Menu

Latest articles

DSA-6503-1 thunderbird – security update
DSA-6502-1 mkvtoolnix – security update
DSA-6501-1 firefox-esr – security update
DSA-6500-1 tor – security update
China’s Salt Typhoon backdoors Latin American orgs with new snooping malware
China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across [...]
Cyberthreats are moving faster than SMBs: Readiness must accelerate
As AI adoption expands the attack surface and adds to the security workload, businesses need automation backed by experts
TypeSafe AI’s new models work with machines, not humans
Today’s large language models are verbose, even if they’re being asked to recommend a simple decision, driving up usage costs through the sheer volume of [...]
London property manager breach may have exposed bank details and lockbox codes
London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys [...]
Self-modifying AI agents expose a blind spot in enterprise security
As debate over AI safety intensifies, new research is drawing attention to a more immediate risk for enterprises: AI agents that can alter the models they [...]
Cisco drops another exploited zero-day, this time a perfect 10
Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed [...]
Test environment let anyone access live customer data
Welcome back to PWNED, the weekly column where we learn important life lessons about how we let cybercrims access our data through carelessness. Hopefully, [...]
Container Security Failure Could Let a Malicious Image Reach the Linux Host
Container security can fail before a workload fully enters its root filesystem, the private file tree the container is meant to see.
Linux SMB Security Fixes Restore Ownership and Input-Trust Boundaries
SMB, or Server Message Block, lets Linux systems access files shared over a network.
How Transparent Huge Pages Could Lose Rewritten Data During Reclaim
Transparent huge pages let Linux manage memory in larger blocks for better performance.
Why eBPF Security Depends on Matching Metadata Lifetimes
eBPF lets verified programs run inside the Linux kernel. Linux eBPF security depends on supporting data remaining available for as long as those programs [...]
Effective Encryption Strategies to Safeguard Your Online Identity
In today’s world, almost every part of our lives is directly or indirectly linked to the Internet. As cyberattacks in network security grow more advanced, [...]
Ofcom discovers issuing Online Safety Act fines is easier than collecting them
Ofcom chiefs have acknowledged that most fines issued under the Online Safety Act (OSA) remain unpaid, highlighting limitations in the comms [...]
Stop tuning your models and fix your data
Walk into any boardroom or technology conference today, and the conversation is entirely consumed by the promise of agentic AI. We are told that autonomous [...]
MSBuild explained: Understanding Microsoft’s build platform
Visual Studio is a lot more than an editor and debugger; it’s the host for Microsoft’s cross-platform build tools. MSBuild is one of those forgotten [...]
Your AI testing dashboards are green. That’s the problem
The green dashboard is one of the most comforting objects in software engineering. It says the build passed, the tests passed, the service is healthy and [...]
How Linux File Permissions Become a Root Trust Boundary
Linux file permissions are usually introduced as a way to decide who may read, write, or execute a file. On a production server, they do something more [...]
Fedora 43 open62541 Security Advisory on Critical Denial of Service Issues
Fedora 43 php-pecl-mongodb2 Important Out-of-Bounds Read Fix CVE-2026-84968
Fedora 43 Roundcube 1.6.19 Security Updates Address XSS Email Issues
Fedora 44 python-django6 Important Updates for XSS and DoS Vulnerabilities
Fedora 44 open62541 Key Fixes for Denial of Service and Code Execution
Fedora 44 php-pecl-mongodb2 Important Out-Of-Bounds Read CVE-2026-84968
Fedora 44 Roundcube 1.7.4 Security Fix XSS Email Header CVE-2026-38c637be37
Fedora 44 python-jwcrypto Minor Risk Security Updates 2026-8caad572b0
Fedora 45 Python Django 6 Key Denial of Service XSS Patch 2026-522a9411e7
Fedora 45 open62541 Critical Code Execution Denial of Service Patch 2026
Fedora 45 Roundcube 1.7.4 Security Update for XSS and Injection Issues
Fedora 45 Python JWCrypto Low Severity Security Fix 2026-6d094c5360
Docker Sandboxes Flaw Lets a Guest Reach Host Unix Sockets
Docker has fixed a high-severity Docker Sandboxes vulnerability that allowed a malicious guest to redirect a host-side relay toward Unix sockets outside [...]
Acronis Backup Flaw Is Being Exploited on Linux Hosting Servers
Acronis has fixed a high-severity vulnerability in its Linux hosting backup integrations after detecting exploitation in limited, targeted attacks. The [...]
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Slackware mozilla-thunderbird Critical Security Update 2026-259-02
Slackware 15.0 Mozilla-Firefox Medium Security Fix 2026-259-01
AI agents can modify themselves without humans telling them to do so
The list of dodgy things AI agents can and will do on their own – like stealing people’s credentials, escaping onto the open internet, communicating [...]
Rocky Linux 10 and .NET 9.0 Advisory for CVE-2026-58649 CVE-2026-69806
Rocky Linux 10 NET 8.0 Moderate Info Leak CVE-2026-58649 RLSA-2026-67525
Rocky Linux 10 RLSA-2026-67584 Rsyslog Moderate Remote Crash
Rocky Linux 10 RLSA-2026-67530 .NET 10.0 Important Elevation of Privilege
Rocky Linux .NET 9.0 Important Security Update RLSA-2026-67614
Rocky Linux PostgreSQL Important Security Fix RLSA-2026-67848
Rocky Linux 9 RLSA-2026-54184 grafana Important Denial of Service
Rocky Linux RLSA-2026-67608 leapp-repository Important Security Update
Rocky Linux 9 Kernel Important Security Advisories RLSA-2026-67470
Rocky Linux 9 RLSA-2026-67524 .NET 8.0 Moderate Information Disclosure
Rocky Linux RLSA-2026-67583 Rsyslog Low Configuration Crash Advisory
Rocky Linux 9 .NET 10.0 Important Security Update RLSA-2026-67613
Rocky Linux Grafana Important Privilege Escalation DoS RLSA-2026-54243
Ubuntu 26.04 libheif Important Denial of Service USN-8774-1
Ubuntu python-cryptography Important Cipher Timing DoS Threats USN-8776-1
Debian ThunderBird Important Arbitrary Code Exec Vulnerabilities DSA-6503-1
SUSE gvfs Important OOB Memory Access Vulnern 2026-4200-1
SUSE 12 SP5 pcre2 Important Security Issue Resolution 2026-4201-1
SUSE Corosync Important Buffer Overflow Integer Overflow Vuln 2026-4202-1
SUSE Tomcat Important DoS Authentication Issues Fix 2026-4203-1
SUSE glibc Moderate DoS Buffer Overflow Vuln 2026-4204-1
SUSE lcms2 Low Information Disclosure Threat Advisory 2026-4205-1
SUSE google-cloud-sap-agent Important Denial of Service Vuln 2026-4206-1
SUSE Important kbd Local Privilege Escalation Vulnern 2026-4207-1
SUSE ClamAV Important Security Update Advisory 2026-4208-1
SUSE Containerized-Data-Importer Important Security Update 2026-4209-1
SUSE Alloy Important Security Update for Seven Issues 2026-4210-1
SUSE 15 SP7 kbd Important Local Privilege Escalation Fix CVE-2026-72693
SUSE Important Security Update 2026-4212-1 Fixes 21 Issues
SUSE OpenVPN Important Remote Access Denial of Service Vulnern 2026-4213-1
SUSE 16.0 Helm Important DoS Credential Exfiltration Vulnern 2026-23688-1
SUSE libzypp Critical Cache Issues Vulnern SUSE-SU-2026-23689-1
CISA decides weekly vulnerability bulletin isn’t necessary anymore
If you rely on the Cybersecurity and Infrastructure Security Agency’s weekly vulnerability bulletin to keep you up to date on the latest threats, we have [...]
DSA-6499-1 cjose – security update
Debian MKVToolNix Serious Buffer Overflow CVE-2026-90783
Debian Firefox-ESR Important Code Execution Threats DSA-6501-1
Debian Trixie DSA-6500-1 Tor Denial of Service Vulnerability Fix
Ubuntu 24.04 Perl Important Denial of Service Vulnerabilities USN-8736-2
Google Pixel phones pwned in zero-click attacks
Both Google and Uncle Sam warned that attackers have exploited a zero-day improper authorization bug in Pixel phones’ cellular modems that can bypass [...]
Big Tech’s AI safety rift signals disruption and disparity for enterprises
A growing divide among leading AI companies over how to secure increasingly powerful models is beginning to translate into challenges for enterprise IT, [...]
AWS bets that AI agents need an inbox, not another chat window
AWS is betting that AI agents need a different interface as they move beyond answering prompts and start working autonomously in the background. The [...]
Spain gets its first taste of AI-aided cyber attack
Spain’s data protection agency (AEPD) has reported the country’s first-ever personal data breach caused by the actions of an autonomous AI agent. Francisco [...]
Ministry of Justice apologizes after court staff accessed Southport victims’ files
The Ministry of Justice (MoJ) has apologized after court staff accessed documents relating to victims and survivors of the 2024 Southport murders without [...]
We are all managers now
Career paths for software developers have always been a touch problematic.  Early on, you started out as a junior developer, and maybe there were ladder [...]
How to keep AI-generated code aligned with your standards
One of the first questions I ask devops organizations is to walk me through their development and operations standards. What are the non-negotiable devops [...]
Debian DSA-6496-2 nginx Update Fixes Module Build Regression
Ubuntu 26.04 LTS WebOb Important Redirect Control Issue USN-8759-1
Mythos has made 2026 patching hell. It might make 2027 a breeze
When Microsoft delivered over 970 patches last week, many saw a nightmare for beleaguered security staff. Gartner research vice president Craig Lawson [...]
Hundreds of OpenAI agents attack RubyGems platform
A swarm of hundreds of OpenAI agents uploaded “malicious packages” to RubyGems and tried to steal API keys, the Ruby community gem hosting service revealed [...]
Fedora 43 Erlang Critical Buffer Overflow Updates 2026-02481296e8
Fedora 43 sblim-sfcb Security Flaws in IPC – CVE-2026-73583 CVE-2026-73584
Fedora 43 environment-modules Security Update for CVE-2026-85013
Fedora 43 python-configargparse Vulnerability Exposes Critical Config Data
Fedora 44 Rubygems Important Resolv Denial of Service Vuln 2026-2857104379
Fedora 44 Ruby Important DNS Denial of Service Vuln FEDORA-2026-da06bdeb38
Fedora 44 Erlang Important Multiple Issues 2026-64363fe778
Fedora 44 perl-Authen-SASL Replay Attack Fix CVE-2026-86219 2026-53e2875c88
Fedora 44 sblim-sfcb Key IPC Out-of-Bounds Memory Access and File Issues
Fedora 44 Knot 3.5.8 Important DNS Security Update 2026-4782ac1f8b
Fedora 44 Environment-Modules Update CVE-2026-85013 Severity High
Fedora 44 python-configargparse Security Update for Config Disclosure Issue