CVE-2026-4428: Issues with AWS-LC - CRL Distribution Point Scope Check Logic Error

AWS-LC is a general-purpose cryptographic library maintained by AWS. We identified CVE-2026-4428 affecting X.509 certificate verification. A logic error in the CRL (Certificate Revocation List) distribution point matching in AWS-LC allows a revoked certificate to bypass revocation checks during certificate validation, when the application enables CRL checking and uses partitioned CRLs with Issuing Distribution Point (IDP) extensions. Applications that do not enable CRL checking (X509_V_FLAG_CRL_CHECK) are not affected. Applications using complete (non-partitioned) CRLs without IDP extensions are also not affected.

Amazon Web Services, Inc.
Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit

Apple backports CVE-2023-43010 WebKit fix after Coruna exploit kit abused iOS flaws, protecting older iPhones and iPads from memory corruption attacks

The Hacker News
CVE-2026-26117: Hijacking Azure Arc on Windows for Local Privilege Escalation & Cloud Identity Takeover 

CVE-2026-26117 lets low-privileged users hijack Azure Arc, escalate to SYSTEM, and take over the machine’s cloud identity and RBAC access.

Cymulate
Microsoft Patch Tuesday, March 2026 Edition – Krebs on Security

New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released

Google fixes actively exploited Chrome zero-day CVE-2026-2441, a high-severity CSS use-after-free flaw enabling sandboxed remote code execution.

The Hacker News
Apple fixes zero-day flaw used in 'extremely sophisticated' attacks

Apple has released security updates to fix a zero-day vulnerability that was exploited in an "extremely sophisticated attack" targeting specific individuals.

BleepingComputer
Microsoft's Valentine's gift to admins: 6 exploited zero-day fixes

: Roses are red, violets are blue ... now get patching

The Register

If you have a Galaxy A33, there's a crucial update you should install! 🔐📱

Samsung is releasing a new firmware for the Galaxy A33 5G, featuring the January 2026 security fix.

It's currently available for the Korean model SM-A336N as build A336NKSSDGZA1 and will soon reach other regions.

To see if it's ready in your area, go to Settings > Software update > Download and install.

#SamsungUpdate #GalaxyA33 #SecurityPatch #TechNews

Fortinet unearths another critical bug as SSO accounts borked post-patch

: More work for admins on the cards as they await a full dump of fixes

The Register