Menu

Latest articles

DSA-6530-1 pcre2 – security update
DSA-6529-1 libwebsockets – security update
Timeshare exit scams: From fake buyers to recovery fraud
Con artists are targeting timeshare owners who want out – and some victims are hit twice
Unsloth’s model picker had a code-execution problem
True to its name, AI-model-training tool Unsloth would do more work than it was asked to when developers checked out a model: It would also allow arbitrary [...]
Securing AI agents requires securing the systems around them
Enterprise AI is changing from software that primarily generates information to software that can take action. AI agents can call APIs, invoke tools, [...]
GitLab Patches Critical CI/CD Flaws That Can Run Code on Servers
Two critical GitLab flaws can turn authenticated continuous integration and delivery (CI/CD) configuration into code execution on self-managed servers.
Amazon Prime Phishing Scam Uses Fake Billing Alert to Steal Logins and Card Details
Pentagon personnel database breach exposes personal data of millions
More than half of UK businesses lack confidence in basic cyber skills
More than half of UK businesses lack confidence in their ability to perform at least one basic cybersecurity task, according to the government’s [...]
AI cuts software developers some slack
My mom used to say that Hodges’s law was “Junk expands to fill the space allotted for it.” We lived in three houses over the years, each one bigger than [...]
Validating AI models and agents with property-based testing
Testing deterministic systems is relatively straightforward. Create an assertion that the system should pass, and automate validating it against a series [...]
Observability for AI-native systems: New SLIs beyond latency and error rate
When HTTP 200 means nothing An AI assistant can return a response in under a second, maintain 99.9% availability and still give customers a fabricated [...]
8 Top Red Teaming Service Providers for Enterprise Adversary Emulation
UK rail cops’ £320K face-scanning spree nets zero matches
British Transport Police (BTP) spent more than £320,000 putting half a million commuters through live facial recognition cameras, only for the system to [...]
Spectre bug is back, this time to haunt JIT engines
The Spectre microarchitecture vulnerability has returned yet again, this time to vex just-in-time (JIT) engines that generate machine code for browsers, [...]
Ubuntu 26.04 LTS libdbi-perl Critical DoS and Code Exec Vuln 8841-1
Mageia 10 Whatsie Bugfix Update Dark Theme Issue 2026-0140
Mageia 10 9 urpm-ng Bugfix Migration Advisory 2026-0139
Fedora 43 libxmp Medium Playback Bugfix Advisory 2026-47ffcebe44
Fedora 43 Thunderbird Software Upgrade with version 2026-a387125860
Fedora 43 RootlessKit Update DoS Fix CVE-2026-56855 & CVE-2026-78662
Fedora 43 sngrep Critical Buffer Overflow Fix CVE-2026-90558
Fedora 43 perl-Imager Key Concerns with TGA Color Map and Palette
Fedora 43 Parted Update Severity Important Partition Fix CVE-2026-89085
Fedora 44 libxmp Medium Bugfix Release for Security Issue 2026-c40eb5767e
Fedora 44 sngrep 1.8.4 Buffer Overflow Fix Advisory 2026-3ff086aa2a
Fedora 44 flatpak-builder 1.4.12 Update Advisory 2026-9b73fdb8e6
Fedora 44 perl-Imager Update CVEs 2026-93019 2026-93018 Security Advisory
Fedora 44 rootlesskit Denial of Service Issues Resolved 2026-3e60aed77e
Linux Perf Filter Can Expose the Kernel’s Randomized Address
A newly reported Linux perf filter flaw lets an unprivileged user find where the kernel is loaded on a tested x86-64 configuration.
Meta’s next big AI bet is enterprise; its biggest hurdle may be trust
Meta is once again repositioning itself to target the enterprise market. This week, the company announced the Meta Enterprise Platform, which it says will [...]
Linux File Truncation Patch Targets Data Loss Beyond the Requested Range
A Linux patch series addresses how file truncation or hole punching could discard valid data beyond the range an application asked to remove.
Linux Tracing Patch Addresses a Probe Use-After-Free Race
A proposed Linux tracing patch addresses a race that could free a function probe while its return callback is still using it.
Fedora 45 Cinnamon Refresh Rebuild for libxdo 2026-c836eb1b43
Fedora 45 xdotool Important Security Advisory 2026-c836eb1b43
Fedora 45 GnuCash Update 5.17 Security Notification 2026-a95c9d3b51
Fedora 45 GnuCash-Docs Update 5.17 – Advisory FEDORA-2026-a95c9d3b51
Fedora 45 hplip 3.26.6 Important Exec Escalation CVEs 2026-ebccf08143
Fedora 45 mingw-llvm Critical DoS Buffer Overflow Advisory 2026-e03c0baa59
Fedora 45 sngrep Critical Buffer Overflow CVE-2026-90558 Advisory 2026-019
Fedora 45 tecla Update GNOME 51.0 Security Advisory 2026-48a7996f9c
Fedora 45 xdg-desktop-portal-gnome Update 2026-48a7996f9c
Fedora 45 Sushi Update for GNOME 51.0 Advisory 2026-48a7996f9c
Fedora 45 Sysprof Update GNOME 51.0 Performance 2026-48a7996f9c
Fedora 45 Rygel 46.0 Medium Performance Update 2026-48a7996f9c
Fedora 45 Shotwell Photo Organizer Update Advisory 2026-48a7996f9c
Fedora 45 mutter Patch 51.0 Security Notice 2026-48a7996f9c
Fedora 45 Quadrapassel GNOME 51.0 Update Advisory 2026-48a7996f9c
Fedora 45 Nautilus Update GNOME File Manager 51.0 2026-48a7996f9c
Fedora 45 libshumate Patch Notification 2026-48a7996f9c
Fedora 45 libdex Package Update Advisory for 2026-48a7996f9c Released
Fedora 45 gsettings-desktop-schemas 51.0 Update Advisory 2026-48a7996f9c
Fedora 45 libadwaita Update GNOME 51.0 Adv 2026-48a7996f9c
Fedora 45 Gnote Update to GNOME 51.0 Advisory 2026-48a7996f9c
Fedora 45 gnome-user-docs Update Alert for Version 51.0 Released
Upgrade to Fedora 45 Gnome Text Editor Boosts Session Control Features
Fedora 45 gtk4 Update Advisory for GNOME 51.0 FEDORA-2026-48a7996f9c
Fedora 45 libsecret 0.21.8.2 Security Update For GNOME 51.0
Fedora 45 gnome-system-monitor Version 51.0 Update Advisory 2026-48a7996f9c
Fedora 45 gnome-shell Version 51.0 Severe User Interface Management Issues
Fedora 45 GNOME First-Time Setup Latest Update 2026-48a7996f9c
Fedora 45 gnome-settings-daemon Software Update 2026-48a7996f9c
Fedora 45 gnome-shell-extensions Update 51.0 Enhancements 2026-48a7996f9c
Fedora 45 gnome-keyring Security Advisory 2026-48a7996f9c
Fedora 45 GNOME Remote Desktop Important Update 2026-48a7996f9c
Fedora 45 GNOME Maps Update Announcement for Version 2026-48a7996f9c
Fedora 45 GNOME Clocks Update for Version 51.0 Advisory 2026-48a7996f9c
Fedora 45 gnome-characters Update to GNOME 51.0 2026-48a7996f9c
Linux Memory Fault Bug Can Release a Lock Twice on SuperH
A proposed Linux patch addresses a double unlock in the SuperH architecture’s page-fault handling.
DSA-6533-1 firefox-esr – security update
DSA-6532-1 tor – security update
DSA-6531-1 openssl – security update
How to Review Linux Security Boundaries: Three Kernel Examples
A Linux security review can find a check, a lock, or a safe-looking range and still miss the failure.
Slackware Mozilla-Firefox Critical Security Fix Advisory 2026-272-01
Dutch ShinyHunters Suspect Investigated for Trying to Arrange 2 Murders
Add one more AI worry to the nightmare scenario: self-replicating prompt injections
Imagine a prompt injection that keeps replicating itself like a worm. It’s not just the stuff of bad dreams. “We have found instances of our GPT [...]
DSA-6527-1 rsync – security update
FBI to ShinyHunters: ‘We know how to find you’
The FBI’s cyber chief has a message for the criminals that hacked the bureau’s jobs portal last week: “We know how to find you,” so turn [...]
When to Use Stablecoins for Cross-Border Business Payments
Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
The public still doesn’t know who is abusing a critical Citrix vulnerability exploited as a zero-day weeks before disclosure, but we now know that the [...]
The devil is still in the email – but wearing a new mask
When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack
Hackers Use Hijacked University Emails to Scam Students, Pose as FBI Agent
AI models keep posting screenshots showing sensitive data from inside tech companies
Amid the growing concern about AI models escaping security simulations to hack websites comes word that these “superintelligent” blobs of code [...]
Meta’s ex launches agent rival to Meta’s Muse
Manus’s relationship with Meta? It’s complicated. Just months after they called off their merger, they find themselves competing in the market for agentic [...]
OpenAI pulls the plug on GPT 6.1 Astra as agents keep crossing lines
OpenAI has scrapped the planned October release of GPT-6.1 Astra after internal testing found the model did not meet the company’s safety and alignment [...]
AMD agrees to buy World Labs to fill out its AI stack
Advanced Micro Devices (AMD) has agreed to buy World Labs, a developer of AI “world models” that incorporate knowledge of the physical world, to extend the [...]
Apple patches CoreGraphics zero-day already exploited in targeted attacks
Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen [...]
OpenAI benches GPT-6.1 Astra for overstepping the mark
OpenAI has killed off the planned release of GPT-6.1 Astra after the model got better at doggedly pursuing tasks but worse at knowing when it should stop. [...]
Phishing Exposure Nears 70% Across Key US Industries. What Should Security Teams Do?
Former X-Force hackers chase the offensive cyber gold rush
Two former leaders of IBM’s X-Force Red team have launched RemoteThreat, an offensive cybersecurity startup backed by $7 million in pre-seed funding. [...]
Teen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows
Why faster AI coding can mean harder engineering
We keep asking whether AI can make developers more productive, but that’s the wrong question. We should instead be asking what happens when it does. All [...]
What happens when the cloud blows up?
I’ve covered cloud computing for a long time, and one of the most persistent myths I encounter is that public clouds exist above the laws of physics that [...]
OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon
OpenAI has detailed the extent of the dirty deeds its agents indulged in Down Under in a Tuesday blog post titled How we will do better for Australia, [...]
Ubuntu 14.04 LTS curl Important Regression Security Issues USN-8487-2
Nvidia releases Open Agent Safety Platform to monitor and govern agentic AI
Nvidia on Monday rolled out an agentic governance system called the Open Agent Safety Platform that combines software with out-of-band DPU-based silicon in [...]
Fedora 44 VLC 3.0.24 Important Insights on Information Leak and Code Risks
Fedora 44 perl-Dancer2 Major Deserialization Vulnerability 2026-3b893ccf2d
Fedora 44 perl-Catalyst-Plugin-Static-Simple Security Alert 2026-2d96cf2594
Fedora 44 perl-HTML-FormFu Key Resource Exhaustion Patch 2026-18537daffc