August .NET Update Breaks WPF Printing
Printing and PDF export fail in some WPF apps after August 2026 .NET updates; Microsoft offers a risky workaround.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
Printing and PDF export fail in some WPF apps after August 2026 .NET updates; Microsoft offers a risky workaround.
CVE-2026-18963 allows full account takeover via reset flow; patches out.
Dutch regulators fine Uber $964M for automated driver account suspensions without human review.
A China-nexus espionage campaign targets Myanmar government and IT sectors via graduation invites, deploying QUICAgent.
Broadcom patches 91 Spring vulnerabilities, with one critical flaw exposing LDAP servers to attack.
Experts warn of resilience gaps after Iranian hackers disable a UK power plant for days.
Supply-chain attack on Android car head units turns them into proxy nodes and ad fraud tools.
Attackers target Windows named pipes; developers must verify identities, permissions, and data.
ToxicPanda 2.0 uses VPN permissions to block Google Play, adding 167 commands and targeting 349 apps.
Manic, Grandoreiro, and ToxicPanda 2.0 show how banking malware is becoming more sophisticated.
Flock Safety CEO urges privacy-safety compromise as misuse reports mount and lawmakers on both sides push back.
Researchers show how Windows' own BTR.sys can delete security software at boot, evading blocks.
TikTok will pay $400 million to resolve U.S. child privacy claims, marking one of the largest COPPA recoveries.
A new study finds leading AI labs lack clear public plans for containing rogue models, even as regulators push for disclosure.
Researchers uncover 14 malicious npm packages delivering RedC2 4.0, an AI-assisted Linux backdoor, via stealthy loader.
Waymo has responded to NHTSA's questions about a January crash where a robotaxi struck a child, but the documents are redacted.
Retired Gen. Paul Nakasone launches Nakasone Group, a boutique advisory firm for high-profile clients facing cyber and geopolitical threats.
SecurityWeek’s weekly roundup covers a Ray bug, Threema DDoS, T-Mobile’s cable cut, Evooo1Bot, and more.
Wazuh adds AI-powered analyst tools and integrations to ease security operations workload.
GitLab's CVE-2026-19478 is under active exploitation, days after disclosure, urging immediate patching.