Menu

Latest articles

DSA-6481-1 firefox-esr – security update
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from [...]
I’ve been deepfaked: What do I do?
Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal
Drowning in CVEs and thirsty for answers? Try CTEM
A decade or two ago, board executives asked “why should I care about cybersecurity?” Five years ago, they were asking “Are you patching [...]
Cybercrooks trawl Fishbrain to net password hashes
Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking [...]
Meta upgrades Muse Spark for long-horizon coding without raising API prices
Meta is upgrading its Muse Spark family with a new model aimed at long-horizon coding tasks and agentic software development while keeping its standard API [...]
UK’s Online Safety Act has made ‘absolutely no difference,’ kids say
Children have told England’s Children’s Commissioner, Dame Rachel de Souza, that the UK’s Online Safety Act (OSA) “has made [...]
How to keep your mission-critical cloud workloads running
Entrusting mission-critical workloads in the cloud puts a lot of pressure on IT operations to build resilience into data infrastructure they don’t even own [...]
Running AI agents in sandboxes with Microsoft Execution Containers
One of the problems facing those who develop agents today, especially when building agents that run on edge systems with a mix of local and cloud AI, is [...]
TechCrunch Disrupt: What’s next for AI and software development
First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code [...]
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
PWNED Welcome back to PWNED, where we talk about organizations that are independently self-owned. This week’s tale of toxic tech involves a disgruntled [...]
To keep the AI hacking genie bottled up, try one-way networks
To prevent frontier AI models breaking out of test environments and collaborating to hack other companies, we may have to rethink the network architectures [...]
Oracle Linux 9 wget Moderate Buffer Overflow Fix ELSA-2026-62143-0
Oracle Linux 9 gimp Important Fixes for Vulnerabilities ELSA-2026-61587-0
Oracle Linux 9 iperf3 Important JSON Value Check Fix ELSA-2026-61389-0
Oracle Linux 9 nodejs Important Security Patch ELSA-2026-61386-0
Oracle Linux 9 Nodejs Security Advisory ELSA-2026-61383 Critical CVEs
Oracle Linux 9 freerdp Important CWCVEs Buffer Overflow ELSA-2026-61379-0
Oracle Linux 9 xmlrpc-c Important HTML Injection Fix ELSA-2026-61316-0
Oracle Linux 9 Pipewire Moderate Security Advisory ELSA-2026-61240-0
Oracle Linux 9 Golang Important Bug Fix Advisory ELSA-2026-60304-0
Oracle Nginx Important Denial of Service Fix ELSA-2026-59490
Important CVEs for Oracle Linux 9 xorg-x11-server-Xwayland ELSA-2026-38490
Oracle Linux 10 wget Moderate Bug Fixes Advisory ELSA-2026-62142-0
Fedora 45 Dracut Essential Root Privilege Correction 2026-5bf73fe397
rustup 1.29.1 brings concurrency improvements
The team behind the rustup installer for the Rust programming language has released an update to the command-line utility. Announced September 1, rustup [...]
Fedora 44 Syncthing CVE-2026-40898 Denial of Service Advisory
Fedora 44 NSS Heap Buffer Overflow Patch Update 2026-42a3a95e62
Fedora 44 Firefox Important Heap Buffer Overflow Vuln 2026-42a3a95e62
Fedora 44 mingw-gstreamer1-plugins-good Remote Code Execution Vulnerability
Fedora 44 mingw-gstreamer1-plugins-base Has Serious Remote Code Exec Risks
Fedora 44 mingw-gstreamer1 Critical Remote Code Exec Issues 2026-e6ca27403f
Fedora 44 mingw-gstreamer1-plugins-bad-free Critical Remote Code Execution
Fedora 44 mingw-expat Denial of Service Fix Update 2026-f5e2a6b9b5
Fedora 44 mingw-openexr Update Addresses Integer Overflow Vulnerability
Fedora 44 ProFTPD Security Bugfix Advisory 2026-f073efe2f3
Fedora 43 gvfs Critical Heap Overflow Disclosures and Fixes 2026-571b7e1505
Fedora 43 Exiv2 Bugfix Denial of Service Issues 2026-2854e48ee4
Fedora 43 nss Important Heap Buffer Overflow Advisory 2026-208add2041
Fedora 43 Firefox Heap Overflow Security Advisory 2026-208add2041
Fedora 43 FreeRDP Update to 3.31.0 Advisory FEDORA-2026-e0f5d28f57
Fedora 43 mingw-gstreamer1 Plugins Vulnerability High Risk RCE Alert
Fedora 43 mingw-gstreamer1-plugins-base Critical RCE Vulnerability Update
Fedora 43 mingw-expat Update Denial of Service CVE-2026-72522 Advisory
Fedora 43 mingw-openexr Denial of Service and Overflow Vulnerabilities
Fedora 43 ProFTPD Update Important FTP Bugfixes FEDORA-2026-0abbe10cdc
SUSE Texlive Moderate Heap Use-After-Free CVE-2026-63729 2026-3924-1
SUSE Bzip2 Low Off-By-One Error Issue Vulnerability 2026-3925-1
DSA-6482-1 chromium – security update
Why Patched Linux Servers Still Fail a Penetration Test
A patched Linux server can still fail a penetration test because patch status cannot show whether an attack path remains open.
How to Prevent DNS Leaks and Secure Proxy Credentials on Linux Systems
Using a proxy on Linux changes how web traffic reaches its destination, but it does not automatically protect every part of the connection. DNS requests [...]
Smashing Security podcast #483: This AI helps thieves steal your iPhone
Rocky Linux 10 Kernel Advisory RLSA-2026-61887 Important Security Fixes
Rocky Linux Nodejs Key Filesystem Access Memory Issues RLSA-2026-62583
Rocky Linux GIMP Important Remote Code Exec Advisory RLSA-2026-62507
Ubuntu 18.04 LTS Linux Kernel Important WiFi Injection Threat USN-8715-1
Ubuntu 20.04 18.04 Kernel Important Threat Correction USN-8714-1
Ubuntu 20.04 Linux Kernel Important WiFi Issue USN-8661-4
Claude Mythos only model to complete full cyber kill chain, experts say
Despite what we saw with OpenAI’s models going rogue, creating message boards, and breaking into Hugging Face, only one advanced AI model – [...]
Debian Firefox-ESR Critical Issues Execution CVE-2026-16365 DSA-6481-1
DSA-6480-1 keystone – security update
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
A human ransomware crook used frontier AI models to breach an enterprise network in less than 10 hours, an intrusion Unit 42 says would normally take human [...]
SUSE dovecot22 Critical Denial of Service Issues Fix Advisory 2026-3919-1
SUSE libgcrypt Moderate DoS Issue Fix Advisory SUSE-SU-2026-3921-1
SUSE vim Key Security Update Mitigates Risks of Code Execution 2026-23391-1
SUSE Linux Micro 6.2 Gzip Moderate Buffer Overflow Vuln 2026-23392-1
SUSE vim Important Security Fixes Advisory 2026-23393-1 CVE-2026-73070
SUSE dhcpcd Moderate Memory Leak and DoS Vuln 2026-23400-1
SUSE Python Cryptography Moderate PKCS#7 Timing CVE-2026-69247
SUSE udisks2 Significant Local Privilege Escalation Patch 2026-23405-1
SonicWall’s SMA1000 boxes under active attack again
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and [...]
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration. In an email sent to affected [...]
Google brings predictive AI to BigQuery without the ML training
Google is adding a pre-trained foundation model for tabular data to BigQuery, allowing enterprise teams to generate predictions from structured data [...]
5 ways to augment security risk management in the AI era
IT operations and security teams receive thousands of alerts every day from threat intelligence sources, such as vulnerability scanners, observability [...]
UK cyber bill targets AI users, not the vendors building it
The UK government has rejected proposals from members of the the House of Lords to bring AI vendors within the scope of the Cyber Security and Resilience [...]
Claude Code has left a little hole in my soul
I built a complete, working application in a day this past weekend.  Well, less than a day if you don’t count the time I spent waiting on Claude Code to do [...]
Seven critical vibe coding mistakes — and how to avoid them
Vibe coding an application or an AI agent sounds too good to be true. A single developer prompts their way through a plan and has the code for a working [...]
Oracle Linux 10 Nodejs Key Security Update ELSA-2026-61376-0 CVEs
Oracle Linux 10 ELSA-2026-38489 Important Xwayland CVE Fix
Oracle Linux 9 Gzip Moderate Buffer Overflow Vuln ELSA-2026-61623-0
Oracle glib2 Moderate Buffer Overflow Fix ELSA-2026-61766-0 CVE-2026-15588
Oracle Linux 8 mingw-sqlite Important Update for CVE-2026-11822
Oracle 8 xorg-x11-server Important CVE-2026-55999 ELSA-2026-38487 Fix
Linux Patch Addresses SA2UL Stack Overflow Found in IPsec Setup
A version 2 Linux kernel patch posted on August 31 fixes a stack overflow in the SA2UL hardware crypto driver. The Kernel Address Sanitizer, or KASAN, [...]
Linux Patch Targets RxRPC Teardown Race During Namespace Exit
RxRPC is a Linux kernel transport for remote procedure calls. A teardown race reported in August shows that its network namespace cleanup can still reach a [...]
Linux Patch Proposes Landlock Policy Objects for eBPF at Exec
A version 2 Linux kernel patch series posted on August 31 proposes a new eBPF security interface for applying Landlock policy during program execution. The [...]
Anthropic makes changes to stop AI agents running amok again
Learning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment [...]
Slackware pcre2 Security Update Advisory 2026-244-01 Released Today
Fedora 44 Cockpit Important Memory Leak Fix Advisory 2026-4ca90cfeb9
Fedora 44 gdk-pixbuf2 CVE-2026-81893 Critical Invalid Write
Fedora 44 Emacs Critical Local Command Injection CVE-2026-79992
Fedora 44 OpenSSL 3.5.8 Security Update Advisory 2026-51251b4657
Fedora 44 python-linkify-it-py Security Fix CVE-2026-48801 CVE-2026-59887
Fedora 44 python-llm Arbitrary Code Execution Advisory 2026-4f3301f569
Fedora 44 openvkl Important Heap Overflow Vulnern CVE-2026-21399
Fedora 44 rkcommon Critical Buffer Overflow Advisory 2026-9f32915b09
Fedora 43 Bubblewrap Update Resolves SIGCHLD Subprocess Management Issue
Ubuntu 26.04 LTS SSSD Crash Due to Smartcard Interaction USN-8672-1
SUSE yast2-auth-client Important Command Injection Advisory 2026-3914-1