Menu

Latest articles

Humans in the loop miss a third of dangerous AI coding agent requests
A browser-based game designed to test humans’ ability to safely approve AI coding agent requests suggests humans in the loop aren’t as good at [...]
IT department put sticky notes on the laptops to help employees log in
PWNED Welcome back to PWNED, the weekly column where we lovingly poke fun at other organizations’ security screw-ups, in hopes the rest of us can [...]
Meta launches Muse Code for complex software work with persistent AI agents
Meta has released a beta coding agent designed to handle complex software assignments across large codebases. Available for macOS and Linux, Muse Code uses [...]
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Agents are coming for data (just slowly)
Agents have turned up just about everywhere in software this past year, with one conspicuous exception: data. That’s a little odd, because querying data is [...]
Microsoft Web IQ: Ground your AI agents with up-to-date web data
Microsoft has unveiled a suite of IQ products over the last few months. Work IQ, Fabric IQ, and Foundry IQ build on what Microsoft used to call its [...]
Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway
Chinese Wi-Fi router vendor Zbtlink has denied its products contain backdoors but paused firmware downloads while it fixes unspecified security [...]
Rocky Linux sg3_utils Important Command Execution Fix RLSA-2026-50142
Rocky Linux Kernel Moderate DoS Bug Fixes RLSA-2026-49871
Rocky Linux 10 ldns Important Off-Path Attack Fix RLSA-2026-49836
Rocky Linux Thunderbird Significant Security Patch RLSA-2026-49621
Rocky Linux 10 libgcrypt Moderate Denial of Service RLSA-2026-50144
Rocky Linux RLSA-2026-50747 freerdp Important Remote Code Execution Fix
Rocky Linux sg3_utils Important Command Execution Fix RLSA-2026-50141
Rocky Linux Thunderbird Update for Flaws RLSA-2026-49921 CVE-2026-14899
Rocky Linux libgcrypt Moderate DoS Buffer Overflow Risk RLSA-2026-50147
Rocky Linux 9 ldns Important Off-Path Poisoning Attack RLSA-2026-50108
Rocky Linux 9 fence-agents Important Denial of Service Fix RLSA-2026-50317
Fix for Low DoS Vulnerability in Kernel of Rocky Linux 9 RLSA-2026-49870
Rocky Linux 9 osbuild-composer Important DoS Fix RLSA-2026-49838
Rocky Linux kernel-rt Moderate IPC Security Issue RLSA-2026-49851
Rocky Linux Thunderbird Security Advisory RLSA-2026-49922 – Critical Update
Rocky Linux Moderate Info Disclosure Security Update RLSA-2026-49927
Rocky Linux 8 RLSA-2026-49857 Kernel Moderate Bug Fix and Security Update
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
The chain of events leading up to OpenAI’s agents attacking Hugging Face and other organizations in July began months earlier, and involved agents asking [...]
SUSE Wireshark Important Denial of Service Protocol Crash Vuln 2026-3501-1
openSUSE 15.5 SUSE-SU-2026-3502-1 OpenSSL Important DoS Issue
SUSE Python-Django Critical DoS And XSS Issues Resolution 2026-3503-1
SUSE Containerd Moderate Denial of Service Fix 2026-3504-1 CVE-2026-35469
SUSE openSUSE Leap 15.5 Critical pcp Security Update 2026-3505-1
SUSE pcp Critical DoS Command Injection Advisory 2026-3506-1
SUSE pcp Critical Command Injection and DoS Vulnerabilities Fix 2026-3507-1
SUSE 12 SP5 PCP Critical Command Injection and Escalation Flaws 2026-3508-1
Java 28 starts to take shape
Java Development Kit (JDK) 28, a non-LTS (Long-Term Support) or “feature release” of standard Java due in March 2027, has started to take shape. Features [...]
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
openSUSE Vifm Important Buffer Overflow Fix CVE-2026-8997 2026-0276-1
openSUSE python-nltk Important ReDoS Path Traversal Updates 2026-0277-1
Oracle Linux 7 Kernel Important Security Update ELSA-2026-500121
Oracle 8 fence agents Advisory ELSA-2026-49927 for CVE-2026-44431
Oracle Thunderbird Significant Revision ELSA-2026-49922
Oracle ELSA-2026-49520 ldns Important DNS Source Validation Issue
Oracle mingw-glib2 Important Buffer Overflow Issues ELSA-2026-49512
Oracle Linux 8 Kernel Important Update CVE-2026-64530 ELSA-2026-49214
Oracle Linux 8 ELSA-2026-500121 Kernel Important Update
Oracle Linux 9 Fence Agents Key Update ELSA-2026-50317-0 CVE-2026-59939
Oracle Linux 9 libgcrypt Buffer Overflow Denial of Service ELSA-2026-50147
Oracle Linux 9 sg3_utils Significant Update Notice ELSA-2026-50141-0
Oracle Linux 9 ldns Important DNS Spoofing Fixes ELSA-2026-50108-0
Oracle Linux 9 Thunderbird Important Security Advisory ELSA-2026-49921
Oracle 9 osbuild-composer Important Bug Fix Advisory ELSA-2026-49838
Oracle Linux 9 p11-kit Moderate Buffer Overflow ELSA-2026-49667
Oracle Linux 9 frr10 Important Bug Fix Advisory ELSA-2026-49607
Significant Security Updates for Oracle Linux 9 Kernel ELSA-2026-49212
Oracle Linux 9 java-25-openjdk Important Security Update ELSA-2026-42899
Oracle 10 libgcrypt Moderate DoS Buffer Overflow Vuln ELSA-2026-50144-0
Oracle Linux 10 sg3_utils Important Bug Fix Advisory ELSA-2026-50142-0
Oracle PHP8.4 Minor Bug Fix Advisory Announcement ELSA-2026-49914
Oracle Linux 10 ELSA-2026-49836 ldns Important Off-Path Attack
Oracle Linux 10 Kernel Significant Bug Fixes – ELSA-2026-49211 Updates
Oracle Linux 10 Node.js Important Security Advisory ELSA-2026-48034
Prompt injection isn’t the bug, AI agent frameworks are
Nearly a dozen flaws, some critical, in major AI agent frameworks that enterprises use to build apps reveal a security failure that extends beyond prompt [...]
Strengthening Linux Cybersecurity in Enterprise Infrastructure
Linux runs cloud platforms, containerized applications, and business-critical servers. It is the engine that powers much of today’s business [...]
Visual Studio Code 1.132 advances built-in dictation
Visual Studio Code 1.132, the latest version of Microsoft’s popular, open-source code editor, has been released. The brings improvements to built-in [...]
Choosing the Right Secrets Detection Platform
Not every security incident begins with sophisticated malware or a compromised server. Sometimes it is nothing more than a developer pushing code before [...]
IBM’s agentic AI platform is under active attack – patch now
A critical vulnerability in IBM-owned, low-code AI builder Langflow lets unauthenticated attackers execute code remotely on vulnerable default deployments, [...]
AWS updates DynamoDB with native vector search to ease AI application development
AWS is finally adding native vector search to its managed NoSQL database DynamoDB, which is typically used to store high-volume operational and [...]
Reducing Attack Surface Without Breaking Production
When people talk about Linux hardening, the conversation often quickly turns to enterprise security platforms, EDR agents, and complex monitoring stacks.
London cops handed victim’s new address and number to her stalker, watchdog says
UPDATED The UK’s data protection regulator has criticized London’s Metropolitan Police Service (MPS) after its officers handed a victim’s [...]
UK charities count the cost of Beacon CRM cyberattack
Beacon CRM has confirmed it was hit by a cyberattack that exposed data belonging to a growing list of UK charities. The company, which markets its software [...]
Debian DLA-4717-1 Linux Priv Escalation DoS Info Leak Severity Critical
Five ways to evaluate AI agent orchestration platforms
AI agent orchestration platforms coordinate role-based and task-based AI agents, along with the tools, data, and people they depend on, into multistep [...]
A trip down shareware lane
I hope you’ll indulge me this week as I take a break from my usual rantings about agentic coding and meander down memory lane. I learned to code BASIC in [...]
Rocky Linux Kernel Moderate RXSA-2026-49857 CVE-2026-52923 Security Update
Debian botan3 Important Denial of Service Bypass Issues DSA-6412-1
Debian aom Critical Denial of Service CVE-2026-56208 DSA-6411-1
Ruby on Rails critical bug puts every image upload under scrutiny
A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066, could turn a seemingly innocuous image into a front [...]
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project
The UK’s AI Security Institute has observed AI models performing what it calls “unsanctioned action” 19 times during security tests. The Institute (AISI) [...]
Fedora 43 open62541 Denial of Service Updates 2026-1435f05fde
Fedora 43 doctl Security Update Denial of Service Vuln 2026-a36bdff8d7
Fedora 44 Kernel Important Fix Security Advisory 2026-864f36550e
Fedora 44 Perl Update Addresses Critical Buffer Overflow Vulnerabilities
Fedora perl-Devel-Cover Important Heap Overflow Info CVE-2026-8376
Fedora 44 perl-PAR-Packer Critical Buffer Overflow and Disclosure Fix
Fedora 44 Perl Critical Heap Buffer Overflow Information Leak Advisory
Fedora 44 abrt Vulnerability in Content Injection and Race Condition
Fedora 44 Coreutils Denial of Service CVE-2026-56391 Advisory
Fedora 44 open62541 v1.5.6 Denial of Service Advisory ID 2026-23b21104ef
Fedora 44 doctl Update Denial of Service Vulnerabilities 2026-7ca1b24b3c
Slackware 15.0 stunnel Critical Memory Access Issues Fix SSA-2026-216-01
DSA-6412-1 botan3 – security update
DSA-6411-1 aom – security update
SnapLogic introduces agentic assistant for data integration
SnapLogic has introduced its new SnapGPT, an agentic assistant that helps enterprise teams plan, build, understand, and operate integrations through [...]
Rocky Linux Kernel Low Denial of Service Issue RXSA-2026-49870
SUSE 15-SP7 rsyslog Important Buffer Overflow Vuln 2026-3478-1
SUSE Kubevirt Important Addressing Four Issues 2026-3480-1
SUSE netty Important Resource Exhaustion Security Update 2026-3482-1
openSUSE Valkey Important Remote Code Execution Threat 2026-3483-1
SUSE Linux 15 SP6 Important RCE TLS Issues Fix Vuln 2026-3483-1
SUSE bind Important DNS Cache Poisoning Fix Advisory 2026-3484-1
openSUSE spice-vdagent Important Buffer Overflow Threats 2026-3485-1