Live
Unpatched Mbed TLS Devices Leave Decrypted Data Exposed in Memory—Here’s How to Clean Up·MSFT +2.1%Unchecked Diffie-Hellman Parameters Can Brick Mbed TLS Devices — The Fix Is a Simple Update·NVDA +0.2%Mbed TLS 2.24.0 Patches Hostname Spoofing Hole That Leverages Crafted IP Certificates·GOOGL +1.7%Attackers Can Crash Your Go Apps with a Crafted Number – What to Do About CVE-2021-33198·AMZN +1.1%Azure Linux CVE-2021-33195: Microsoft's Limited Attestation & Go DNS Vulnerability Risks·MSFT +2.1%CVE-2025-24294: Critical Ruby DNS Vulnerability Threatens Windows Applications·NVDA +0.2%Critical NVIDIA Container Toolkit Vulnerability (CVE-2025-23266) Exposes Host Systems to Attack·GOOGL +1.7%Azure Linux Attestations & Supply Chain Security: Beyond the One-Line Advisory·AMZN +1.1%Unpatched Mbed TLS Devices Leave Decrypted Data Exposed in Memory—Here’s How to Clean Up·MSFT +2.1%Unchecked Diffie-Hellman Parameters Can Brick Mbed TLS Devices — The Fix Is a Simple Update·NVDA +0.2%Mbed TLS 2.24.0 Patches Hostname Spoofing Hole That Leverages Crafted IP Certificates·GOOGL +1.7%Attackers Can Crash Your Go Apps with a Crafted Number – What to Do About CVE-2021-33198·AMZN +1.1%Azure Linux CVE-2021-33195: Microsoft's Limited Attestation & Go DNS Vulnerability Risks·MSFT +2.1%CVE-2025-24294: Critical Ruby DNS Vulnerability Threatens Windows Applications·NVDA +0.2%Critical NVIDIA Container Toolkit Vulnerability (CVE-2025-23266) Exposes Host Systems to Attack·GOOGL +1.7%Azure Linux Attestations & Supply Chain Security: Beyond the One-Line Advisory·AMZN +1.1%

Articles from February 2026

Browse all Windows news articles published in February 2026

12 articles Page 81 of 250
Articles from February 2026
All archives
Mbed Tls · Memory Safety

Unpatched Mbed TLS Devices Leave Decrypted Data Exposed in Memory—Here’s How to Clean Up

A bug in the widely used Mbed TLS encryption library fails to scrub decrypted plaintext from memory after certain read operations, potentially exposing session tokens, passwords, and other secrets to...

SE Security Desk·22w ago
Denial Of Service · Diffie-hellman

Unchecked Diffie-Hellman Parameters Can Brick Mbed TLS Devices — The Fix Is a Simple Update

A vulnerability in the widely used Mbed TLS cryptographic library allows attackers to remotely freeze or crash connected devices by feeding them oversized Diffie-Hellman key exchange parameters. The...

SE Security Desk·22w ago
Certificate Validation · Hostname Verification

Mbed TLS 2.24.0 Patches Hostname Spoofing Hole That Leverages Crafted IP Certificates

In August 2020, the maintainers of the widely embedded Mbed TLS library released version 2.24.0 to fix a certificate validation flaw that could allow an attacker to impersonate any domain name by...

SE Security Desk·22w ago
Big Rat Parsing · Cve 2021 33198

Attackers Can Crash Your Go Apps with a Crafted Number – What to Do About CVE-2021-33198

A dangerous parsing bug in Go’s standard math/big package can let unauthenticated attackers remotely crash any service that feeds untrusted numeric text into (*big.Rat).SetString or UnmarshalText....

SE Security Desk·22w ago
Azure Linux · Cve 2021 33195

Azure Linux CVE-2021-33195: Microsoft's Limited Attestation & Go DNS Vulnerability Risks

Microsoft's recent security advisory regarding Azure Linux and CVE-2021-33195 has sparked significant discussion in the security community, revealing important nuances about vulnerability disclosure...

SE Security Desk·22w ago
Cve 2025 24294 · Dns Compression Vulnerability

CVE-2025-24294: Critical Ruby DNS Vulnerability Threatens Windows Applications

A critical vulnerability in Ruby's DNS resolution library has been disclosed, posing significant risks to Windows applications and servers running Ruby-based software. CVE-2025-24294, a...

SE Security Desk·22w ago
Container Security · Gpu Security

Critical NVIDIA Container Toolkit Vulnerability (CVE-2025-23266) Exposes Host Systems to Attack

A critical security vulnerability in NVIDIA's Container Toolkit has been discovered that could allow attackers to execute arbitrary code with elevated privileges on host systems, creating a realistic...

SE Security Desk·22w ago
Artifact Verification · Azure Linux

Azure Linux Attestations & Supply Chain Security: Beyond the One-Line Advisory

Microsoft's recent security advisory regarding Azure Linux—a one-line statement noting the inclusion of a potentially vulnerable open-source library—has sparked significant discussion within the...

SE Security Desk·22w ago
Apple Native Validation · Cve 2025 7395

CVE-2025-7395: WolfSSL Apple Certificate Validation Bypass Threatens Windows & IoT Security

A critical security vulnerability designated CVE-2025-7395 has been disclosed in the widely-used wolfSSL TLS/SSL library, exposing potentially millions of devices and applications to...

SE Security Desk·22w ago
Amd Gpu · Azure Linux

CVE-2025-38098: Microsoft's Azure Linux Attestation Sparks Debate on Vulnerability Transparency

A recent Microsoft Security Response Center (MSRC) attestation for CVE-2025-38098, a vulnerability in the open-source AMDGPU kernel driver, has ignited a significant discussion within the security...

SE Security Desk·22w ago
Backport Patch · Binutils

CVE-2025-7546: Critical Binutils Memory Corruption Threat & Windows Security Implications

The cybersecurity landscape has been shaken by the disclosure of CVE-2025-7546, a critical memory corruption vulnerability in GNU Binutils 2.45 that poses significant risks to software development...

SE Security Desk·22w ago
Cve 2025 6965 · Embedded Builds

SQLite CVE-2025-6965: Critical Memory Corruption Bug Threatens Embedded Systems

A critical memory corruption vulnerability in SQLite, tracked as CVE-2025-6965, has been discovered and patched, posing significant risks to the countless applications and systems that rely on this...

SE Security Desk·22w ago