Menu

Latest articles

DSA-6480-1 keystone – security update
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
A human ransomware crook used frontier AI models to breach an enterprise network in less than 10 hours, an intrusion Unit 42 says would normally take human [...]
SonicWall’s SMA1000 boxes under active attack again
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and [...]
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration. In an email sent to affected [...]
Google brings predictive AI to BigQuery without the ML training
Google is adding a pre-trained foundation model for tabular data to BigQuery, allowing enterprise teams to generate predictions from structured data [...]
5 ways to augment security risk management in the AI era
IT operations and security teams receive thousands of alerts every day from threat intelligence sources, such as vulnerability scanners, observability [...]
UK cyber bill targets AI users, not the vendors building it
The UK government has rejected proposals from members of the the House of Lords to bring AI vendors within the scope of the Cyber Security and Resilience [...]
Claude Code has left a little hole in my soul
I built a complete, working application in a day this past weekend.  Well, less than a day if you don’t count the time I spent waiting on Claude Code to do [...]
Seven critical vibe coding mistakes — and how to avoid them
Vibe coding an application or an AI agent sounds too good to be true. A single developer prompts their way through a plan and has the code for a working [...]
Oracle Linux 10 Nodejs Key Security Update ELSA-2026-61376-0 CVEs
Oracle Linux 10 ELSA-2026-38489 Important Xwayland CVE Fix
Oracle Linux 9 Gzip Moderate Buffer Overflow Vuln ELSA-2026-61623-0
Oracle glib2 Moderate Buffer Overflow Fix ELSA-2026-61766-0 CVE-2026-15588
Oracle Linux 8 mingw-sqlite Important Update for CVE-2026-11822
Oracle 8 xorg-x11-server Important CVE-2026-55999 ELSA-2026-38487 Fix
Linux Patch Addresses SA2UL Stack Overflow Found in IPsec Setup
A version 2 Linux kernel patch posted on August 31 fixes a stack overflow in the SA2UL hardware crypto driver. The Kernel Address Sanitizer, or KASAN, [...]
Linux Patch Targets RxRPC Teardown Race During Namespace Exit
RxRPC is a Linux kernel transport for remote procedure calls. A teardown race reported in August shows that its network namespace cleanup can still reach a [...]
Linux Patch Proposes Landlock Policy Objects for eBPF at Exec
A version 2 Linux kernel patch series posted on August 31 proposes a new eBPF security interface for applying Landlock policy during program execution. The [...]
Anthropic makes changes to stop AI agents running amok again
Learning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment [...]
Slackware pcre2 Security Update Advisory 2026-244-01 Released Today
Fedora 44 Cockpit Important Memory Leak Fix Advisory 2026-4ca90cfeb9
Fedora 44 gdk-pixbuf2 CVE-2026-81893 Critical Invalid Write
Fedora 44 Emacs Critical Local Command Injection CVE-2026-79992
Fedora 44 OpenSSL 3.5.8 Security Update Advisory 2026-51251b4657
Fedora 44 python-linkify-it-py Security Fix CVE-2026-48801 CVE-2026-59887
Fedora 44 python-llm Arbitrary Code Execution Advisory 2026-4f3301f569
Fedora 44 openvkl Important Heap Overflow Vulnern CVE-2026-21399
Fedora 44 rkcommon Critical Buffer Overflow Advisory 2026-9f32915b09
Fedora 43 Bubblewrap Update Resolves SIGCHLD Subprocess Management Issue
Ubuntu 26.04 LTS SSSD Crash Due to Smartcard Interaction USN-8672-1
SUSE yast2-auth-client Important Command Injection Advisory 2026-3914-1
SUSE 2026-3915-1 Important apache2-mod_auth_openidc Out-of-Bounds Issue
SUSE Terraform Important File Access Issues Advisory 2026-3916-1
SUSE ucode-intel Important Security Update September 2026-3917-1
SUSE cups-filters Moderate Infinite Loop and Print Job Issues 2026-3918-1
SUSE Linux Micro 6.0 Kernel Important Security Update 2026-23366-1
SUSE Linux Micro 6.0 Kernel Security Important Patch 2026-23367-1
SUSE Micro 6.0 Kernel RT Important Security Update 2026-23368-1
SUSE Linux Micro 6.0 Delivers Essential Kernel RT Security Fix 2026-23369-1
SUSE Linux Micro 6.0 Kernel RT Important Security Update 2026-23370-1
SUSE Linux Micro 6.0 Kernel RT Key Update for Security Issue 2026-23371-1
SUSE Linux Micro 6.0 Important Kernel RT Security Update 2026-23372-1
SUSE Linux Micro 6.0 Kernel RT Important Security Update 2026-23373-1
SUSE Linux Micro 6.0 Important Kernel RT Security Update 2026-23374-1
SUSE Linux Micro 6.0 Security Update 2026-23375-1 Essential Kernel Patch
SUSE Linux Micro 6.0 Kernel RT Live Patch 21 Important Fixes 2026-23376-1
SUSE Kernel RT Live Patch 22 Important Security Update 2026-23377-1
SUSE Micro 6.0 Kernel Live Patch Important Security Update 2026-23378-1
SUSE Linux Micro 6.0 Kernel RT Important Vuln Fix 2026-23379-1
SUSE Linux Micro 6.0 Kernel RT Important Security Update 2026-23380-1
SUSE Linux Micro Important Kernel RT Issues Resolved 2026-23381-1
SUSE Linux Micro 6.0 Important Kernel RT Security Patch 2026-23382-1
SUSE Linux Micro 6.0 Kernel Key Update Live Patch 10 SUSE-SU-2026-23383-1
SUSE Linux Micro 6.0 Kernel Important Security Update 2026-23384-1
SUSE Linux Micro 6.0 Kernel Important Vulnerability Patch 2026-23385-1
SUSE Micro 6.0 Kernel Live Patch 13 Important Update Vuln 2026-23386-1
SUSE Linux Micro 6.0 Important Kernel Security Patch SUSE-SU-2026-23387-1
SUSE Linux Micro 6.0 Kernel Important Security Update 2026-23388-1
SUSE Linux Enterprise Micro 6.0 Kernel Security Update 2026-23389-1
SUSE Micro 6.0 Kernel Important Security Update 2026-23390-1
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used [...]
Another Artifactory CVE under attack by AI agents or humans
Security researchers reported that someone is exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass bug, just days after the vendor [...]
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent [...]
SUSE libapr-util1 Critical SQL Injection Heap Overflow Vuln 2026-3905-1
SUSE python3-sqlparse Important Denial of Service Vulnern 2026-3906-1
SUSE Python-sqlparse Important Denial of Service Advisory 2026-3907-1
Firefox helps iPhone users bypass ads on web sites while making money showing its own ads
After several weeks of anticipation, Mozilla has started rolling out ad blocking to the iOS version of its popular browser, but you can still expect to see [...]
Anthropic pledges to try harder to keep models under control, asks partners to chip in
Anthropic says it’s taking steps to limit the misbehavior of its AI models after a review found Claude models going beyond the scope of fictional [...]
This month in security with Tony Anscombe – August 2026 edition
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month’s cybersecurity news
Apache Fory serialization framework adds JSON support for Kotlin and Scala
The Apache Fory community has announced the release of Fory 1.7.0, an update of the multi-language serialization framework that adds Fory JSON support for [...]
OpenClaw rolls out system-wide overhaul, updates security controls across agent platform
OpenClaw has released what it describes as the largest update in its history, introducing a system-wide overhaul spanning runtime behavior, plugins, and [...]
33-hour BGP hijack of Softaculous traffic prompts security scramble
Softaculous and Virtualizor customers are being urged to reset credentials and inspect their servers after a 33-hour BGP hijacking incident diverted [...]
Why tech needs a new kind of English major
I saw Spider-Man: Brand New Day last week. I struggled to enjoy it. I guess I hit CGI overload, although its 89% score on Rotten Tomatoes suggests others [...]
A look at AWS’s agentic toolkit for cloud migration
Amazon Bedrock AgentCore is an AWS technology that deserves a closer look because it is not simply another migration automation tool. It is an agentic AI [...]
4 standards solve agent identity. None solves the harder question: Is it still the agent you approved?
I’ve stopped being surprised by the service account nobody can explain. It was created for a migration that finished years ago. It still holds credentials. [...]
Moburst Targets Fortune 500 Brands as AEO Partner
Moburst, a digital growth agency, is positioning its Answer Engine Optimization practice specifically at enterprise and Fortune 500 brands, arguing that [...]
Compose Multiplatform 1.12.0 welcomes coding agents with MCP server
JetBrains has released Compose Multiplatform 1.12.0, an update to the declarative framework for sharing Kotlin UI code across platforms. Highlights of the [...]
openSUSE Unbound Important DoS Threat Resolution 2026-3885-1
openSUSE yast2-samba-client Important Command Injection Issue 2026-3887-1
openSUSE Yast2-Samba-Client Important Command Injection Fix 2026-3888-1
openSUSE yast2-samba-client Important Command Injection Vuln 2026-3889-1
openSUSE 15.4 yast2-auth-client Key OS Command Injection Patch 2026-3894-1
openSUSE 2026 yast2-auth-client Important OS Command Injection Fix
Broadcom says that enterprise AI agents need two things: Data they can trust and boundaries they can’t cross
For enterprises deploying AI agents, security and trust are top-of-mind issues. When given the authority to act autonomously, they can inadvertently leak [...]
openSUSE Python-httplib2 Important Memory Overflow Vuln 2026-3898-1
openSUSE yast2-auth-client Important OS Command Injection Fix 2026-3901-1
Ubuntu OpenZFS Important Authorization Bypass Risk USN-8705-2
Healthcare cyberattacks hit pacemakers and millions of patient records
Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global [...]
Rocky Linux 9 nodejs Important Memory & Access Issues RLSA-2026-61383
Rocky Linux Node.js Significant Memory Exhaustion Risk – RLSA-2026-61386
Debian LTS Expat Security Update DLA-4765-1 for Various CVEs
Debian 11 to 12 libdbd-csv-perl Regression Fix Update DLA-4764-2
SUSE OpenSSL Vital Security Update Addressing Multiple Vulnerabilities
SUSE OpenSSL Important Memory Abuse Heap Overflow Advisory 2026-3877-1
SUSE openssl-1_1 Important Memory Issue Buffer Overflow Vuln 2026-3878-1
SUSE vim Important Arbitrary Code Exec Denial of Service Vuln 2026-23346-1
SUSE SSSD Moderate Out-of-Bounds Memory Issues Vuln 2026-23347-1
SUSE Unbound Important DoS Vulnerabilities Fix Advisory 2026-23349-1
SUSE Curl Moderate Password Leak and Auth Issues Vuln 2026-23350-1
SUSE Micro 6.1 Advisory 2026-23351-1 Highlights CVE-2026-3886 Risk