Menu

Latest articles

DSA-6511-1 znc – security update
Decades-old file security flaws found in Android, Linux, macOS, and Windows
Security researchers affiliated with Austria’s Graz University of Technology have found flaws in the implementation of file notification systems on [...]
CVE flood pushes Ubuntu onto weekly kernel release cycle
Canonical is speeding up Ubuntu kernel releases to one a week as AI-assisted bug hunting helps bury defenders under an ever-growing pile of CVEs. The [...]
Someone went shopping in ASUS’s eShop – for customer data
Asus has warned eShop customers that an intruder got into part of its online store and may have helped themselves to contact details and order records. The [...]
Teradata aims to make agentic execution of multistep data work more efficient
Teradata is adding a context engine, an execution layer, and reusable agent skills to Tera, its AI-powered workspace for enterprise data and AI tasks, in [...]
Google to critical infra orgs: Our AI scanners won’t be evil, promise
Google has jumped on the AI-defense-for-critical-systems train with its Scan for Good initiative, and says that its threat-hunting models have already [...]
Ukrainian ransomware developer jailed for nearly 13 years
Turning security complexity into useful intelligence: What’s new in Red Hat Lightspeed
In a post-Mythos world, IT teams face a mounting crisis. Many are doing more with the same staff, and security work hasn’t gotten simpler. Alerts still [...]
2026 update: The road to quantum-safe cryptography in Red Hat OpenShift
A year ago, I wrote about the road to quantum-safe cryptography in Red Hat OpenShift. At the time, much of that road was forward-looking: TLS 1.3 was not [...]
AlmaLinux 8 Python 2.7 Major SQL Injection Info Disclosure Vulnerability
AlmaLinux 8 Container-Tools Important Security Fix CVE-2019-5736
AlmaLinux 8 libyang Bug Fix Advisory ALEA-2021-1906 Moderate
AlmaLinux 8 libarchive Moderate Bug Fix Advisory ALEA-2021-1580
New AvisLoader Windows Malware Uses ClickFix Lure and Tox P2P for C2
Managing the life cycle of AI agents at scale
There’s a new reality emerging for development teams: existing software delivery practices don’t translate cleanly to agentic AI systems. Practices built [...]
Government contractor exposed path to immigration records
Welcome back to PWNED, the column where we look at all the ways your security can become self-owned. Today’s scary story involves government contractors [...]
Mageia 10 xdg-dbus-proxy Medium Broadcast Filtering Bypass CVE-2026-93676
Mageia perl-URI Important IDNA Encoding Fix CVE-2026-19953
Mageia KBD Important Local Escalation Vulnerability CVE-2026-72693
Fedora 43 Chromium Critical Race Condition Buffer Overflow Vulnerability
Fedora 43 kernel 7.2.7 Important System Fix Advisory FEDORA-2026-8202400aa0
Fedora 43 mingw-pcre2 Important Information Disclosures – CVE-2026-89162
Fedora 44 Unbound Important Heap Buffer Overflow RCE Vuln 2026-996b326401
Fedora 44 mingw-pcre2 Critical Information Disclosure and Code Exec CVEs
SUSE Apptainer Important DoS Buffer Overflow Fix SUSE-SU-2026-4308-1
SUSE gimp Important Denial of Service and Code Execution Fix 2026-4309-1
openSUSE Kernel Important Security Update CVE-2026-46150 CVE-2026-64423
Fedora 45 libheif Security Advisory 2026-78461b38b3 Denial of Service
Fedora 45 WebKitGTK Update for Eclipse Crash Notice FEDORA-2026-c66009e517
Fedora 45 mingw-pcre2 Out-of-Bounds Disclosure and Code Execution Risk
Fedora 45 evolution-data-server Update Bug Fixes CVE-2026-88859
Fedora 45 evolution-ews Update Addresses Severe JavaScript Execution Bug
Fedora 45 Evolution Important Security Fix Advisory 2026-5debc0de2b
OpenAI agents ‘infiltrated Australian government website’
Australia’s Prime Minister Anthony Albanese has revealed an OpenAI agent “infiltrated an Australian government website” while trying to research medical [...]
DSA-6512-1 libreoffice – security update
Mageia Pipewire Significant RAOP Buffer Overflow Vulnerability 2026-0443
Mageia Libwebsockets Security Update Resource Consumption CVE-2026-10650
Mageia 10 amavisd Service Vulnerability Fix for Bug 2026-0133
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
Apple touts simpler and clearer code with Swift 6.4
Apple has released Swift 6.4, an upgrade to the programming language that brings improvements across the board including core library APIs, builds, [...]
Ubuntu 26.04 XDG Desktop Portal Local Deletion Vulnerability USN-8287-2
Ubuntu 26.04 LTS libgit2 Important Remote Exec Vulnerability CVE-2026-5917
Rocky Linux 10 perl-DBI Important Heap Overflow Risk RLSA-2026-70753
Rocky Linux 10 RLSA-2026-69609 OpenEXR Important Heap Overflow
Rocky Linux 10 rsyslog Important Denial of Service RLSA-2026-69541
Rocky Linux 10 libarchive Low Heap Overflow Signed Integer Overflow Alert
Rocky Linux PostgreSQL16 Important Arbitrary Code Execution RLSA-2026-70186
Rocky Linux Podman Important Denial of Service Fixes RLSA-2026-70201
Rocky Linux 9 Firefox Gains Key Security Patch for Privilege Escalation
Rocky Linux 9 Podman Important Denial of Service Issues RLSA-2026-69961
Rocky Linux PostgreSQL Important Security Update RLSA-2026-69607
Rocky Linux OpenEXR Important Heap Overflow Vuln RLSA-2026-69608
Rocky Linux 9 RLSA-2026-70391 Key Update for Networking Denial of Service
Rocky Linux 9 RLSA-2026-70191 Runc Important Denial of Service Fix
Rocky Linux 8 RLSA-2026-69924 postgresql Important Arbitrary Code Execution
Debian znc Critical DoS Fix DSA-6511-1 CVE-2026-82373 CVE-2026-82374
Mobile App Security in HealthTech: Safeguarding Patient Data Against Cybersecurity Threats
MCP Toolbox Flaw Could Expose Google Service Tokens
A September 23 advisory describes a flaw in the Python SDK used with MCP Toolbox: a shared cache could send a Google ID token to a service it was not meant for.
Emacs Security Flaw Could Run Code From an Untrusted File
A September 22 advisory on an Emacs vulnerability says opening a crafted file could run code on the reader’s computer, even with the editor’s [...]
Linux HID Flaw Could Leak Kernel Memory Through Input Events
A newly merged Linux HID fix addresses a Wacom input-device path that could read beyond a short report and pass a value to local software.
Linux DAMON Page-Table Bug Could Corrupt Arm64 System Memory
Linux DAMON, the kernel’s Data Access Monitor, samples memory use to show which pages a workload touches.
Ubuntu 26.04 LTS NetworkManager Important Info Exposure CVE-2026-19685
Ubuntu 26.04 SQL Parsing Denial of Service Vulnerabilities USN-8808-1
Ubuntu Open-iSNS Critical Denial of Service Vulnerability USN-8807-1
GitHub Enterprise Server Flaw Could Let Attackers Run Code
A GitHub Enterprise Server security fix addresses a way to turn the appliance’s notebook viewer into a route to its own internal services.
Someone’s attacking a critical 0-day RCE in F5 BIG-IP APM
F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code. [...]
Oracle Linux 10 Podman Important Updates CVE-2026-17106 ELSA-2026-70201
Oracle Linux 10 PostgreSQL 16 Significant Security Advisory ELSA-2026-70186
Oracle Linux 10 libarchive Low Security Advisory ELSA-2026-69553
Oracle rsyslog Important Buffer Overflow Fix ELSA-2026-69541
Oracle Linux 10 Firefox Important Vulnerability Update ELSA-2026-69461
Oracle Linux 10 Curl Important Security Flaws ELSA-2026-69125
Oracle Linux PostgreSQL 18 PostGIS Security Fix ELSA-2026-67166-0
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
JetBrains unveils JetBrains Air for agentic software development
JetBrains on September 22 announced JetBrains Air, an open system of products for managing AI-powered software development workflows across developers, [...]
Looking for free Robux? Here’s what’s real, and what’s a scam
Fake giveaways, free Robux generators and lookalike login pages all target the same thing – your Roblox account
Email Makes Up Nearly 1 in 3 MSSP Analyses: How Tier 1 Can Triage Phishing Faster
OpenAI, Anthropic cut AI model costs as price-performance race intensifies
Enterprises can now buy frontier AI for far less per token after OpenAI and Anthropic cut prices on their newest models on Tuesday. OpenAI released GPT-6 [...]
GitHub App keys can still enable takeovers long after they are forgotten
GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories [...]
Academic publisher Elsevier hit by LAPSUS$ redirect attack
Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew’s [...]
Closing the observability gap for the AI-ready enterprise
The modern enterprise is a digital enterprise. From the back office to the factory floor, connected systems and digital services form the operational [...]
Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes
British regulator takes a hard look at Pornhub’s Apple-powered age checks
Ofcom has opened an investigation into whether Pornhub’s Apple-based age checks are effective enough to keep children away from its adult content. [...]
Software dependencies are running away from us
You may very well have a big problem and you don’t even know it.  Do you have complete control over the dependencies of your application? I’m guessing that [...]
Get started with htmx 4
htmx is a simple way to add rich interactivity to web pages without writing JavaScript. On an htmx-powered page, you can imbue buttons, form elements, [...]
Why security belongs in the network
Every attack leaves a trail across the network, from initial reconnaissance to lateral movement and data exfiltration. That makes the network one of an [...]
Oracle Linux 7 389-ds-base Important Security Updates ELSA-2026-55758
Oracle Linux Firefox Important Remote Access Vulnern ELSA-2026-54248
Debian LTS DLA-4791-1 memcached Buffer Overflow and Timing Attacks
Visual Studio Code 1.138 brings agent sessions to Dev Containers
Visual Studio Code 1.380, the latest update to Microsoft’s open-source code editor, introduces three new features for AI-powered coding: agent sessions in [...]
Mageia perl-Dancer2 Vulnerable Session IDs Detected CVE-2026-13577
Mageia 10 9 Security Update PKCE Weak Random Number Issue CVE-2026-16615
Mageia 10 9 Important GNU cpio Path Traversal Memory Issues 2026-0435
Mageia diffutils Critical Heap Overflow Vulnern 2026-0434
Mageia Twinkle Bugfix Advisory for the Year 2026 and Update 0130
Why Seccomp Must Be Rechecked After Container Restore
Seccomp limits which Linux system calls a process can make.
How Container Restore Can Reopen Privilege Escalation Paths
Privilege escalation in a container does not always begin with a new exploit.
What CRIU Restores Beyond Application Memory in Linux Containers
Linux containers can be paused, checkpointed, and rebuilt later with CRIU.
Fedora 44 Chromium Buffer Overflow Race Condition Fix 2026-f910229c11
Fedora 44 Kernel Significant Patches Upgrade 2026-ca91e91bf0