Menu

Latest articles

CISA updated ransomware intel on 59 bugs last year without telling defenders
A slippery slope: Beware of Winter Olympics scams and other cyberthreats It’s snow joke – sporting events are a big draw for cybercriminals. Make sure you’re not on the losing side by following these best practices.
X marks the raid: French cops swoop on Musk’s Paris ops
Microsoft finally sends TLS 1.0 and 1.1 to the cloud retirement home
Polish cops bail 20-year-old bedroom botnet operator
DIY AI bot farm OpenClaw is a security ‘dumpster fire’
British military to get legal OK to swat drones near bases
xrdp is an open source RDP server. It was found that xrdp contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code
Several security issues were fixed in CRaC JDK 21.
Several security issues were fixed in OpenJDK 21.
Several security issues were fixed in OpenJDK 8.
Several security issues were fixed in OpenJDK 11.
15.x 15.1 (2026-01-24) Fix #15088: When building a new train, the refit button state may be incorrect (#15162) Fix #15160: Incorrect company names displayed in load game window (#15161)
Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor
StopICE hacked to send alarming text messages, admins accuse border patrol agent of sabotage
Russia-linked APT28 attackers already abusing new Microsoft Office zero-day
McDonald’s is not lovin’ your bigmac, happymeal, and mcnuggets passwords
OpenClaw patches one-click RCE as security Whac-A-Mole continues
Notepad++ update service hijacked in targeted state-linked attack
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
Infrastructure cyberattacks are suddenly in fashion. We can buck the trend
AI will not save developer productivity
How should AI agents consume external data?
An update that solves five vulnerabilities and contains one feature can now be installed.
An update that solves five vulnerabilities and contains one feature can now be installed.
An update that solves three vulnerabilities can now be installed.
Why native cloud security falls short
An update that fixes one vulnerability is now available.
Open-source AI is a global security nightmare waiting to happen, say researchers
Enterprise Spotlight: Manufacturing Reimagined
AI security startup CEO posts a job. Deepfake candidate applies, inner turmoil ensues.
Multiple vulnerabilities have been found in Pillow, an image processing library for Python. CVE-2021-23437 The getrgb function is susceptible to a ReDoS. CVE-2022-24303
Ceph is a distributed object, block, and file storage platform. CVE-2022-0670 A flaw was found in Openstack manilla owning a Ceph File system “share”, which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the
Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2025-67724 Custom reason phrases can cause multiple vulnerabilities (like XSS, header injection, …) due to being used unescaped in HTTP headers.
Update to 0.46.3, fixes CVE-2026-24049.
Security fix for CVE-2026-24049
Fix CVE-2025-15536
This month in security with Tony Anscombe – January 2026 edition The trends that emerged in January offer useful clues about the risks and priorities that security teams are likely to contend with throughout the year
DynoWiper update: Technical analysis and attribution ESET researchers present technical details on a recent data destruction incident affecting a company in Poland’s energy sector
FBI takes notorious RAMP ransomware forum offline
MGAA-2026-0008 – Updated remove-old-kernels packages fix bugs
AI use may speed code generation, but developers’ skills suffer
https://security-tracker.debian.org/tracker/DSA-6117-1
Moderate: glibc security update
Important: openssl security update
Moderate: curl security update
Important: openssl security update
Moderate: gcc-toolset-15-binutils security update
January blues return as Ivanti coughs up exploited EPMM zero-days