Menu

Latest articles

ShinyHunters tells The Reg: We hacked the FBI to ‘protect our business’
ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to millions of cancer patients, university and K-12 [...]
OpenAI wants you to use AI — but not to train its AI
Here’s an interesting concept: an AI company that fires people for using AI. It sounds like a strange way to run a company but there’s a real reason behind [...]
Crooks use fake desktop apps to fool HR staff into giving them remote access
You work in your company’s human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a [...]
Microsoft’s new Copilot unifies enterprise context for code and chat
Microsoft’s Copilot super-app has arrived, two months after CEO Satya Nadella confirmed it was in development. It combines conversational Chat, the [...]
Bitget blames North Korea for $387.5M crypto wallet raid
The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 [...]
Been told to pay at a Bitcoin ATM? Read this first
Crypto ATM scams often follow a predictable script – here’s how to recognize it and what to do if you’ve already been caught out
Documentation placeholder domain used in ClickFix attacks
The domain name third-party[.]com is being used to serve malware to users — bad news for those following a little too literally online documentation that [...]
Which copy of that file is the real one? Dinner, off the record, in Midtown
EVENT: The Register is hosting a private dinner in New York on Tuesday 27 October for senior technology, infrastructure and data leaders, with LucidLink. [...]
GitLab issue email’s only security is obscurity
It was meant to make life simpler: a secret email address to which developers can send a message and create an issue in their GitLab project. But poor [...]
Only 26% of Detected CISA Known Exploited Vulnerabilities Were Fully Remediated
Google plans Gemini 4 release before year-end
Google’s Gemini 4 AI model is in the early days of post-training, the phase in which a base AI model is refined to behave reliably, and should be released [...]
Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems
SectopRAT Abuses Legitimate Audio Software Files to Steal PC Data
IBM’s big cloud decision
A recent piece in Academy of Management Today by Daniel Butcher takes a fresh look at IBM’s pivot to cloud computing, and it’s worth your time. The article [...]
Mageia Python-Webob Important Open Redirect Issue Advisory 2026-0452
Mageia Unbound Critical Heap Overflow Remote Code Execution DoS 2026-0451
Mageia Python GitPython Key Denial of Service Vulnerability CVE-2026-87819
Mageia 10 Discover Bugfix Advisory – Important Update 2026-0136
Fedora WebKitGTK Critical Security Issues and Fixes 2026-40db9b80a2
Fedora 44 Squid 7.7 Proxy Update Advisory 2026-56c3705788
Fedora 44 unveils rust-cryptoki with advisory ID 2026-738ce6f6f8
Fedora 44 Pcs Update CVE-2026-84828 Security Notice and Advisory
Fedora 44 mingw-gdk-pixbuf Critical CVE-2026-16768 CVE-2026-81893 Fix
Fedora 44 389-ds-base Serious Heap Overflow Multiple Vulnerabilities FOUND
Fedora 43 Rust-Cryptoki Upstream Release Advisory 2026-c66f1af6a3
Fedora 43 pcs 0.12.3 Update Advisory for CVE-2026-84828
Fedora 43 mingw-gdk-pixbuf Security Advisory CVE-2026-16768 Major Bug Fix
Fedora 43 389-ds-base Critical Heap Buffer Overflow Issues 2026-0b8bc362b1
SUSE perl-DBI Important Arbitrary Code Execution Fix SUSE-SU-2026-4346-1
openSUSE Kernel Important Security Fixes 84 Vulnerabilities 2026-4347-1
SUSE Kernel Security Update Addressing Vulnerability 2026-4347-1
SUSE Linux Enterprise 15 SP7 Kernel Important Security Fix 2026-4344-1
SUSE Corosync Important Heap Overflows Integer Overflow Vuln 2026-23850-1
SUSE Security Update Important Fix for Six Issues 2026-23852-1
SUSE 16.0 Alloy Key Vulnerabilities in Denial of Service and Data Leak
SUSE Linux 16.0 Low Govulncheck Fixes 91 Issues 2026-23855-1
SUSE jsoup Important OutOfMemoryError Vulnern 2026-23856-1
SUSE Libsoup Important Heap Use-After-Free Buffer Overflow Vulnerability
SUSE zstd-jni Major Update Addresses DoS Info Leak and Memory Issues
SUSE RabbitMQ Important Multiple Issues Fix Advisory 2026-23859-1
SUSE Exiv2 Important Heap Overflow Issues Patch 2026-23860-1
SUSE Util-Linux Important Local Privilege Escalation Issues 2026-23861-1
SUSE Linux 16.0 Update for Low vulncheck 2026-23863-1 Released Now
SUSE 2026-23864-1 Distribution Important DoS Vulnerabilities
SUSE Alloy Important Security Update CVE-2026-10722 CVE-2026-1229
SUSE libsoup Important Heap Buffer Overflow Vulnern SUSE-2026-23866-1
SUSE 16.0 jsoup Important OutOfMemoryError Vulnern 2026-23867-1
SUSE zstd-jni Important DoS Info Disclosure Fix Advisory 2026-23868-1
SUSE RabbitMQ-Server Important XSS and Access Issues Advisory 2026-23869-1
SUSE util-linux Important Local Privilege Escalation Advisory 2026-23870-1
Fedora 45 Cockpit Advisory 2026-d375ea9e79 Security Update for DoS
Fedora 45 flatpak-builder Update CVE-2026-86320 Code Execution Advisory
Fedora 45 Squid New Version 7.7 Advisory 2026-9e8f1c83d0
Fedora 45 rust-cryptoki New Release Advisory FEDORA-2026-b9e02a8684
Fedora 45 mingw-gdk-pixbuf Critical Out Of Bounds and Buffer Overflow Fixes
Fedora 45 OpenSSL 3.5.8 Security Advisory Rebase 2026-9e18ff28a6
Fedora 45 fixes Denial of Service vulnerability in U-Boot version 2026
Fedora 45 bcm283x Firmware Denial of Service Fix 2026-313e66c007
Fedora 45 389-ds-base Heap Overflow Fix Advisory CVE-2026-11774
Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
DSA-6514-1 php8.4 – security update
DSA-6513-1 chromium – security update
DSA-6416-2 jq – regression update
Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs
A crook has been using three open source AI harnesses to target hundreds of online retailers and other companies, swiping more than 600,000 credit card [...]
Debian 12 Redis Critical Use-After-Free and Out-of-Bounds Alerts DLA-4794-1
Slackware PHP Important Buffer Overflow and Memory Fixes SSA-2026-267-01
Linux Cgroup Namespace Race Could Expose a Freed Root Object
A cgroup namespace gives a Linux process a limited view of the control-group hierarchy that organizes workloads and accounts for resources.
Kubernetes Security Fix Blocks Cross-Namespace Pod Creation
Kubernetes released fixes on Sep 23, 2026 for a control-plane flaw that could create a pod outside the namespace where a user’s permissions applied. [...]
Linux Device Driver Race Leaves Open Files Using Freed Memory
A Linux device driver can keep an open file alive while freeing the hardware state that file still needs.
Linux Integrity Checks Could Read Freed dm-verity Policy Data
Linux integrity checks depend on more than a correct policy or a trusted hash. The kernel must also keep that security state alive for the entire decision. [...]
Linux Console Font Bug Could Read Past Its Memory Buffer
A Linux console font change could leave the framebuffer console with a buffer sized for 256 characters even after a 512-character font was installed.
Ubuntu curl USN-8820-1 Important Remote Code Exec Denial of Service
Ubuntu libass Security Notice USN-8815-1 Code Execution Denial of Service
Ubuntu GDAL Critical Code Execution Crash Threat Notice USN-8812-1
DSA-6511-1 znc – security update
OpenAI Agent Breached Australian Medicare Statistics Portal
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send [...]
Microsoft Password Reset Portal Can Leak Account Verification Details
Decades-old file security flaws found in Android, Linux, macOS, and Windows
Security researchers affiliated with Austria’s Graz University of Technology have found flaws in the implementation of file notification systems on [...]
CVE flood pushes Ubuntu onto weekly kernel release cycle
Canonical is speeding up Ubuntu kernel releases to one a week as AI-assisted bug hunting helps bury defenders under an ever-growing pile of CVEs. The [...]
The Hidden Security Risks of Devices You Forgot Were Connected
Someone went shopping in ASUS’s eShop – for customer data
Asus has warned eShop customers that an intruder got into part of its online store and may have helped themselves to contact details and order records. The [...]
Teradata aims to make agentic execution of multistep data work more efficient
Teradata is adding a context engine, an execution layer, and reusable agent skills to Tera, its AI-powered workspace for enterprise data and AI tasks, in [...]
SCOUTz Prospect Intelligence Platform Launches for MSPs with 30-Day Beta
Google to critical infra orgs: Our AI scanners won’t be evil, promise
Google has jumped on the AI-defense-for-critical-systems train with its Scan for Good initiative, and says that its threat-hunting models have already [...]
Ukrainian ransomware developer jailed for nearly 13 years
Turning security complexity into useful intelligence: What’s new in Red Hat Lightspeed
In a post-Mythos world, IT teams face a mounting crisis. Many are doing more with the same staff, and security work hasn’t gotten simpler. Alerts still [...]
2026 update: The road to quantum-safe cryptography in Red Hat OpenShift
A year ago, I wrote about the road to quantum-safe cryptography in Red Hat OpenShift. At the time, much of that road was forward-looking: TLS 1.3 was not [...]
AlmaLinux 8 Python 2.7 Major SQL Injection Info Disclosure Vulnerability
AlmaLinux 8 Container-Tools Important Security Fix CVE-2019-5736
AlmaLinux 8 libyang Bug Fix Advisory ALEA-2021-1906 Moderate
AlmaLinux 8 libarchive Moderate Bug Fix Advisory ALEA-2021-1580
New AvisLoader Windows Malware Uses ClickFix Lure and Tox P2P for C2
Managing the life cycle of AI agents at scale
There’s a new reality emerging for development teams: existing software delivery practices don’t translate cleanly to agentic AI systems. Practices built [...]
Government contractor exposed path to immigration records
Welcome back to PWNED, the column where we look at all the ways your security can become self-owned. Today’s scary story involves government contractors [...]
Mageia 10 xdg-dbus-proxy Medium Broadcast Filtering Bypass CVE-2026-93676
Mageia perl-URI Important IDNA Encoding Fix CVE-2026-19953
Mageia KBD Important Local Escalation Vulnerability CVE-2026-72693
Fedora 43 Chromium Critical Race Condition Buffer Overflow Vulnerability
Fedora 43 kernel 7.2.7 Important System Fix Advisory FEDORA-2026-8202400aa0