Menu

Latest articles

DSA-6537-1 libpng1.6 – security update
DSA-6536-1 thunderbird – security update
DSA-6535-1 chromium – security update
DSA-6534-1 webkit2gtk – security update
OpenAI alerts 100+ orgs that its ‘misaligned models’ attempted to break in – or worse
OpenAI’s agents have repeatedly strayed beyond their intended scope. Two separate reports detail the activity, including one from Sam Altman’s [...]
Californian accused of shipping $300M worth of Nvidia chips to China without Uncle Sam’s approval
A California business owner was arrested on Thursday after being charged with allegedly smuggling Nvidia hardware to China without the proper export [...]
OpenAI’s wandering AI agents earn it a California subpoena
California’s attorney general has subpoenaed OpenAI as the state investigates what happens when the AI lab’s models escape their testing [...]
IBM’s Bob wants to move in: Agent available for on-prem deployment
Bob, IBM’s agentic software development platform is now available to run on premises and in private clouds, sovereign clouds, and air-gapped environments [...]
367,000-Ship Study Finds Global GPS Spoofing, Red Sea Activity Before Grounding
Fortinet sounds the alarm over actively exploited FortiMail zero-day
Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems [...]
AI is less dangerous than humans
Over the past few weeks, people have been pushing a stack of reports at me as evidence that AI is dangerous to humanity. The OpenAI incident disclosures, [...]
AI could boost software engineer productivity by 32.6%
Tools such as Anthropic Claude Code or OpenAI Codex have changed the face of software development, and all the signs are that this investment is set to [...]
Debian libio-compress-perl Critical CPU Exhaustion and Code Exec DLA-4812-1
Fedora 44 sos CVE-2026-79655 Path Traversal Security Fix
SUSE libX11 Important Buffer Overflow and Out-of-Bounds Issues 2026-4410-1
SUSE Python Moderate Denial of Service Security Patch 2026-4411-1
Proposed Linux IPsec Fix Addresses IP-TFS Packet Cleanup Race
Linux developers have proposed an IPsec fix after reproducing a memory error in IP-TFS, a mode that groups and pads encrypted traffic to make traffic [...]
DSA-6540-1 radsecproxy – security update
DSA-6539-1 php-mongodb – security update
DSA-6538-1 redis – security update
Proposed Linux FastRPC Fix Addresses Shared-Buffer Cleanup Race
Linux developers have proposed a FastRPC fix for a race that can leave the kernel using memory after it has been released.
Proposed Linux QNX6 Fixes Address Filesystem Memory Errors
Linux developers have proposed six fixes for the driver that reads QNX6 filesystems, a disk format associated with the QNX operating system.
LightLLM Profiling Flaw Allows Code Execution Without a Login
LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for [...]
Debian Bookworm Chromium Security Vulnerability Poses Code Execution Risk
Debian LTS DLA-4810-1 Thunderbird Security Vulnerabilities Addressed
ModSecurity Updates Fix WAF Bypasses on Linux Web Servers
ModSecurity has released fixes for a group of web application firewall (WAF) weaknesses that can let dangerous input reach Linux-hosted applications [...]
Rocky Linux 8 Kernel-rt Moderate Security Updates RLSA-2026-74132
Rocky Linux Thunderbird Significant Security Patch RLSA-2026-73971
Rocky Linux 8 Rsync Important Command Injection Issues RLSA-2026-74095
Rocky Linux 8 Kernel Moderate Security Update RLSA-2026-74133
AI agents hacked the hackers, stealing email addresses from security research org
AI agents hacked the hackers – the Dutch Institute for Vulnerability Disclosure (DIVD) – via two zero-day bugs in its Zammad support platform, [...]
SUSE glibc Important Security Update for Nine Issues 2026-23929-1
SUSE Important glibc Security Update Vulnerabilities 2026-23934-1
SUSE Linux Enterprise 16 Kernel Important Security Update 2026-23936-1
SUSE Linux Enterprise 16.0 Kernel Important Security Patch 2026-23937-1
SUSE Linux Enterprise 16 Important Kernel Security Update 2026-23938-1
SUSE Kernel Important Update 2 for Six Vulnerabilities 2026-23939-1
SUSE Kernel Security Update Addressing Important Fault Fixes 2026-23940-1
SUSE Linux Kernel Important Patch for Multiple Vulnerabilities 2026-23941-1
SUSE Kernel Important Security Update 2026-23942-1 Fixes Multiple Threats
SUSE php-composer2 Moderate Path Traversal Threat Vuln 2026-23943-1
SUSE Linux Enterprise Kernel Important Security Update 2026-23944-1
SUSE perl-Protocol-HTTP2 Important DoS Memory Exhaustion Vuln 2026-23945-1
SUSE rpcbind Important Denial of Service Vuln 2026-23946-1
SUSE ImageMagick Important Denial of Service Issues Fix 2026-23948-1
SUSE Emacs Important Arbitrary Code Execution Vuln 2026-23949-1
SUSE gnome-shell Moderate CVE-2026-91786 Vulnerability Fix 2026-23950-1
SUSE Kernel Important Security Fix 2026-23951-1 for Multiple Issues
SUSE perl-DBI Important Arbitrary Module Loading Fix 2026-23952-1
SUSE glibc Important Buffer Overflow Threat Fix 2026-23957-1
SUSE Important rpcbind Denial of Service Vulnerability Fix 2026-23959-1
SUSE Linux Enterprise 16 Kernel Important Security Update 2026-23960-1
SUSE Linux Enterprise 16 Important Kernel Security Update 2026-23961-1
SUSE Kernel Important Security Update Live Patch 9 CVE-2026-46150
SUSE Kernel Important Security Update CVE-2026-46150, 2026-23963-1
SUSE Enterprise 16 Kernel Important Security Update SUSE-2026-23964-1
SUSE Kernel Important Security Issues Fix Advisory 2026-23965-1
SUSE Kernel Important Security Update 2026-23966-1 Includes CVE-2026-46150
SUSE Kernel Important Security Fix Advisory 2026-23967-1
SUSE Linux Kernel Important Security Update 2026-23968-1
Microsoft, Google back Apache Ossie to make enterprise data and AI platforms more interoperable
Microsoft and Google are joining a project to create an open specification for exchanging semantic models across data, analytics, and AI platforms. The [...]
KillSec Ransomware Group Dismantled, 16-Year-Old Suspected Admin Arrested
openSUSE Chromium Important Buffer Overflow Patch 2026-0343-1
Debian libpng Use-After-Free Denial of Service Vulnerability DSA-6537-1
Debian Thunderbird Critical Arbitrary Code Exec Advisory DSA-6536-1
Debian Chromium High Remote Code Execution Service Disruption DSA-6535-1
EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank
Depending on Chinese technology for European infrastructure poses risks that not every country takes seriously. So says the Royal United Services Institute [...]
This month in security with Tony Anscombe – September 2026 edition
Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year’s worth of security patches in one go – here’s how to [...]
Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
A suspected Chinese espionage group impersonated AI policy figures, including a senior Anthropic employee and a former White House official, in phishing [...]
Rocky Linux 10 openssh Moderate Auth Delay Risk RLSA-2026-73954
Rocky Linux gvfs Important Buffer Overflow Risks RLSA-2026-73998
Rocky Linux Node.js 24 Important Security Fix RLSA-2026-73428
Rocky Linux 10 dogtag-pki Important Code Execution Fix RLSA-2026-73765
Rocky Linux 10 RLSA-2026-74001 Expat Critical Denial of Service Risk
Rocky Linux 9 pki-core Important Code Execution Risk RLSA-2026-73766
Rocky Linux 9 RLSA-2026-73955 OpenSSH Moderate Authentication Issue
New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords
Microsoft catches hackers exploiting Zimbra bug before disclosure
Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, [...]
Why Mobile Device Management Needs Its Own Threat Model
MI5 warns UK academics their research may have helped Chinese spies
MI5 has warned that more than 100 UK-linked academics contributed to research projects allegedly funded to improve China’s spying capabilities. The [...]
Google makes Gemini 4 AI model available to a trusted few
Google has unveiled a new frontier AI model after months of delay. Gemini 4 Argon is designed to handle complex, long-horizon workloads spanning software [...]
CISO thought he had a ‘r3@lg00dp@$$w0rd’ but forgot to patch
Welcome back to PWNED, the weekly column where we warn you about weak security practices. This week’s terrifying tale involves a lack of important patching [...]
England’s schools are getting better at mopping up cyber incidents
England’s secondary schools are reporting slightly fewer cybersecurity incidents and faster recovery when disaster strikes, according to a survey by [...]
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader
ShinyHunters suspect arrested, and is now investigated over alleged murder plots
UK privacy watchdog starts over with new board and Manchester HQ
Britain’s data protection watchdog has acquired a new legal identity and governance structure, although the familiar ICO initials are staying put. On [...]
Ubuntu 22.04 LTS Advisory USN-8818-4 Important Privilege Escalation Patch
Ubuntu 20.04 LTS Kernel Security Issues with CVE-2025-38724
Ubuntu 22.04 LTS Linux Kernel FIPS Update USN-8730-7 CVE-2026-53131
Japanese Car-Sharing Site Times Car Data Breach Affects 6.6M Accounts
Ubuntu Linux Kernel 5.15 Critical Privilege Escalation Risk USN-8849-1
Ubuntu 24.04 Linux Kernel Important Local Privilege Escalation 8817-2
Ubuntu 8819-4 Linux Kernel FIPS Important Network & System Threat Fixes
Ubuntu 20.04 LTS Linux Kernel Security Advisory USN-8850-1
Fewer women than ever in UK’s ‘old boys’ club’ cyber industry
The proportion of workers in the UK cybersecurity industry identifying as women has dropped to 16 percent, the lowest level since 2021. Gender diversity [...]
Microsoft doubles down on Rust
After many years of watching how Microsoft develops platforms and rolls out technologies to external users, one thing is clear: anything that is important [...]
The dream of enterprise semantics: Why this time is different
In most companies, the struggle to answer a new question fast has nothing to do with a lack of data. The problem is a lack of semantics. Or to put it [...]
OpenAI bets enterprises are ready to delegate real work to autonomous agents
OpenAI says true agentic AI has finally arrived, pushing beyond the trivial capabilities of early-stage virtual assistants. This week at OpenAI Dev Day, [...]
Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative
Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else
OpenAI, which hoovered up vast amounts of internet content amid copyright fights, has accused individuals associated with China’s Moonshot AI of being [...]