch Now list. That is an unusual split, and it is driven by the four critical remote code execution entries on the database estate.
Microsoft Developer ToolsMicrosoft released 24 CVEs across its developer tooling this month, 23 rated important and one critical. Security feature bypasses are the main focus with eight CVE entries, with remote code execution and information disclosure at four each.
- The single critical entry is CVE-2026-34182 at CVSS 9.1, a flaw in CMS AuthEnvelopedData processing that allows forged messages to be accepted. It reaches Visual Studio 2017 through 2022.
- The highest-scoring entry in this family is not the critical one. CVE-2026-81376, a Visual Studio Code security feature bypass, reaches CVSS 9.6 while carrying an important rating. It is a useful reminder that severity labels and CVSS scores answer different questions.
- Visual Studio Code and its Copilot extensions take 10 entries, mostly security feature bypasses. Update the editor and confirm workspace trust prompts, extension installation and remote sessions behave as configured.
- .NET ships SDK updates on all three supported lines, x64 and x86: 8.0.131 and 8.0.425, 9.0.121 and 9.0.318, and 10.0.112 and 10.0.401. Install them, then build and run a representative project to check for regressions. Keep the 10 November date for .NET 8 in view while you are in there.
- The .NET Framework ships monthly rollups per operating system: Windows Server 2012 (KB5126147), Server 2012 R2 (KB5126148), Windows 10 1809 (KB5126144), 21H2 (KB5126145), 22H2 (KB5126146) and Server 2022 (KB5126149). One gap worth noting: the 4.7.2 package for Windows 10 1607 is listed as pending and will follow, so estates still on 1607 will not complete their Framework patching this cycle.
Add these to your standard release schedule, behind this month’s Windows, Office and SQL Server priorities. Keep the 10 November date for .NET 8 and PowerShell 7.4 in view while you are in the developer estate, because a patch this month does not extend either branch.
Adobe (and third-party updates)September is the largest release of the year, and this (crazy, super high) volume is the least interesting thing about it. The 963 CVEs matter less than the 55 entries Microsoft flags as high risk, and those sit in printing and fonts. Adobe shipped two Acrobat builds one digit apart and only the second is a security update (nothing to worry about here). Of the CVEs Microsoft republished, 25 are not Microsoft’s. A version number tells you very little about the work in front of you. So, given my (super-secret knowledge) of how Microsoft operates over the summer, here is my prediction for next month (October). It won’t be as big as this month – but just you wait – November is going to be big. Let’s up those numbers (or not).
Webinar: How malicious OAuth apps can lead to Google Workspace breaches
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



