Menu

Latest articles

HackerOne slams supplier for delayed breach notice after staff data exposed
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
An update that solves 11 vulnerabilities and has two security fixes can now be installed.
An update that solves 11 vulnerabilities and has two security fixes can now be installed.
An update that solves one vulnerability and has two security fixes can now be installed.
An update that solves one vulnerability and has two security fixes can now be installed.
Country that put backdoors into Cisco routers to spy on world bans foreign routers
New ‘StoatWaffle’ malware auto‑executes attacks on developers
Russian initial access broker who fed ransomware crews gets 81 months in US prison
VS Code now updates weekly
When Windows 11 sneezes, Azure catches cold
Designing self-healing microservices with recovery-aware redrive frameworks
7 safeguards for observable AI agents
An architecture for engineering AI context
Claude attacks were ‘Rorschach test’ for infosec community, scaring former NSA boss
Public-private partnerships vital in disrupting China’s Typhoons, says RSA panel with no government speakers
Lightning-fast exploits make it essential to patch fast, ask questions later
https://security-tracker.debian.org/tracker/DSA-6175-1
Google unleashes Gemini AI agents on the dark web
Smooth criminals talking their way into cloud environments, Google says
US chip testing firm shrugged off ransomware hit as minor – then came the data leak
RSAC 2026: Uncle Sam backs out, and AI agents are everywhere
Microsoft fixes broken Windows update days after vowing fewer broken updates
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
The drone swarm is coming, and NATO air defenses are too expensive to cope
The agent security mess
How to land a software development job in an AI-focused world
Net-CIDR could allow unintended access to network services.
Debian Goodies could be made to crash or run programs as your login if it opened a specially crafted file.
# Security update for helm Announcement ID: SUSE-SU-2026:0948-1 Release Date: 2026-03-20T18:07:28Z Rating: important References:
https://security-tracker.debian.org/tracker/DSA-6176-1
Russians are posing as Signal support to launch phishing attacks
https://security-tracker.debian.org/tracker/DSA-6173-1
Jul Blobul discovered that SPIP, a website engine for publishing, is prone to a privilege escalation vulnerability. For the stable distribution (trixie), this problem has been fixed in version 4.4.13+dfsg-0+deb13u1. We recommend that you upgrade your spip packages.
Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens
Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens
Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.
https://security-tracker.debian.org/tracker/DSA-6174-1
https://security-tracker.debian.org/tracker/DSA-6171-1
Move fast and save things: A quick guide to recovering a hacked account What you do – and how fast – after an account is compromised often matters more than it may seem
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex
Upstream announcements: WordPress 6.9.2 Release WordPress 6.9.3 and 7.0 beta 4 WordPress 6.9.4 Release
Update to 1.73.3; Fixes: RHBZ#2426392, RHBZ#2415186
Update to 0.37.1 (rbhz#2445943) Fixes Denial of Service via malformed Content-Length header (CVE-2026-31870 Reenables 32-bit build Update to 0.37.0 (rhbz#2441656)