Articles from February 2026
Browse all Windows news articles published in February 2026
Unpatched Mbed TLS Devices Leave Decrypted Data Exposed in Memory—Here’s How to Clean Up
A bug in the widely used Mbed TLS encryption library fails to scrub decrypted plaintext from memory after certain read operations, potentially exposing session tokens, passwords, and other secrets to...
Unchecked Diffie-Hellman Parameters Can Brick Mbed TLS Devices — The Fix Is a Simple Update
A vulnerability in the widely used Mbed TLS cryptographic library allows attackers to remotely freeze or crash connected devices by feeding them oversized Diffie-Hellman key exchange parameters. The...
Mbed TLS 2.24.0 Patches Hostname Spoofing Hole That Leverages Crafted IP Certificates
In August 2020, the maintainers of the widely embedded Mbed TLS library released version 2.24.0 to fix a certificate validation flaw that could allow an attacker to impersonate any domain name by...
Attackers Can Crash Your Go Apps with a Crafted Number – What to Do About CVE-2021-33198
A dangerous parsing bug in Go’s standard math/big package can let unauthenticated attackers remotely crash any service that feeds untrusted numeric text into (*big.Rat).SetString or UnmarshalText....
Azure Linux CVE-2021-33195: Microsoft's Limited Attestation & Go DNS Vulnerability Risks
Microsoft's recent security advisory regarding Azure Linux and CVE-2021-33195 has sparked significant discussion in the security community, revealing important nuances about vulnerability disclosure...
CVE-2025-24294: Critical Ruby DNS Vulnerability Threatens Windows Applications
A critical vulnerability in Ruby's DNS resolution library has been disclosed, posing significant risks to Windows applications and servers running Ruby-based software. CVE-2025-24294, a...
Critical NVIDIA Container Toolkit Vulnerability (CVE-2025-23266) Exposes Host Systems to Attack
A critical security vulnerability in NVIDIA's Container Toolkit has been discovered that could allow attackers to execute arbitrary code with elevated privileges on host systems, creating a realistic...
Azure Linux Attestations & Supply Chain Security: Beyond the One-Line Advisory
Microsoft's recent security advisory regarding Azure Linux—a one-line statement noting the inclusion of a potentially vulnerable open-source library—has sparked significant discussion within the...
CVE-2025-7395: WolfSSL Apple Certificate Validation Bypass Threatens Windows & IoT Security
A critical security vulnerability designated CVE-2025-7395 has been disclosed in the widely-used wolfSSL TLS/SSL library, exposing potentially millions of devices and applications to...
CVE-2025-38098: Microsoft's Azure Linux Attestation Sparks Debate on Vulnerability Transparency
A recent Microsoft Security Response Center (MSRC) attestation for CVE-2025-38098, a vulnerability in the open-source AMDGPU kernel driver, has ignited a significant discussion within the security...
CVE-2025-7546: Critical Binutils Memory Corruption Threat & Windows Security Implications
The cybersecurity landscape has been shaken by the disclosure of CVE-2025-7546, a critical memory corruption vulnerability in GNU Binutils 2.45 that poses significant risks to software development...
SQLite CVE-2025-6965: Critical Memory Corruption Bug Threatens Embedded Systems
A critical memory corruption vulnerability in SQLite, tracked as CVE-2025-6965, has been discovered and patched, posing significant risks to the countless applications and systems that rely on this...