Menu

Latest articles

DSA-6438-1 postgresql-17 – security update
1.6M RingCentral accounts’ data dumped after ShinyHunters extortion attack
Some 1.6 million unique email addresses tied to RingCentral have been leaked online, alongside names, physical addresses, and phone numbers, according to [...]
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer?
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
French tax authority admits data heist after crook touts 2M records
France’s tax authority has confirmed that an intruder accessed its systems and extracted data in June after an alleged cybercriminal advertised a [...]
Nvidia moves into hot market for model routers
Model routing has emerged as a way to keep AI inferencing costs down by examining prompts and directing them to the most appropriate model — for example, [...]
Oracle’s new database security tool is free — for six months
Oracle has released a security tool intended to provide organizations with a centralized view of security risk across their database environments. Oracle [...]
Autonomous AI attacks pose ‘clear and present danger’ to critical infrastructure
In early July, attackers used open source AI agents to autonomously hack government systems and energy companies, signaling to defenders that AI-powered [...]
Crypto wallet maker Trezor confirms 13,000 customers’ details exposed in logistics breach
Cryptocurrency hardware wallet maker Trezor has confirmed that a breach at one of its shipping partners exposed the personal data of more than 13,000 [...]
Google cuts Gemini 3.7 Flash prices as enterprise AI economics diverge and Pro cadence slows
Google has launched Gemini 3.7 Flash, with updates focused on coding, automation, and agent workflows, alongside lower pricing for production deployments. [...]
Cloud ops is different in a neocloud
Enterprises are taking a serious look at neoclouds, the specialized cloud providers built primarily around AI infrastructure, especially GPUs, high-speed [...]
Debian Trixie Unzip Important Code Execution Issue DSA-6440-1
Scottish prosecutors cast eye over leaky supplier after staff data exposed
Scotland’s public prosecution service has warned 300 staff that their personal information may have been caught up in a cyberattack on one of its [...]
Debian Trixie Zip Command Injection Vulnerability DSA-6439-1
Gentoo Bubblewrap Critical Root Access Risk GLSA-202608-09 CVE-2026-41163
Gentoo libinput High Multiple Vulnerabilities GLSA-202608-08
Gentoo Exim High Code Exec Vulnerabilities GLSA-202608-07
Gentoo Flatpak High Sandbox Escape Issues GLSA-202608-06
Rocky Linux php8.4 Low Bug Fix DoS Enhancement RLSA-2026-49914
Rocky Linux 10 PHP Low Denial of Service Fix RLSA-2026-48170
Rocky Linux Advisory RLSA-2026-40416 PHP 8.2 Low Denial of Service
Rocky Linux 9 PHP Low Security Fixes RLSA-2026-48197 CVE-2026-14355
Rocky Linux 8 php Low Denial of Service RLSA-2026-47750 CVE-2026-14355
Rocky Linux PHP RLSA-2026-47749 Low AES-WRAP-PAD Denial of Service
Gentoo Apache HTTPD High Remote Execution Risk GLSA-202608-05
Gentoo Dnsmasq High Remote Code Execution Multiple Issues GLSA-202608-04
Gentoo rsync Important Multiple Privilege Escalation Issues GLSA 202608-03
New Zealand says China tried using space investments to spy on local affairs
New Zealand’s Security Intelligence Service (NZSIS) has claimed Chinese companies are building space facilities in the nation to gather military [...]
DeepSeek raises some V4 prices by more than 10x as AI demand strains capacity
One of AI vendor DeepSeek’s biggest selling points has been its ultra-low price point, but that party’s about to end. The Chinese model provider is raising [...]
Fedora 43 erlang-cowlib Denial of Service Fix 2026-ce97d80dae
Fedora 43 erlang-cowboy Denial Service Fix Advisory 2026-ce97d80dae
Fedora 44 flatpak Security Advisory Update 1.18.1 FEDORA-2026-6b83471b0e
Fedora 44 libnfs Important Fixes for CVE-2026-57918 CVE-2026-53689
Fedora 44 erlang-cowlib Denial of Service Fix 2026-7d233ad8b0
Fedora 44 erlang-cowboy Denial Of Service Fix Advis 2026-7d233ad8b0
OpenAI ditches Recall-style screenshot surveillance for friendly keylogging
If you want to record whatever you do on a computer, send those records to OpenAI, use more ChatGPT tokens, and increase your vulnerability to prompt [...]
DSA-6442-1 util-linux – security update
DSA-6441-1 python-httplib2 – security update
DSA-6440-1 unzip – security update
DSA-6439-1 zip – security update
Oracle Linux 10 FreeRDP Important Buffer Overflow Fix ELSA-2026-54486
Oracle Linux 10 python-idna Moderate IDNA Fix Advisory ELSA-2026-54481
Oracle Linux Grafana Moderate Fix Advisory ELSA-2026-54178 CVE-2026-8609
Oracle Linux 10 ELSA-2026-36541 Kernel Important Bug Fix Advisory
Oracle Linux 9 Python3.9 Important Security Advisory ELSA-2026-54268
Oracle Linux 9 Java-17-OpenJDK Significant Security Notice ELSA-2026-42887
Microsoft updates C++ build tools for Visual Studio
The MSVC Build Tools Preview is updated regularly with the latest features and fixes from the MSVC (Microsoft C++) development team. The MSVC team’s [...]
Slackware 15.0 rsync Security Update Advisory 2026-225-01
Rocky Linux 10 RLSA-2026-54486 FreeRDP Important Remote Code Execution
Mageia dhcpcd Critical Memory Corruption DoS Vuln 2026-0335
Ubuntu Linux Kernel Advisory USN-8633-2 – Important Security Fixes
Ubuntu 22.04 LTS Linux Kernel Security Fix USN-8631-3 CVE-2025-27558
Oracle Linux 8 Advisory ELSA-2026-54290 python-idna Moderate CVE-2026-45409
Oracle Linux 8 grafana Critical Security Revision ELSA-2026-54243
Oracle Linux 8 isns-utils Important Double-Free Fix ELSA-2026-53848
Oracle Linux 8 perl-DBI Important Buffer Overflow Fix ELSA-2026-52772
Oracle Kernel Moderate Security Advisory ELSA-2026-52765 CVE-2026-64496
Oracle Linux 7 glib2 Important Buffer Overflow Fix ELSA-2026-51183
Oracle Linux 7 libXfont2 Important CVE-2026-56001 ELSA-2026-51063
Oracle Linux 7 ELSA-2026-50808 libpng Moderate CVE-2026-33416
Oracle Linux 7 gstreamer1-plugins-good Security Update ELSA-2026-49603
Ubuntu 16.04 Kernel Important Flaw Escalates Privileges USN-8548-2
Ubuntu 16.04 Linux Kernel Important Privilege Escalation Issues USN-8530-2
Ubuntu 16.04 LTS Kernel Important Flaw Escalation CVE-2026-43503
Debian PostgreSQL DSA-6438-1 Multiple Security Issues Detected
Ubuntu 26.04 LTS Axios High Server-Side Request Forgery Issues USN-8638-1
DSA-6435-1 spip – security update
Routing Security in Practice: Detecting BGP Hijacks and RPKI-Invalid Announcements
Border Gateway Protocol (BGP) is still trust-based. In the past, a router would announce it originated a block of address space, and its neighbors would [...]
Debian 12 DLA-4739-1 Chromium Important Security Flaws Fixed
Ubuntu 26.04 LTS Linux Kernel Advisory USN-8637-1 Security Update
Ubuntu 22.04 LTS Linux Kernel Significant Packet Injection Flaw USN-8631-2
Ubuntu 24.04 LTS Kernel Security Update Addresses Key Issues USN-8630-2
Visual Studio Code 1.133 brings flexibility to Claude sessions
Microsoft has released Visual Studio Code 1.133, an update to its code editor that brings more flexibility to Anthropic Claude sessions. The update also [...]
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong
Trump wants to grant private cyber firms a license to hack back
Donald Trump is allowing government agencies to contract private cybersecurity companies to carry out operations against cyber-enabled transnational [...]
The backup Microsoft never promised you
Confidence in an organization’s cyber recovery capabilities deserves scrutiny. If a ransomware attack disables the SaaS data tenanted in the [...]
eBPF Security Logs May Show the Wrong File or Command, New Study Warns
A Linux security tool can catch a system call and still record the wrong thing.
Linux Audit Can Log a Syscall but Miss the Flag That Explains It
Linux Audit can tell defenders that a system call ran while leaving out the setting that explains what the call did.
Databricks acquires Electric to bring local Postgres databases to agentic apps
Databricks is acquiring Electric, a startup that brings WebAssembly-based Postgres databases into application environments, for an undisclosed sum, in an [...]
Linux Security Roundup Privilege Escalation DoS Code Execution August 2026
This week’s Linux security updates cover several areas administrators cannot afford to overlook. Debian, Ubuntu, Fedora, SUSE, openSUSE, and other [...]
AWS key exposed in JavaScript may have lit way to Beacon’s charity data
Beacon, a CRM provider for charities and nonprofits, says an AWS access key “potentially exposed in public JavaScript build artifacts” is the [...]
Rocky Linux 8 Kernel Update Moderate Security Issues RLSA-2026-54246
Rocky Linux python-idna Moderate Denial of Service RLSA-2026-54290
Rocky Linux 8 abrt Important Arbitrary File Issues RLSA-2026-54272
Rocky Linux 8 RLSA-2026-54247 Kernel-rt Medium Denial of Service
Rocky Linux python3.9 Important Filter Bypass Vulnern RLSA-2026-54268
Relief from the bookkeeping of change management
It’s an idle Tuesday afternoon. You’re in hour three of change management calls to get a CostCenter tag update approved for a production change. Only [...]
Why AI models need a real-time web intelligence layer
A growing sentiment in tech is that large AI model providers will eventually replace traditional software vendors. The argument makes some sense. If a [...]
MCP didn’t remove sessions. It handed them to the model
A few years ago, I helped move an application off sticky sessions so we could scale behind an ordinary round-robin load-balancer. On paper it was an [...]
Passwords stored in public Google Doc then showed up in search results
PWNED Welcome, once again, to PWNED, the weekly column where we highlight others’ security failures. Hopefully, there’s a lesson in all this, but it could [...]
Debian DSA-6433-1 xdg-dbus-proxy Important Policy Bypass
Debian LTS xorg-server Urgent DoS Privilege Escalation Notice DLA-4738-1
Debian DLA-4737-1 xorg-server Critical Privilege Escalation Vulnerabilities
Gentoo FreeType Normal Info Leak Multiple Issues GLSA-202608-02
Chinese Loongson processors have leaky caches, researchers find
Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could [...]
Ubuntu 26.04 LTS USN-8632-1 Follow-Redirects Credential Disclosure
Fedora 43 cri-o 1.34.11 Denial of Service Fix CVE-2026-34986
Fedora 43 vaultwarden 1.37.1 Denial Of Service Fix Advisory 2026-84a39c58c9
Fedora 44 SQLite Arbitrary Code Execution Vulnerability Fix CVE-2026-11822
Fedora 44 Linux Firmware Update Advisory 20260810 FEDORA-2026-c53019ed4f