Menu

Latest articles

Protecting legacy OT systems against modern cyberthreats Many manufacturing plants depend on OT systems that stay in service for many years. That long run can hide significant cybersecurity risks.
Navigating the future: Schiphol Airport’s journey to shift-left platform engineering
Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed
Massive password-stealing attack hits 75k Fortinet firewalls
FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness
Critical Joomla JCE RCE Added to CISA KEV as Attacks Target Linux Web Servers
Malicious JetBrains Plugins: The IDE Is Now a Supply-Chain Attack
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
QR Code Phishing Linux Quishing Risks and Mitigation Strategies
FreeRDP 3.27 Raises the Baseline for Secure Remote Access
SimpleHelp Authentication Bypass Exposes Remote Access Security Risk
Several security issues were fixed in GStreamer Bad Plugins.
AWS targets software release bottlenecks with DevOps Agent update
Digital sovereignty needs an operating model
Cisco adds another SD-WAN box to max-severity bug advisory
graphite2 could be made to crash or run programs if it opened a specially crafted file.
Homebrew 6.0 released with new security mechanism, Linux sandbox and more
Multiple security vulnerabilities were discovered in LibreOffice, which could result in denial of service or potentially the execution of arbitrary code if malformed files are opened. For Debian 12 bookworm, these problems have been fixed in version 4:7.4.7-1+deb12u13.
From RAG to ontology: Databricks bets on context as the key to trusted AI agents
Helpdesk scammers are making house calls to make their lies feel more real
The system could be made to run programs as an administrator.
Several security issues were fixed in the Linux kernel.
The system could be compromised under certain conditions.
Z.ai pitches GLM-5.2 for long-running software engineering tasks
Code like Hemingway
Designing frontend systems for cloud latency, not just cloud failure
10 tips for getting better R code from your AI coding agent
Update NSS to 3.124.0 Update Firefox to 152.0
Update NSS to 3.124.0 Update Firefox to 152.0
Fix editor command injection vulnerability (only affectsversion 2.6.0). (#1432) https://github.com/jonas/tig/issues/1432
Update to 149.0.7827.114 CVE-2026-12007: Use after free Core CVE-2026-12008: Use after free DigitalCredentials CVE-2026-12009: Insufficient validation of untrusted input Accessibility CVE-2026-12010: Heap buffer overflow GPU
x86 HVM I/O port list traversal [XSA-491, CVE-2026-42487] domctl lock open to abuse [XSA-492, CVE-2026-42489, CVE-2026-42490] Arm: Completion of memory accesses not guaranteed by completion of a TLBI [XSA-493, CVE-2025-10263] x86: mismatched mapcache metadata [XSA-494, CVE-2026-42488]
Update to 1.9.2 for CVE-2026-10846
Version 0.16.0 – 2026-06-08 Security Fix out-of-bounds read via undersized frames in amqp_handle_input (GHSA-9mmv-r8g3-qp46, #878) Fix client crash when server negotiates frame_max below the AMQP protocol
BIRD 3.3.1 (2026-06-09) BGP: Fix crash when incoming connection for disabled protocol arrives BGP: Fix parsing labelled NLRIs with no next hop BGP: Fix cork behavior in collision with graceful restart BGP: Fix crash on dumping pending export statistics
CVE-2026-34253 – fix arbitrary code execution via buffer underflow
33.0.5 Release
This release fixes CVE-2026-10725 (exhausting memory when decompressing request headers). It also improves examples.
Fix arbitrary memory write with crafted Ventana BIF file (CVE-2026-48977).
Fix editor command injection vulnerability (only affectsversion 2.6.0). (#1432) https://github.com/jonas/tig/issues/1432
BIRD 3.3.1 (2026-06-09) BGP: Fix crash when incoming connection for disabled protocol arrives BGP: Fix parsing labelled NLRIs with no next hop BGP: Fix cork behavior in collision with graceful restart BGP: Fix crash on dumping pending export statistics
33.0.5 Release
This release fixes CVE-2026-10725 (exhausting memory when decompressing request headers). It also improves examples.
Fix arbitrary memory write with crafted Ventana BIF file (CVE-2026-48977).
Update to version 3.10.0
Security update
Security update