Menu

Latest articles

DSA-6506-1 chromium – security update
DSA-6505-1 bind9 – security update
DSA-6504-1 libapache2-mod-auth-openidc – security update
GitLab joins rush to slow AI coders with rate limits
Devops platform GitLab already rate-limits some functionality on its hosted service, but will tighten those-limits for some functions and for some users [...]
Researchers used Claude to hack OpenAI employees’ ChatGPT accounts
Talk about your competitor getting through the door. Security researchers used Anthropic’s Claude to help hack into OpenAI employees’ ChatGPT [...]
North Korea’s fake job interviews infected 30,000 devices
North Korea’s employment scams work both ways. As well as placing fraudulent IT workers inside Western companies, regime-backed cybercriminals have [...]
Beware the SparroWock: The backdoor that bites, the commands that catch
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
FBI: Fake cop and government impersonation scams cost victims $1.6B
Scammers impersonating law enforcement or government officials have cost victims more than $1.6 billion since January 2025, the FBI reports. The FBI’s [...]
A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a [...]
Stop rewriting stable code: How Lightwell protects your bottom line and developer velocity
How Lightwell breaks the forced-upgrade cycle to keep your systems protected and your developers focused on innovation.The Monday morning CISO [...]
How a TOCTOU Race Condition Breaks Linux Path Validation
A Linux path can be valid when a program checks it and point somewhere else when the program uses it. That gap creates a time-of-check to time-of-use, or [...]
Supercharge your programming skills with Python superpowers
Some Python features are so useful they feel almost illegal, or like they’re granting you superpowers. We have dataclasses to take the hassle out of [...]
Your AI agents are isolated. Your infrastructure isn’t
The detail that caught my attention in the OpenAI-Hugging Face investigation was the package cache. Roughly 1,200 AI agents that were supposed to be [...]
The cloud outage that should terrify the CIO
September 3 started like any other Thursday, until it didn’t. Within roughly 90 minutes, ChatGPT, Claude, Grok, and even Microsoft’s own Copilot were [...]
Debian LTS nginx Security Update DLA-4784-1 Multiple CVEs Addressed
USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech
Think tank the Australian Strategic Policy Institute (ASPI) has warned that Venezuela is poised to adopt Chinese AI systems to enhance surveillance systems [...]
Fedora 44 Chromium Critical Security Update Vuln 2026-441ccd8509
Fedora 44 Parted Update 2026-6ac486039c Critical Data Errors
Fedora 44 python-django5 Significant Fix for Denial of Service and Forgery
Fedora 44 Nodejs Undici Denial of Service Vulnerability Fix CVE-2026-18149
Fedora 44 gnatcoll Critical Update Interface Change Patch 2026-11f44e3c2c
Fedora 44 sblim-cmpi-base Important Local Symlink Attack CVE-2026-73585
Fedora 43 Django 5 Critical Request Forgery Denial-of-Service Alert
Patch for Core Vulnerabilities in GNATCOLL on Fedora 43 – 2026-d5c7f91202
Fedora 43 sblim-cmpi-base Local Symlink Attack Fix CVE-2026-73585
Fedora 43 Nodejs-Undici Denial of Service Vulnerability Fix CVE-2026-18149
Fedora 43 GitPython Update GHSA-hmq2-w58f-27jc Severity Information
SUSE MozillaFirefox Important Security Update 2026-4247-1
SUSE NodeJS18 Important DoS Denial of Service Issue 2026-4248-1
openSUSE netcdf Critical Buffer Overflow Vulnerability Advisory 2026-4249-1
SUSE netcdf Important Out-of-Bounds Write Issue Vulnerability 2026-4249-1
openSUSE Glibc Moderate Buffer Overflow Advisory 2026-4250-1
SUSE glibc Moderate Buffer Overflow Issues Fix Advisory 2026-4250-1
openSUSE cjose Important Buffer Overflow Fix 2026-4251-1
SUSE cjose Important Buffer Overflow Content Modification Vuln 2026-4251-1
SUSE TIFF Moderate Heap Overflow Vulnerability Identified 2026-4252-1
SUSE Important Security Update for cjose Buffer Overflow Issues 2026-4253-1
SUSE Linux Enterprise 12 SP5 Kernel Live Patch Important Fix 2026-4243-1
openSUSE Kernel Important Patch Security Flaws Fix 2026-4244-1
SUSE Kernel Live Patch 39 Important Fixes for Vulnerabilities 2026-4244-1
SUSE Kernel Important Memory Leak Security Fixes Vulnerability 2026-4254-1
Fedora 45 freeipmi Significant Buffer Overflow Resolution 2026-abe39f1809
Fedora 45 python-django5 Critical Server-side Attack Fix CVE-2026-15307
Fedora 45 GNATCOLL Important Patch for Core Vulnerabilities 2026-c8b1bb0c97
Fedora 45 addresses Denial of Service flaw in nodejs-undici CVE-2026-18149
Fedora 45 sblim-cmpi-base Important Local Temp File Issue CVE-2026-73585
Ubuntu 26.04 Bubblewrap Low Regression Issue USN-8779-2
AI coding agents’ 0-click RCE flaw could hand attackers keys to the kingdom
A zero-click vulnerability that allows remote code execution affects all of the major AI coding agents – Anthropic’s Claude Code, OpenAI’s Codex, [...]
Linux Security Researcher Uses AI to Find Four Python Code-Execution Flaws
Security researcher Sai Teja Erukude disclosed four alarming Python security flaws between June and August 2026 after combining specialized AI models with [...]
CISA Warns of Active Attacks on a Critical Cisco ISE Flaw
Attackers are exploiting a critical Cisco ISE flaw that can open the product’s web management interface without a valid login. Cisco disclosed [...]
Ubuntu 26.04 Bubblewrap Notable Denial of Service Vulnerability USN-8779-1
How a PowerPC Guest Could Trigger a KVM Use-After-Free
A PowerPC KVM use-after-free could leave the Linux host kernel accessing a nested-guest object after another virtual CPU caused that object to be removed [...]
SUSE cjose Important Buffer Overflow Vulnerability Patch 2026-4237-1
openSUSE gvfs Addresses Significant Memory Leak and Buffer Overflow Bugs
SUSE gvfs Important OOB Memory Access Issues Vuln 2026-4238-1
SUSE libpcap Essential Out-Of-Band Access Update 2026-4239-1
openSUSE gvfs Important Out Of Bounds Issues Vuln 2026-4240-1
Important Security Update for SUSE 2026-4240-1 gvfs Released
openSUSE pcre2 Important Out-of-Bounds Issues Advisory 2026-4241-1
SUSE pcre2 Important Patch for Six Vulnerabilities 2026-4241-1
SUSE OpenVPN Important Remote DoS Patch CVE-2026-84732 2026-4242-1
openSUSE Kernel Important Live Patch for Multiple Issues 2026-4231-1
Debian LTS xz-utils Security Update DLA-4783-1 Fixes Memory Corruption
SUSE Linux Enterprise 15 SP6 Kernel Important Threats Patch 2026-4231-1
DSA-6503-1 thunderbird – security update
DSA-6502-1 mkvtoolnix – security update
DSA-6501-1 firefox-esr – security update
DSA-6500-1 tor – security update
Debian Chromium Critical Code Execution Denial of Service DSA-6506-1
Red Hat Quay Build Workflow Could Expose Registry Credentials
As of September 17, Red Hat had documented a flaw in a Red Hat Quay build workflow that could expose container registry credentials to code retrieved from [...]
Researchers find way to listen in on headphones from afar
Researchers based in China have devised a way to eavesdrop on signals handled by analog components in devices such as headphones, landline handsets, and [...]
Debian DSA-6505-1 BIND Critical Denial of Service and Cache Poisoning Fix
Debian libapache2-mod-auth-openidc Key Denial of Service Patch DSA-6504-1
China’s Salt Typhoon backdoors Latin American orgs with new snooping malware
China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across [...]
Cyberthreats are moving faster than SMBs: Readiness must accelerate
As AI adoption expands the attack surface and adds to the security workload, businesses need automation backed by experts
TypeSafe AI’s new models work with machines, not humans
Today’s large language models are verbose, even if they’re being asked to recommend a simple decision, driving up usage costs through the sheer volume of [...]
Rocky Linux 8 RLSA-2026-67908 libevent Important Denial of Service Issues
Rocky Linux libsoup Moderate WebSocket DoS RLSA-2026-68266
London property manager breach may have exposed bank details and lockbox codes
London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys [...]
US Coast Guard and FBI board oil tanker to investigate cyber attack
Self-modifying AI agents expose a blind spot in enterprise security
As debate over AI safety intensifies, new research is drawing attention to a more immediate risk for enterprises: AI agents that can alter the models they [...]
Cisco drops another exploited zero-day, this time a perfect 10
Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed [...]
Test environment let anyone access live customer data
Welcome back to PWNED, the weekly column where we learn important life lessons about how we let cybercrims access our data through carelessness. Hopefully, [...]
Container Security Failure Could Let a Malicious Image Reach the Linux Host
Container security can fail before a workload fully enters its root filesystem, the private file tree the container is meant to see.
Linux SMB Security Fixes Restore Ownership and Input-Trust Boundaries
SMB, or Server Message Block, lets Linux systems access files shared over a network.
How Transparent Huge Pages Could Lose Rewritten Data During Reclaim
Transparent huge pages let Linux manage memory in larger blocks for better performance.
Why eBPF Security Depends on Matching Metadata Lifetimes
eBPF lets verified programs run inside the Linux kernel. Linux eBPF security depends on supporting data remaining available for as long as those programs [...]
Effective Encryption Strategies to Safeguard Your Online Identity
In today’s world, almost every part of our lives is directly or indirectly linked to the Internet. As cyberattacks in network security grow more advanced, [...]
Ofcom discovers issuing Online Safety Act fines is easier than collecting them
Ofcom chiefs have acknowledged that most fines issued under the Online Safety Act (OSA) remain unpaid, highlighting limitations in the comms [...]
Stop tuning your models and fix your data
Walk into any boardroom or technology conference today, and the conversation is entirely consumed by the promise of agentic AI. We are told that autonomous [...]
MSBuild explained: Understanding Microsoft’s build platform
Visual Studio is a lot more than an editor and debugger; it’s the host for Microsoft’s cross-platform build tools. MSBuild is one of those forgotten [...]
Your AI testing dashboards are green. That’s the problem
The green dashboard is one of the most comforting objects in software engineering. It says the build passed, the tests passed, the service is healthy and [...]
How Linux File Permissions Become a Root Trust Boundary
Linux file permissions are usually introduced as a way to decide who may read, write, or execute a file. On a production server, they do something more [...]
Fedora 43 open62541 Security Advisory on Critical Denial of Service Issues
Fedora 43 php-pecl-mongodb2 Important Out-of-Bounds Read Fix CVE-2026-84968
Fedora 43 Roundcube 1.6.19 Security Updates Address XSS Email Issues
Fedora 44 python-django6 Important Updates for XSS and DoS Vulnerabilities
Fedora 44 open62541 Key Fixes for Denial of Service and Code Execution
Fedora 44 php-pecl-mongodb2 Important Out-Of-Bounds Read CVE-2026-84968
Fedora 44 Roundcube 1.7.4 Security Fix XSS Email Header CVE-2026-38c637be37