
Defense & recoveryEXPLAINER · 3 MIN READ
GitLab CVE-2026-19478: protecting project data behind the GraphQL API
GitLab disclosed a critical flaw that could let an unauthenticated user alter or delete project and user data under certain conditions. Self-managed instances need update and recovery checks.
Sep 9, 2026 ↗

Defense & recoveryEXPLAINER · 3 MIN READ
Cisco IOS XR: why seven CVEs do not necessarily mean seven bugs
Cisco groups several IOS XR findings under seven CVE identifiers. That affects how you read the severity data—and why a base software version is not enough to confirm the fixes.
Sep 9, 2026 ↗

Defense & recoveryEXPLAINER · 5 MIN READ
Android’s September patches: the adbd flaw and the update fields to check
The September bulletin includes a race-related use-after-free in adbd. Understanding the flaw also means separating Android versions, security patch levels and Google Play system updates.
Sep 9, 2026 ↗

Defense & recoveryEXPLAINER · 5 MIN READ
Two exploited Windows bugs, two routes to SYSTEM privileges
Microsoft’s September fixes cover unsafe file-link handling in Windows Update Stack and heap corruption in ALPC. Both can turn local access into a much more serious compromise.
Sep 9, 2026 ↗

Defense & recoveryCHECKLIST · 5 MIN READ
An incident response plan your team can actually use
Decide who can act, what evidence to preserve and what has to be checked before service resumes. Then rehearse the plan while the systems are still working.
Sep 8, 2026 ↗

Defense & recoveryCHECKLIST · 5 MIN READ
Would your backups survive the same incident as your servers?
A completed backup job is only the beginning. Check who can delete the copies, how much work you could lose, and how long it takes to restore a working business service.
Sep 8, 2026 ↗