Menu

Latest articles

Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer?
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
Debian Trixie Unzip Important Code Execution Issue DSA-6440-1
Debian Trixie Zip Command Injection Vulnerability DSA-6439-1
Gentoo Bubblewrap Critical Root Access Risk GLSA-202608-09 CVE-2026-41163
Gentoo libinput High Multiple Vulnerabilities GLSA-202608-08
Gentoo Exim High Code Exec Vulnerabilities GLSA-202608-07
Gentoo Flatpak High Sandbox Escape Issues GLSA-202608-06
Rocky Linux php8.4 Low Bug Fix DoS Enhancement RLSA-2026-49914
Rocky Linux 10 PHP Low Denial of Service Fix RLSA-2026-48170
Rocky Linux Advisory RLSA-2026-40416 PHP 8.2 Low Denial of Service
Rocky Linux 9 PHP Low Security Fixes RLSA-2026-48197 CVE-2026-14355
Rocky Linux 8 php Low Denial of Service RLSA-2026-47750 CVE-2026-14355
Rocky Linux PHP RLSA-2026-47749 Low AES-WRAP-PAD Denial of Service
Gentoo Apache HTTPD High Remote Execution Risk GLSA-202608-05
Gentoo Dnsmasq High Remote Code Execution Multiple Issues GLSA-202608-04
Gentoo rsync Important Multiple Privilege Escalation Issues GLSA 202608-03
Fedora 43 erlang-cowlib Denial of Service Fix 2026-ce97d80dae
Fedora 43 erlang-cowboy Denial Service Fix Advisory 2026-ce97d80dae
Fedora 44 flatpak Security Advisory Update 1.18.1 FEDORA-2026-6b83471b0e
Fedora 44 libnfs Important Fixes for CVE-2026-57918 CVE-2026-53689
Fedora 44 erlang-cowlib Denial of Service Fix 2026-7d233ad8b0
Fedora 44 erlang-cowboy Denial Of Service Fix Advis 2026-7d233ad8b0
Oracle Linux 10 FreeRDP Important Buffer Overflow Fix ELSA-2026-54486
Oracle Linux 10 python-idna Moderate IDNA Fix Advisory ELSA-2026-54481
Oracle Linux Grafana Moderate Fix Advisory ELSA-2026-54178 CVE-2026-8609
Oracle Linux 10 ELSA-2026-36541 Kernel Important Bug Fix Advisory
Oracle Linux 9 Python3.9 Important Security Advisory ELSA-2026-54268
Oracle Linux 9 Java-17-OpenJDK Significant Security Notice ELSA-2026-42887
Slackware 15.0 rsync Security Update Advisory 2026-225-01
Rocky Linux 10 RLSA-2026-54486 FreeRDP Important Remote Code Execution
Mageia dhcpcd Critical Memory Corruption DoS Vuln 2026-0335
Ubuntu Linux Kernel Advisory USN-8633-2 – Important Security Fixes
Ubuntu 22.04 LTS Linux Kernel Security Fix USN-8631-3 CVE-2025-27558
Oracle Linux 8 Advisory ELSA-2026-54290 python-idna Moderate CVE-2026-45409
Oracle Linux 8 grafana Critical Security Revision ELSA-2026-54243
Oracle Linux 8 isns-utils Important Double-Free Fix ELSA-2026-53848
Oracle Linux 8 perl-DBI Important Buffer Overflow Fix ELSA-2026-52772
Oracle Kernel Moderate Security Advisory ELSA-2026-52765 CVE-2026-64496
Oracle Linux 7 glib2 Important Buffer Overflow Fix ELSA-2026-51183
Oracle Linux 7 libXfont2 Important CVE-2026-56001 ELSA-2026-51063
Oracle Linux 7 ELSA-2026-50808 libpng Moderate CVE-2026-33416
Oracle Linux 7 gstreamer1-plugins-good Security Update ELSA-2026-49603
Ubuntu 16.04 Kernel Important Flaw Escalates Privileges USN-8548-2
Ubuntu 16.04 Linux Kernel Important Privilege Escalation Issues USN-8530-2
Ubuntu 16.04 LTS Kernel Important Flaw Escalation CVE-2026-43503
Debian PostgreSQL DSA-6438-1 Multiple Security Issues Detected
Ubuntu 26.04 LTS Axios High Server-Side Request Forgery Issues USN-8638-1
DSA-6435-1 spip – security update
Routing Security in Practice: Detecting BGP Hijacks and RPKI-Invalid Announcements
Border Gateway Protocol (BGP) is still trust-based. In the past, a router would announce it originated a block of address space, and its neighbors would [...]
Debian 12 DLA-4739-1 Chromium Important Security Flaws Fixed
Ubuntu 26.04 LTS Linux Kernel Advisory USN-8637-1 Security Update
Ubuntu 22.04 LTS Linux Kernel Significant Packet Injection Flaw USN-8631-2
Ubuntu 24.04 LTS Kernel Security Update Addresses Key Issues USN-8630-2
Visual Studio Code 1.133 brings flexibility to Claude sessions
Microsoft has released Visual Studio Code 1.133, an update to its code editor that brings more flexibility to Anthropic Claude sessions. The update also [...]
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong
Trump wants to grant private cyber firms a license to hack back
Donald Trump is allowing government agencies to contract private cybersecurity companies to carry out operations against cyber-enabled transnational [...]
The backup Microsoft never promised you
Confidence in an organization’s cyber recovery capabilities deserves scrutiny. If a ransomware attack disables the SaaS data tenanted in the [...]
eBPF Security Logs May Show the Wrong File or Command, New Study Warns
A Linux security tool can catch a system call and still record the wrong thing.
Linux Audit Can Log a Syscall but Miss the Flag That Explains It
Linux Audit can tell defenders that a system call ran while leaving out the setting that explains what the call did.
Databricks acquires Electric to bring local Postgres databases to agentic apps
Databricks is acquiring Electric, a startup that brings WebAssembly-based Postgres databases into application environments, for an undisclosed sum, in an [...]
Linux Security Roundup Privilege Escalation DoS Code Execution August 2026
This week’s Linux security updates cover several areas administrators cannot afford to overlook. Debian, Ubuntu, Fedora, SUSE, openSUSE, and other [...]
AWS key exposed in JavaScript may have lit way to Beacon’s charity data
Beacon, a CRM provider for charities and nonprofits, says an AWS access key “potentially exposed in public JavaScript build artifacts” is the [...]
Rocky Linux 8 Kernel Update Moderate Security Issues RLSA-2026-54246
Rocky Linux python-idna Moderate Denial of Service RLSA-2026-54290
Rocky Linux 8 abrt Important Arbitrary File Issues RLSA-2026-54272
Rocky Linux 8 RLSA-2026-54247 Kernel-rt Medium Denial of Service
Rocky Linux python3.9 Important Filter Bypass Vulnern RLSA-2026-54268
Relief from the bookkeeping of change management
It’s an idle Tuesday afternoon. You’re in hour three of change management calls to get a CostCenter tag update approved for a production change. Only [...]
Why AI models need a real-time web intelligence layer
A growing sentiment in tech is that large AI model providers will eventually replace traditional software vendors. The argument makes some sense. If a [...]
MCP didn’t remove sessions. It handed them to the model
A few years ago, I helped move an application off sticky sessions so we could scale behind an ordinary round-robin load-balancer. On paper it was an [...]
Passwords stored in public Google Doc then showed up in search results
PWNED Welcome, once again, to PWNED, the weekly column where we highlight others’ security failures. Hopefully, there’s a lesson in all this, but it could [...]
Debian DSA-6433-1 xdg-dbus-proxy Important Policy Bypass
Debian LTS xorg-server Urgent DoS Privilege Escalation Notice DLA-4738-1
Debian DLA-4737-1 xorg-server Critical Privilege Escalation Vulnerabilities
Gentoo FreeType Normal Info Leak Multiple Issues GLSA-202608-02
Chinese Loongson processors have leaky caches, researchers find
Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could [...]
Ubuntu 26.04 LTS USN-8632-1 Follow-Redirects Credential Disclosure
Fedora 43 cri-o 1.34.11 Denial of Service Fix CVE-2026-34986
Fedora 43 vaultwarden 1.37.1 Denial Of Service Fix Advisory 2026-84a39c58c9
Fedora 44 SQLite Arbitrary Code Execution Vulnerability Fix CVE-2026-11822
Fedora 44 Linux Firmware Update Advisory 20260810 FEDORA-2026-c53019ed4f
Fedora 44 apr-util 1.6.5 Denial of Service CVE-2026-32327
Fedora 44 libcupsfilters Important CPU Exhaustion Fixes 2026-f77201a75e
Fedora 44 cri-o 1.34.11 Important Denial of Service Fix 2026-8ce4ffda9c
Fedora 44 Vaultwarden Medium Denial of Service Fix 2026-c28185613c
SUSE gzip Moderate Buffer Overflow Vulnerability ID 2026-3592-1
DSA-6437-1 apr-util – security update
DSA-6436-1 chromium – security update
Smashing Security podcast #480: This is the AI service you should never sign up to
Ubuntu Libgit2 Security Advisory USN-8628-1 Multiple Issues Fixed
Lovable reaches $13.3B valuation as it adds Cerebras, enterprise tools
Vibe-coding website company Lovable has raised $400 million in Series C funding at a $13.3 billion valuation. The company also recently announced a [...]
openSUSE Chromium Critical Update for 41 Vulnerabilities SU-2026-0281-1
Rocky Linux 8 RLSA-2026-47126 Resource Agents Moderate Info Disclosure
Rocky Linux 8 RLSA-2026-47117 libgcrypt Moderate Denial of Service Fix
‘Near-autonomous’ AI agents attack Taiwan’s nuclear safety agency
Suspected Chinese cyber operatives used publicly available AI tools to compromise Taiwanese government systems before expanding the attack to its nuclear [...]
Debian LTS Python Django Key CVE-2026-15337 2026-15920 Advisory DLA-4736-1
Debian SPIP Remote Code Execution SQL Injection and SSRF DSA-6435-1
SUSE Gzip Moderate Buffer Overflow Security Advisory 2026-3590-1
SUSE Kernel Important Fix for 59 Vulnerabilities 2026-3593-1