
KB5124008 update may break Windows 11 domain trust
Microsoft is investigating reports that the Windows 11 KB5124008 update can sever Active Directory trust on some Enterprise devices.
Deep-dive analysis, hands-on tutorials, and cutting-edge threat intelligence from industry practitioners.

Microsoft is investigating reports that the Windows 11 KB5124008 update can sever Active Directory trust on some Enterprise devices.

A threat actor leveraged ownCloud CVE‑2023‑49105 to steal 176 files—including nuclear‑material records—from two Philippine organizations, prompting CISA to add the flaw to its KEV catalog.

Android 17 adds default ECH support, mandatory Certificate Transparency, local‑network permission prompts, and carrier‑controlled 2G shutdown, reshaping mobile privacy.

PaperCut confirms attackers are weaponizing two critical CVEs (CVE‑2026‑82078, CVE‑2026‑81578) and has issued a second patch after the first proved insufficient.

Two high‑severity bugs in PaperCut NG/MF (CVE‑2026‑81578, CVE‑2026‑82078) prompted emergency patches; early reports suggest they could be chained for unauthenticated code execution.

A deserialization bug (CVE‑2026‑82222) in GiveWP up to v4.16.7.1 lets attackers run system commands on the host, even when WordPress registration is disabled.

Omdia analyst Theresa Lanowitz warns that autonomous AI tools can accelerate red‑team work but also introduce new safety and audit challenges.