Belgium's national cybersecurity authority warned that a critical Windows Netlogon RCE vulnerability patched in May is now actively exploited in attacks. The flaw carries a 9.8 CVSS score and can let unauthenticated attackers run code on domain controllers.

The CCB warned on Friday that CVE-2026-41089 in Windows Netlogon is now actively exploited in the wild and could lead to RCE.
CVE-2026-41089 impacts all currently supported Windows Server versions including the latest release Windows Server 2025.
Admins must immediately confirm the May 2026 patches are deployed on all Windows Server domain controllers to block ongoing exploitation attempts.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Mathspace disclosed that attackers stole personal data belonging to 1,079,819 students, staff, and parents or guardians in Australia and New Zealand after breaching its Metabase system. The incident is the latest in a campaign exploiting a Metabase zero-day vulnerability used by multiple companies.
iPhone Handoff will let users switch between two iPhones sharing one number when iOS 27 launches later this month. The feature supports pairing a main device with a companion and requires carrier support, with code referencing T-Mobile US and Telekom.de.
A busy week featured iPhone 18 Pro dummy units ahead of the September 9 keynote, BYD’s deployment of 10,000 ultra-fast chargers since March 5, and tinkerers applying AI tools including DLSS 5 and Claude to everyday devices. The recap also highlights the growing threat of SIM swapping scams that can empty bank accounts through intercepted authentication codes.