Menu

Latest articles

DSA-6396-1 chromium – security update
DSA-6395-1 bind9 – security update
DSA-6394-1 firefox-esr – security update
Year-long Russian attacks infect users as soon as they look at an email
Kremlin cyber goons have been breaking into government and commercial networks for at least a year by exploiting a Zimbra bug with a novel twist on [...]
Google CEO distracts from Gemini 3.5 Pro delay with talk of Gemini 4 and monthly releases
Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in [...]
Millions of California-bought cars can be hijacked via Bluetooth
At least 2.2 million vehicles fitted with dealer-installed KARR and SWDS security systems are vulnerable to nearby Bluetooth attacks that can unlock doors [...]
Oracle drops 1,449 security patches like it’s the new normal
It’s a bad day to be an Oracle admin: Big Red has just released 1,449 security patches ready to be applied. The patches were released as part of the [...]
Iran-linked crews are probing more flavors of US industrial kit
The US Cybersecurity and Infrastructure Security Agency (CISA) has expanded the scope of its alert on Iranian-affiliated hackers attacking critical [...]
One ChatGPT link could smuggle a rogue AI agent into your company
One click on what looked like an ordinary ChatGPT link could plant an attacker-controlled AI agent inside a company’s ChatGPT workspace, according to [...]
If you get knocked on the head and get all your devices stolen and have amnesia, Google will let you back in with a selfie
Tired of worrying about how you might recover all the precious data stored in your Google account if you somehow lose your devices and forget your email [...]
Preparing for Q-day: Four steps to prepare your hybrid cloud today
The arrival of a cryptographically relevant quantum computer, often referred to as Q-day, is moving from a distant theoretical mathematical challenge to an [...]
Swiss train maker tells ransomware crooks to get off at the next stop
Swiss rail manufacturer Stadler Rail says it refused a CHF 10 million ($12.3 million) ransom demand after the Everest ransomware gang compromised one of [...]
Rocky Linux Important .NET 8.0 RLSA-2026-41901 Multiple Threats
Rocky Linux 8 RLSA-2026-41900 .NET 10.0 Important Bug Fixes
Rocky Linux 9 RLSA-2026-42952 glibc Moderate Denial-of-Service Issues
Rocky Linux RLSA-2026-41898 .NET 10.0 Important Security Update
Rocky Linux 9 RLSA-2026-41896 .NET 9.0 Security Important Denial of Service
Rocky Linux .NET 8.0 Important Security Issues RLSA-2026-41894
Rocky Linux 9 Kernel Important Security Update RLSA-2026-43307
Rocky Linux 10 RLSA-2026-41893 .NET 8.0 Important Security Update
Rocky Linux .NET 10.0 Important Denial of Service Issues RLSA-2026-41897
Rocky Linux mariadb-connector-c Important SQL Injection Fix RLSA-2026-43505
Rocky Linux 10 .NET 9.0 Important Security Issues RLSA-2026-41895
Rocky Linux dogtag-pki Important Arbitrary Code Execution RLSA-2026-43400
Rocky Linux 10 Kernel Important Security Update RLSA-2026-42919
Ubuntu 22.04 LTS Linux Kernel Critical Risk Multiple Issues USN-8595-1
Ubuntu 24.04 22.04 Kernel Critical Privilege Escalation Advisory USN-8574-2
Ubuntu 24.04 Kernel Critical Security Flaws Vuln 8594-1
Ubuntu 26.04 LTS Kernel Critical Privilege Escalation Issues USN-8593-1
Debian pdns-recursor Critical Cache Poisoning DNSSEC Bypass DSA-6397-1
Fedora 44 Kernel Important Security Fix 2026-2b94d8d05c
Fedora 44 llvm Severe Buffer Overflow Resolution 2026-597e8f9de1
Fedora 44 Fractal Important Denial Of Service Advisory 2026-600530ae91
Fedora 44 SRT Significant Streaming Improvement 2026-45ce54d51e
Fedora 44 Chromium Important Use After Free Issues 2026-310f620a68
Critical Update Information for Fedora 44 libssh – 2026-0e46c91ccf
Fedora 44 nginx-mod-vts Critical Patch for Code Execution 2026-60fc198d3b
Fedora 44 nginx-mod-fancyindex Critical CVE-2026-42533 Arbitrary Code Exec
Fedora 44 perl-DBI Important Update Denial of Service CVEs 2026-1c5ffc6018
Fedora 44 nginx-mod-modsecurity Critical Update for CVE-2026-42533
Fedora 44 nginx-mod-headers-more Critical Code Exec Fix 2026-60fc198d3b
Fedora 44 nginx-mod-js-challenge Moderate Access Issue Fix 2026-60fc198d3b
Fedora 44 nginx Moderate Arbitrary Code Execution Vuln 2026-60fc198d3b
Fedora 44 nginx-mod-naxsi Critical Arbitrary Code Exec Vuln 2026-60fc198d3b
Fedora 44 NGINX-Mod-Brotli Critical Fix for CVE-2026-42533
Fedora 44 perl-YAML-Syck Important Memory-Safety CVEs 2026-2139aa7dce
Fedora 44 Collectl Important Code Issue Advisory 2026-71a9784a57
Fedora 43 Kernel Critical Exploit Update 2026-6503a6a639
Fedora 43 libssh Critical Denial of Service Buffer Overflow 2026-063caa9112
Fedora 43 Fractal Medium Stack Exhaustion Risk Resolution 2026-9630be304f
Fedora 43 SRT Major Security Transport Update 2026-51628b98a8
Fedora 43 Chromium Critical Use After Free Issues FEDORA-2026-ac712bf651
Fedora 43 perl-DBI Critical Denial of Service Fix FEDORA-2026-c0abcba354
Fedora 43 perl-YAML-Syck Critical Denial of Service Update 2026-c8484f1afb
Fedora 43 collectl Important Insecure Code Handle Vuln 2026-e2b3dd1ec0
Debian Chromium Critical Denial of Service Arbitrary Code DSA-6396-1
Debian LTS DLA-4694-1 NSS Critical Denial Of Service Code Execution
Rocky Linux RLSA-2026-42552 Kernel Important Security Fix
Rocky Linux RLSA-2026-42733 glibc Moderate Information Disclosure and DoS
Rocky Linux 8 RLSA-2026-42550 kernel-rt Important Security Fixes
WSL container: A quiet revolution for Windows development
Running containers on Windows has never been as easy as it should be. While there are versions of Docker Desktop and Podman that work with both the Windows [...]
Determining the ROI of AI requires data that most companies lack
Leadership wants to scale AI. Budgets are tripling. Adoption is up. Then the CFO asks the question every board now asks: which of these initiatives is [...]
Talking smack about a doctor got him access to private medical files
PWNED Welcome back to PWNED, the weekly column where we focus on security own-goals so you can avoid them. This week’s topic involves serious problems in [...]
G# language for .NET borrows from Go, Kotlin, and Swift
G# (GSharp) is moving forward as a programming language for Microsoft’s .NET platform, touted as bringing Go-, Kotlin-, and Swift-style ergonomics to the [...]
CISA KEV vs. NVD: How Linux Teams Should Prioritize Vulnerabilities That Actually Matter
Organizations should combine the NVD and CISA KEV catalog to prioritize vulnerabilities effectively, focusing on managing real risks rather than being [...]
DSA-6398-1 webkit2gtk – security update
DSA-6397-1 pdns-recursor – security update
OpenAI scored an own goal with HuggingFace attack, showing how open Chinese models are winning
OPINION OpenAI has acknowledged its models powered the autonomous agents that compromised HuggingFace infrastructure. It might be taken as a convoluted [...]
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware
Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and [...]
Ubuntu 26.04 LTS Exim Important File Access and Priv Escalation USN-8590-1
Oracle expands Cloud@Customer with new database service for mid-sized workloads
Oracle is expanding its Cloud@Customer on-premises portfolio with a managed database offering that it says will enable enterprises to run databases, [...]
Linux kernel team publishes 432 CVEs in two days
If you’re responsible for Linux security, someone just dumped a pile of work onto your desk: 432 Linux kernel CVEs were published across Sunday and [...]
Cisco’s new AI model tells code reviewers where to look for vulnerabilities
Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a [...]
Rocky Linux 10 RLSA-2026-41937 sssd Important Access Fix
Rocky Linux 10 glib2 Important Integer Underflow Fix RLSA-2026-42063
Rocky Linux 10 Pacemaker Important Denial of Service CVE-2026-10649
Rocky Linux 10 libtiff Important Heap Overflow Update RLSA-2026-41892
Rocky Linux 10 acl Important Symlink Traversal Threat RLSA-2026-42739
Rocky Linux glibc Moderate Security Fix Denial Service 2026-42694
Rocky Linux Dovecot Important Denial of Service Vulnern RLSA-2026-41988
Rocky Linux 10 c-ares Important Use-After-Free Issue RLSA-2026-42096
Rocky Linux python3.14 Important CPU Denial of Service Vuln RLSA-2026-40856
Rocky Linux libtiff Important Buffer Overflow Vuln RLSA-2026-42668
Rocky Linux 9 httpd Important Security Issues RLSA-2026-41906
Rocky Linux 9 Python 3.14 Important CPU DoS Vulnerability RLSA-2026-41949
Rocky Linux Dovecot Important Denial Of Service RLSA-2026-41905
Rocky Linux 9 Important webkit2gtk3 Security Update RLSA-2026-42062
Rocky Linux 9 glib2 Important Integer Underflow Vuln RLSA-2026-42089
Rocky Linux SSSD Important Security Update RLSA-2026-42122
Rocky Linux acl Important Symlink Privilege Escalation RLSA-2026-42736
Rocky Linux 8 pki-deps Important Code Execution Threat RLSA-2026-43218
GitLab previews auto-remediation of vulnerable dependencies
GitLab has released GitLab 19.2, an update to the company’s devsecops platform that allows teams to fix vulnerable dependencies automatically, use Security [...]
Ubuntu 26.04 Tar Important Directory Injection Fix USN-8477-3
openSUSE python313-bleach Moderate Threats Mitigated 2026-11323-1
openSUSE Tumbleweed perl-YAML Moderate Update CVE-2026-63676
openSUSE Tumbleweed 7zip Moderate CVE-2026-14266 Advisory 2026-11319-1
Ubuntu 26.04 LTS Kerberos Important DoS Issues USN-8585-1 CVE-2026-11850
Ubuntu 26.04 GIFLIB Critical Denial of Service 2026-23868
Ubuntu libgphoto2 Important Buffer Abuse Denial of Service Vuln 8586-1