Menu

Latest articles

DSA-6408-1 chromium – security update
DSA-6407-1 incus – security update
DSA-6406-1 php8.4 – security update
This month in security with Tony Anscombe – July 2026 edition
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
DSA-6409-1 libgd2 – security update
Oracle Linux 10 openssh Important Remote Access Issues ELSA-2026-47757
Oracle Linux 10 gstreamer1-plugins-bad-free Important Fix CVE-2026-59691
Oracle Linux 10 ELSA-2026-47085 Rest Important Weak Random Generation
Oracle Linux 10 Pipewire Important Patch CVE-2026-5674 ELSA-2026-47083
Oracle Linux 10 libXfont2 Important CVE Fixes ELSA-2026-47079
Oracle Linux 9 Node.js Key Security Updates ELSA-2026-47058 CVE-2026-13149
Oracle Linux 9 Nodejs Important Security Advisory ELSA-2026-47057
Oracle Linux 8 Fence Agents Important CVE Fix Advisory ELSA-2026-47736
Oracle Linux 8 ELSA-2026-47731 GStreamer1 Plugins Bad Free Important Fix
Oracle Linux 8 ELSA-2026-47184 libtiff Important Heap Overflow
Oracle Linux compat-libtiff3 Important Buffer Overflow Fix ELSA-2026-47183
Oracle ELSA-2026-47177 yelp Important Fix for CVE-2026-13601
Oracle Linux 8 libgcrypt Moderate Denial of Service Fix ELSA-2026-47117
Oracle Linux Firefox Important Security Fix ELSA-2026-47105
Oracle Linux 8 libXfont2 Major CVE Resolution Notice ELSA-2026-47103
Oracle Linux 8 Vim Important Arbitrary Execution ELSA-2026-48703
Oracle python-pillow Important Buffer Overflow Fix ELSA-2026-48021
Oracle Linux 8 SSSD Important Bug Fix Advisory ELSA-2026-46990
Oracle 8 dovecot Important IMAP Parser Fix ELSA-2026-46532
Oracle Linux 8 Grafana Important Bug Fix CVE-2026-44740 ELSA-2026-46391
Oracle Linux 8 Kernel Significant Security Patch ELSA-2026-45115
Oracle glibc Medium Out-of-Bounds Write Vulnerabilities ELSA-2026-42733
Oracle Linux 10 Vim Important Command Issues ELSA-2026-48650
Oracle Linux 10 Fence Agents Important Fix ELSA-2026-48585 CVE-2026-59939
Oracle Linux 10 Kernel Important Security Update ELSA-2026-45114
Oracle Linux 10 buildah Important Buffer Overflow Vuln ELSA-2026-36199
Oracle Linux 10 OpenSSL Critical Security Notice ELSA-2026-25237
Oracle 10 Kernel Important Security Update ELSA-2026-21557
Oracle Linux 7 gimp Important Multiple Security Issues ELSA-2026-26168
Oracle PackageKit Important CVE-2026-41651 Update ELSA-2026-22146
Debian 11 Bullseye Poppler Important Code Execution and DoS Fix DLA-4709-1
Oracle Linux 9 vim Security Command Execution Flaws ELSA-2026-47982
Oracle Linux 9 gstreamer1-plugins-bad-free Important Fixes ELSA-2026-47179
Oracle Linux 9 Yelp Important Patch CVE-2026-13601 ELSA-2026-47178
Important Firefox Update for Oracle Linux – ELSA-2026-47104 Released
Oracle Linux 9 libXfont2 Important CVE-2026-56001 CVE-2026-56002 Advisory
Oracle Linux 9 ELSA-2026-45192 Kernel Important Bug Fixes
Debian Incus Significant Privilege Escalation Vulnerabilities DSA-6407-1
Debian PHP 8.4 Critical Denial of Service SQL Injection Issues DSA-6406-1
openSUSE Python-NLTK Important Fix CVE-2025-71408 Advisory 2026-0269-1
Linux Security Patches Have Become Machine-Readable Intelligence
Every Linux security patch contains more than a bug fix. It records exactly what assumptions changed, which validation failed, and which code path [...]
Beyond the screenshot: Why you should verify what you see
The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine
The most famous brand in physical security got pwned by ShinyHunters
A leading name in home and business physical security, Brinks Home, recently said it identified unauthorized access to a portion of its IT systems, an [...]
Rocky Linux 9 java-25-openjdk Important Multiple Issues RLSA-2026-42899
openSUSE yq Important DoS Infinite Loop Vuln 2026-21500-1
openSUSE Perl-Mojolicious Moderate CSRF Fix Vuln 2026-21496-1
openSUSE Tomcat 11 Important Security Fixes Vuln 2026-21490-1
openSUSE Leap 16.0 Security Advisory Important Bind Issues 2026-21489-1
openSUSE Leap 16.0 openvpn Important DoS Vulnerabilities 2026-21488-1
openSUSE Leap 16.0 valkey Important RCE Threats Advisory 2026-21485-1
openSUSE Ignition Important Privilege Escalation Vuln 2026-21482-1
openSUSE Leap 16.0 Advisory 2026-21477-1 OpenSSH Important Issues
openSUSE Leap 16.0 google-guest-agent Privilege Escalation and Loop Issues
Understanding Trust Boundaries in Linux Infrastructure
Every time you SSH into a server, run sudo, install a package, or start a container, Linux decides whether to trust it. Most of those decisions happen so [...]
Anthropic and OpenAI are competing to see whose agents can go rogue harder
One company’s inventive campaign for an unreleased product has become a contest between Anthropic and OpenAI to see which can shout the loudest about [...]
Charities remain locked out of CAF Bank online accounts
A week after suspending online banking, CAF Bank still has no timetable for restoring access to its 14,000 UK charity customers. The bank updated customers [...]
Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs
Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure [...]
Why Python Is the Right Language for Linux Security Automation
Linux administrators automate almost everything. Backups run on a schedule, logs rotate on their own, updates ship through pipelines, and health checks [...]
From Beginner to Pro: How Your Linux Setup Should Evolve as a Developer
Your operating system forms the base layer of your production pipeline. Moving from a basic workstation layout to an enterprise environment takes [...]
The $5 million threat: AI Is supercharging phishing attacks
No time to lose: Why post-quantum security for financial services must start now
Post-quantum cryptography: The emerging threatThe transition to post-quantum cryptography (PQC) is becoming an urgent priority for the global financial [...]
Lights on! Real-time threat response with Red Hat Advanced Cluster Security
Part 2 of a series on implementing zero trust in Red Hat OpenShift with the layered zero trust validated pattern (ZTVP)In our previous article, we explored [...]
JetBrains says a crafted HTTP request could break TeamCity
JetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary [...]
OpenAI drops GPT-5.6 Luna and Terra API prices by up to 80%
OpenAI has cut API prices for its GPT-5.6 Terra and Luna models by 20% and 80%, respectively, while also reducing the number of usage credits the models [...]
Rocky Linux perl Important DoS Security Fix RLSA-2026-48225 CVE-2026-9538
Why observability matters to frontend teams more than they think
For a long time, I thought of observability as something mainly owned by backend, platform or site reliability teams. Frontend engineers built the [...]
UK says the cloud is financial infrastructure
Every cloud architect, every financial services executive, and frankly every enterprise CTO should be paying attention to what is going on in the United [...]
The platform team isn’t a cost center, it’s product infrastructure
A few years ago, I sat in a postmortem that I still think about. We’d had a production incident where a routine deploy had quietly shipped with the wrong [...]
Debian LTS gsasl Important Memory Disclosure Fix DLA-4707-1 CVE-2026-56968
Anthropic’s Claude escaped test sandbox to attack three organizations
Anthropic has admitted that its Claude models escaped sandboxes to access the open internet and attack three organizations – but has also advanced decent [...]
Fedora 43 Unbound Critical DNS Denial of Service Fixes 2026-3170ee6a1c
Fedora 43 Pack Security Update 2026-e6e0368149 Addresses CVEs
Fedora 43 dokuwiki Security Advisory FEDORA-2026-68853bb50c Backport Fixes
The Fedora update for DokuWiki enhances its security by backporting patches, ensuring the wiki remains easy to use while storing content in plain text files.
Fedora 43 NASM Critical Heap Vulnerability Fixes Addressed 2026-9af234bcd6
Fedora 43 Lego Off-path Poisoning CVE-2026-10846 Advisory 5.3.1
Fedora 43 Valkey 8.1.9 Important Remote Code Exec Fixes 2026-9de44775c7
Fedora 43 libnbd Security Advisory 2026-045e6f85c6 Command Injection
Fedora 44 Pack Critical Local Privilege Escalation and SSH DoS Updates
Fedora 44 DokuWiki Security Fixes Advisory 2026-d37b1b981a
Fedora 44 Valkey Important TLS Remote Code Exec Vuln 2026-3d18a65cc4
Ubuntu OpenSSL Critical Denial of Service Issue USN-8625-1
DSA-6405-1 linux – security update
JetBrains open sources KotlinLLM runtime code generator
KotlinLLM, a research prototype for delegating runtime logic to a large language model (LLM) from Kotlin code, is now going open source and public, [...]
Rocky Linux openssh Important Denial of Service Threat RLSA-2026-47756
Rocky Linux 9 Kernel Important Security Fixes RLSA-2026-47040
openSUSE python3-pyOpenSSL Low Unhandled Exception CVE-2026-27448
SUSE python3-pyOpenSSL Low Issue Bypass Risk Advisory 2026-3424-1
openSUSE python-urwid Important Insecure Web Session IDs CVE-2026-9323
SUSE python-urwid Important Web Session Security Fix 2026-3425-1
SUSE Bind Important DNSSEC Cache Poisoning Vulnerabilities 2026-3426-1
SUSE Valkey Important Remote Code Exec Vulnerabilities 2026-3427-1
SUSE Runc Low Integrity Risk Fix Advisory 2026-3428-1 CVE-2026-41579
openSUSE libarchive Moderate Denial of Service and Other Issues 2026-3429-1
SUSE libarchive Moderate File Handling Issues Advisory 2026-3429-1
openSUSE Tomcat Important Security Issues Update CVE-2026-59083 59084