Visualização normal

Hoje — 11 de Setembro de 2026cybersecurity
  • ✇cybersecurity
  • Microsoft finally patched that bug that was nuking people's desktop backgrounds /u/whocybergh0st
    So if you've been dealing with your wallpaper randomly turning into a plain black screen since late August, turns out it wasn't just you. A bunch of people got hit with this after installing that KB5120998 preview update on Windows 11 24H2/25H2 desktop settings would just fail to load properly and default to black no matter what you tried. Manually resetting your background didn't even fix it because the setting itself wasn't loading correctly in the first place. Same update also messed with mou
     

Microsoft finally patched that bug that was nuking people's desktop backgrounds

10 de Setembro de 2026, 19:50

So if you've been dealing with your wallpaper randomly turning into a plain black screen since late August, turns out it wasn't just you. A bunch of people got hit with this after installing that KB5120998 preview update on Windows 11 24H2/25H2 desktop settings would just fail to load properly and default to black no matter what you tried. Manually resetting your background didn't even fix it because the setting itself wasn't loading correctly in the first place.
Same update also messed with mouse settings for some folks, and once that got reset there was apparently no way to get your old config back either. Rough couple weeks if you got hit by both.
Good news is this week's Patch Tuesday update (KB5124008) apparently fixes it for good. If you're still seeing the black wallpaper issue, just grab the latest cumulative update and it should sort itself out.
Kind of funny that this isn't even a new problem for MS they had almost the exact same wallpaper bug back in 2020 with a Windows 7 update. You'd think they'd have learned by now lol.
Anyway if your desktop's been looking sad and empty lately, this is why. Go update.

submitted by /u/whocybergh0st
[link] [comments]
Ontem — 10 de Setembro de 2026cybersecurity
  • ✇cybersecurity
  • Cisco confirms max-severity FMC bug (CVE-2026-20079) is being exploited in the wild /u/whocybergh0st
    CVSS 10.0, unauthenticated auth bypass in Cisco Secure FMC. Attacker sends a crafted HTTP request to the web interface → gets root. No login needed. Disclosed back in March as "no known exploitation." That changed — Cisco confirmed this week (Sept 9) that PSIRT saw active exploitation starting in August. No workarounds exist. Patching is the only fix. CISA added it to KEV — federal agencies must patch by Sept 12. The sketchy part: back in July, Cisco disclosed a different FMC bug (static credent
     

Cisco confirms max-severity FMC bug (CVE-2026-20079) is being exploited in the wild

9 de Setembro de 2026, 18:44

CVSS 10.0, unauthenticated auth bypass in Cisco Secure FMC. Attacker sends a crafted HTTP request to the web interface → gets root. No login needed.

Disclosed back in March as "no known exploitation." That changed — Cisco confirmed this week (Sept 9) that PSIRT saw active exploitation starting in August.

No workarounds exist. Patching is the only fix.

CISA added it to KEV — federal agencies must patch by Sept 12.

The sketchy part: back in July, Cisco disclosed a different FMC bug (static credentials, CVE-2026-20316) that was also being exploited, and quietly added the same indicators of compromise to the 20079 advisory too without confirming 20079 itself was hit. The IOC log example they published is dated July 23, weeks before Cisco says it "became aware" of 20079 exploitation in August. When asked to clarify the connection, Cisco didn't really answer.
Bottom line: if you run Secure FMC, patch now, and check /var/log/messages for activity tied to /var/tmp/license.tmp — even if you already patched, since a hotfix stops future attacks but doesn't undo an already-compromised box.

submitted by /u/whocybergh0st
[link] [comments]

Skullcandy Dime 3 earbuds will pair with strangers' devices automatically and there's no way to patch them

10 de Setembro de 2026, 00:08

CERT/CC put out a warning on this one. Skullcandy Dime 3 earbuds (model S2DCW) running firmware 1.0.0.28 will accept a Bluetooth pairing request from any nearby device with no PIN, no physical access, and no approval prompt.
It's CVE-2025-20701, a flaw in the Airoha Bluetooth Audio SDK used across a bunch of earbud brands (same bug affected Beats Studio Buds, fixed by Apple back in June).

Once an attacker's device pairs, it gets trusted status and can auto-reconnect whenever it's in range letting them hijack your audio, kick you off, and pull live mic audio.

You might get a "new device paired" notification, but it's easy to mistake for a random disconnect/reconnect blip.

The rough part: Skullcandy did fix it in firmware 1.0.0.30, but there is currently no way for users to update their earbuds not manually, not through the app. So if you bought a Dime 3 with the vulnerable firmware, you're stuck on it.
Basically these things are wide open to close-range hijacking/eavesdropping with no fix in sight for existing units. If you own a pair, worth checking your firmware version and maybe not trusting the mic for anything sensitive until Skullcandy sorts out an update path.

submitted by /u/whocybergh0st
[link] [comments]
❌
❌