Microsoft
- CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi object
- CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
- CVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
- CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
- CVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
- CVE-2026-64567 btrfs: reject free space cache with more entries than pages
- CVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
- CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error path
- CVE-2026-64573 Bluetooth: qca: fix NVM tag length underflow in TLV parser
- CVE-2026-64574 wifi: mac80211: tear down new links on vif update error path
Graham Cluley
- Beware cut-price AI services that read your every word
- Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
- Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
- Fake IRS letters target cryptocurrency holders
- The $5 million threat: AI Is supercharging phishing attacks