Menu

Latest articles

Oracle Linux glib2 Moderate D-Bus Buffer Overflow Patch ELSA-2026-57015
Oracle perl-Date-Manip Important DoS Fix ELSA-2026-56971
Oracle Linux PHP 8.4 Important Bug Fix Advisory ELSA-2026-56969
Oracle Linux 9 .NET 10.0 Bug Fix Important Advisory ELSA-2026-55857
Oracle Linux MySQL 8.4 Important Bug Fix Advisory ELSA-2026-56007
Oracle Linux curl Important Update ELSA-2026-55450 Fixing Multiple Issues
Oracle Linux 10 yggdrasil Important CVE-2026-33810 Advisory ELSA-2026-57126
Oracle Kernel Important Advisory ELSA-2026-38492 CVE-2026-43163
Oracle Linux Nodejs Important Memory Exhaustion Fix ELSA-2026-55603
Oracle Linux 9 ELSA-2026-55856 .NET 9.0 Important Security Advisory
Oracle Python3 Important CVE-2026-11940 Advisory ELSA-2026-56219
Oracle Gstreamer1 Plugins Good Moderate Buffer Overflow 2026-56966
Oracle Linux 9 Node.js Essential Update for CVE-2026-69192 ELSA-2026-55601
Oracle Linux 9 pcp Important Command Injection Issues ELSA-2026-55740
Oracle Linux 9 bind9 Important DNS Fixes ELSA-2026-55442
Oracle Linux 9 glib2 Moderate Security Update ELSA-2026-55440
Oracle curl Important Fix for ELSA-2026-55439 in Oracle Linux 9
Oracle Linux 8 Gstreamer1-Plugins-Bad-Free Key Updates ELSA-2026-56521
Oracle Linux 8 nghttp2 Moderate HTTP Smuggling Advisory ELSA-2026-55804
Oracle Linux 8 ELSA-2026-56133 attr Moderate Privilege Escalation
Oracle Linux 8 ELSA-2026-56131 pam Moderate Session Management Fix
Oracle 8 Kernel Moderate Update for CVE-2026-45991 ELSA-2026-54246
Oracle Linux 8 ELSA-2026-56130 sg3_utils Important Bug Fix
Oracle Linux 8 pcp Important Fixes for Vulnerabilities ELSA-2026-55560
Oracle Linux 8 ELSA-2026-55446 libXfont2 Important CVE Fix
Rocky Linux 8 GStreamer1 Plugins Experience Moderate Memory Growth Issue
Rocky Linux 8 java-21-openjdk Moderate HTTP TLS Upgrades RLSA-2026-55787
Slackware mozilla-thunderbird Critical Security Issues Fix 2026-231-02
Slackware Mozilla-Firefox Critical Security Fix SSA-2026-231-01
Gentoo acl attr Multiple Vulnerabilities GLSA-202608-20
Gentoo quickjs-ng High Multiple Code Execution Threat GLSA-202608-19
Rocky Linux 9 RLSA-2026-56973 MySQL Important Performance Issues
Gentoo Emacs High Arbitrary Code Execution Risk GLSA-202608-18
Gentoo libssh2 High Remote Code Execution Vulnerability GLSA-202608-17
Rocky Linux mysql Important Security Patch RLSA-2026-56936
Debian 12 Swift Security Update DLA-4746-1 Addresses SSRF DoS Risks
Debian Highlights Key DNS Hijacking Denial of Service CVEs 6452-1
Ubuntu nginx USN-8563-4 Regression Denial of Service Advisory
Ubuntu curl Important Sensitive Data Exposure USN-8651-1 CVE-2026-11856
Ubuntu libpng Critical DoS Threats Addressed USN-8639-1
Ubuntu 26.04 Cap’n Proto Important HTTP Request Smuggling Issues USN-8650-1
Debian DSA-6451-1 Firefox-esr Critical Code Execution Issues
SUSE open-iscsi Important Auth Bypass & Remote File Write Vuln 2026-3647-1
SUSE python311 Important Security Patch Regression Fix SUSE-SU-2026-3648-1
SUSE Python313 Important DoS and Injection Risks Fixed Advisory 2026-3649-1
DSA-6452-1 designate – security update
US Bank investigates LockBit’s claims as ransomware crims set pay-or-leak deadline
US Bank says that it’s investigating ransomware crew LockBit’s claims that it breached the financial institution and stole data, which the crims [...]
Researcher tricks Apple’s Find My into sharing location data with Linux
A young security researcher figured out a way to enroll a Linux device into Apple’s Find My network and read live location data from it. Find My is Apple’s [...]
Ransomware crook poses as recovery firm to steal payments from fellow extortionists
A ransomware affiliate appears to have found a new way to squeeze victims for cash: pose as the good guy and undercut the criminals it was working with. [...]
Ubuntu PostgreSQL Critical Buffer Overflow SQL Injection Vuln 8653-1
Grok chat duped into swallowing injected instructions
xAI’s Grok web chat agent is currently vulnerable to a novel form of prompt injection, according to security researchers with Adversa AI. The [...]
TrueFoundry debuts open-source AI agent harness, claiming up to 75% lower costs
TrueFoundry has launched TrueForge, an open-source agent harness that lets developers build and run AI agents using models from different providers, [...]
French tax authority says break-in exposed data of 600K, including some private messages
France’s tax authority says attackers may have stolen the contents of messages exchanged with hundreds of taxpayers during the data raid it confirmed [...]
openSUSE openssl-3-livepatches Important DoS Patch 2026-3651-1
SUSE OpenSSL-3 Livepatches Important DoS Security Update 2026-3651-1
openSUSE Podman Important Environment Leak Access Risk 2026-3652-1
SUSE Podman Important Host Environment Leak and Symlink Issues 2026-3652-1
Anthropic’s Opus language problems may be creating a hidden cost for AI coding
AI coding assistants are supposed to reduce the work required to turn a developer’s intent into working software. But some users of Anthropic’s Opus 4.8 [...]
The five walls standing between a demo agent and a deployed one
Building an AI agent that looks impressive in a demo is now a weekend project. Building one that an enterprise will actually let touch its CRM, its data [...]
Introducing G#: A Go-like language for .NET
Microsoft’s open sourcing of .NET not only has sped up the development of the platform, but also has allowed new languages and features to be built on top [...]
Nobody’s agent fleet fails the way the vendors say it will
I run 49 scheduled AI agents on one laptop. Another 24 sit beside them, deliberately switched off. That distinction matters more than it sounds. After [...]
AI agent suggested installing a malware package. Engineer almost took its advice
PWNED Welcome back to PWNED, the column where we make fun of those who are security self-owned, so hopefully you don’t do the same. This week, we have a [...]
DSA-6454-1 sabnzbdplus – security update
DSA-6453-1 libgit2 – security update
Smashing Security podcast #481: Never say this to a robot dog
‘Not a theoretical risk,’ feds warn as attackers use AI-made code to hack critical infrastructure controllers
Attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, [...]
DSA-6450-1 srt – security update
DSA-6449-1 swift – security update
Linux Identity, Privilege & Administrative Access
Access to a Linux system involves several connected decisions. The system must determine who or what is requesting access, verify that identity, decide [...]
ICE boss to agents: Leave the Meta spy glasses at home
Some ICE employees seemingly needed a reminder not to wear their Meta pervert glasses to work. Because only ICE can spy on ICE. Meta smart glasses are [...]
Flock surveillance backlash mounts as fiendish Halloween plans circulate
Surveillance tech company Flock has struggled with its public image for years, but the problem has become particularly acute in recent weeks. Its network [...]
Mageia 10 lsp-plugins Bug Fix Advisory Release 2026-0101 Update
Ubuntu Bind9 Security Advisory USN-8648-1 CVE-2026-10723 CVE-2026-10822
Ubuntu Nginx Important DoS Injection Flaws USN-8563-3 CVE-2026-42533
Ubuntu libheif Important Denial of Service Vulnerabilities USN-8649-1
Comcast gives its Wi-Fi motion detector a security makeover
Comcast has folded its Wi-Fi-based intruder detection feature into Xfinity Shield, a repackaged bundle of physical and cybersecurity offerings. The US [...]
Ubuntu 26.04 introduces vital fixes for LibTIFF denial of service flaw
Ubuntu 26.04 libssh Important Denial of Service Vulnerability USN-8093-2
Decoding Origin: Cursor’s GitHub rival that was launched during the latter’s outage
AI coding tools are increasingly becoming the place where developers write and modify software. SpaceX-owned Cursor now wants to bring code hosting into [...]
Fix for Test Failure in Debian LTS ruby-grape DLA-4706-2 Update
Rocky Linux 8 pam Moderate Plaintext Recovery Threat RLSA-2026-56131
Rocky Linux 8 attr Medium Symlink Traversal Fix RLSA-2026-56133
Rocky Linux 8 sg3_utils Important Command Execution Fix RLSA-2026-56130
Rocky Linux 8 RLSA-2026-56219 Python3 Important Security Issue
Rocky Linux gstreamer1-plugins-bad-free Heap Overflow CVE-2026-19387 Alert
Rocky Linux 9 .NET 10.0 Important Security Update RLSA-2026-55857
Rocky Linux 9 RLSA-2026-55856 .NET 9.0 Important Security Update
AI inference: Five best practices for successful AI applications
While some organizations are still getting started with their AI strategies, others are in pilot purgatory, with few experiments or proofs of concept [...]
Coding agents make mistakes. So what?
Regular readers will probably have figured out that I’m generally an optimist. I think things are always getting better, and the future of the human race [...]
Prison for data analyst who tried to extort $2.5 million from his employer
Ubuntu dotnet Important Request Smuggling Information Disclosure 8641-1
Australian hotel chain leaks guests’ PII after breach at third-party database operator
Australian aparthotel chain Quest has revealed it leaked customer data. A Reg reader kindly shared an email from the chain with the subject line “Important [...]
AI’s attribution problem gets worse as models scale
Diffusion models are becoming sophisticated enough that they can reproduce an image even when they don’t have access to the original. In a series of ‘what [...]
Fedora 43 Python 3.14.7 Security Advisory 2026-7f32bbb5b0
Fedora 43 libnfs Security Advisory CVE-2026-57918 CVE-2026-53689
Fedora 43 Lemonldap-ng Update Advisory CVE-2026-19349 Security Fix
Fedora 43 perl-List-SomeUtils-XS Critical Heap Overflow Fix 2026-6217093b91
Fedora 43 radsecproxy Bug Fix Update 2026-057cd843d0 Released Now
Fedora 43 perl-Imager Important EXIF Decode Fix CVE-2026-19082
Fedora 44 Python 3.12 Update Critical Denial of Service Fix 2026-a9f0296a41