Microsoft has pushed out KB5124010, the September 2026 optional preview update for Windows 11 24H2 and 25H2. It contains 46 changes, including Bluetooth fixes, a way to remap the Copilot key, and support for Emoji 17.0.
The release is a non-security update. Monthly preview updates like this one give administrators and users an early look at fixes and features that will reach all devices with next month's Patch Tuesday, the regular monthly release of Windows security and quality updates. Unlike the cumulative updates shipped on Patch Tuesday, previews such as KB5124010 contain only quality improvements. They do not patch security vulnerabilities.
Microsoft has confirmed that recent Windows 11 updates are stopping the desktop from loading on some systems. Affected users see a black screen after signing in.
The problem started with the August 2026 preview updates and carried into later releases, including this month's Patch Tuesday rollout. According to Microsoft, it mainly hits Azure Virtual Desktop (AVD) hosts that use FSLogix. AVD is Microsoft's cloud-based desktop and app virtualization service. FSLogix is a tool that speeds up the loading of user profiles in virtual desktop environments.
Which updates are involved
Microsoft lists the following updates as linked to the issue:
Some developers are publishing private GitLab email addresses in READMEs, contributing guides and support pages to collect bug reports. According to researchers at application security company Aikido, these addresses carry a credential that attackers can use to act on GitLab as the developer who owns them.
The addresses come from a built-in GitLab feature called "Email work item to this project." GitLab generates them automatically. When someone sends a message to one of these addresses, GitLab turns the email into an issue or task in the project.
The problem is that each address contains a long-lived token tied to the developer's account. This string works as the credential for creating work items by email.
A newly discovered botnet called Carbonato is breaking into poorly secured Docker hosts and installing the Hermes Agent AI framework, which then carries out the operators' orders on compromised machines, according to ThreatDown.
The enterprise security company found the malware in an unauthenticated Docker registry that held nearly 60 repositories and 4.3 GB of image data. The operational evidence recovered from it covers the period from October 2024 to August 2026. The archive also held details on a separate campaign that pushed counterfeit cryptocurrency wallet apps, a lure that has recently shown up in Mac-focused stealer campaigns as well.
Researchers at Zenity Labs have disclosed three vulnerabilities in Salesforce Agentforce, the company's platform for AI agents. Attackers could have abused the flaws to turn trusted agents against their own organizations. The agents could be made to leak sensitive customer relationship management (CRM) data or to send phishing messages to employees.
The researchers call the set of bugs SalesBleed. According to Zenity Labs, two of the flaws allowed zero-click data exfiltration. The third let an attacker weaponize an Agentforce agent to spread phishing inside a company.
Zenity Labs reported the issues to Salesforce on June 1. Salesforce confirmed that all three had been fixed by August 19.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.