Security
Primary-source computer news with the consequences attached.
CISA gives exploited MikroTik flaws a three-day patch clock
CISA added two exploited RouterOS flaws with a September 13 deadline; exposed SSH and bandwidth-test services need updates and compromise checks.
CISA puts four exploited edge and browser flaws on urgent clocks
CISA added exploited flaws in Cisco FMC, NetScaler, Fortinet appliances, and Chromium V8; three carry September 12 federal remediation dates.
Microsoft patches two Windows privilege flaws under attack
Microsoft says two local Windows privilege flaws are being exploited; September updates close paths from low privileges to SYSTEM access.
Cloudflare makes post-quantum origin TLS automatic
Cloudflare now scans TLS 1.3 origins and prefers hybrid post-quantum key exchange by default, reducing retries in its rollout while leaving important limits.
Google tells Slurm clusters to rebuild for an sbcast flaw
Google says Cluster Toolkit nodes not recreated since September 7 remain vulnerable to a high-severity Slurm sbcast flaw that can bypass checks and crash nodes.
CISA adds an exploited Chrome V8 flaw to its deadline list
CISA added the actively exploited Chromium V8 flaw CVE-2026-85046 to its catalog, setting a September 18 remediation deadline after Google shipped a Chrome fix.
Google’s HEIR compiler makes private AI less theoretical
An open-source compiler brings homomorphic-encryption workloads closer to ordinary machine-learning toolchains.
Red teams are preparing for attacks that operate at machine speed
Google says agentic systems change both offensive automation and the way defenders must test authorization boundaries.