Menu

Latest articles

DSA-6492-1 ruby-rack – security update
More JFrog Artifactory bugs under attack, and all 3 have patches
JFrog Artifactory instances continue to get hit hard. Multiple attackers are exploiting three JFrog Artifactory bugs to gain administrative control over [...]
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor
Anthropic finds evidence of a fourth AI escaping from containment
Anthropic has owned up to a fourth security incident involving its AI model, Claude, escaping onto the open internet and attacking other organizations [...]
OpenAI launches managed Agents API to simplify enterprise AI agent development
OpenAI on Wednesday introduced a new Agents API that brings the agent harness and infrastructure behind Codex to developers, potentially giving enterprises [...]
Ukrainian lawyer’s second career as a Conti coder earns him 4 years behind bars
A Ukrainian lawyer who wound up coding malware for the Conti ransomware gang has been sentenced to four years in a US prison. Oleksii Oleksiyovych [...]
EU’s Cyber Resilience Act starts the 24-hour vulnerability clock
Manufacturers selling products with digital elements in the EU must now report actively exploited vulnerabilities to cybersecurity authorities under the [...]
Adobe Patches Actively Exploited Magento Vulnerability on Linux Servers
Adobe has released an emergency fix for a Magento vulnerability that attackers are already using against online stores. Someone exploiting the flaw can [...]
New Linux Kernel Testing Tool Can Force Race Conditions
Linux kernel testing can miss a bug when it depends on two tasks reaching the same data in an unusual order. These independently running tasks are called [...]
Linux Privilege Escalation Exploit Uses an RDS Cleanup Bug
A new Linux privilege escalation exploit shows how a cleanup mistake in Reliable Datagram Sockets, or RDS, can give a local user root access, meaning [...]
IPv6 Security Flaw Lets Route Listing Reach Freed Kernel Memory
Listing network routes should tell administrators where traffic will go. An IPv6 security report instead shows Linux accessing a freed record used to keep [...]
Ubuntu Flatpak File Access Deletion Issues CVE-2026-34078 CVE-2026-34079
Ubuntu 26.04 LTS .NET Important Info Exposure and Code Exec 2026-8740-1
Ubuntu FFmpeg Important Denial of Service Exploit USN-8716-2
Cloud has a new bulk capacity market
For 15 years, public cloud providers have defined the industry for most enterprises: on-demand, automatically metered services delivered over the open [...]
Rocky Linux 10 Tar Moderate Hidden File Injection and Path Escape Issue
Fedora 43 curl Update 2026-6841033933 Denial of Service Info Leak
Fedora 43 libevent Critical Security Fixes and Important Updates Released
Fedora 43 Corosync Critical Heap Overflow Fix CVE-2026-81666 CVE-2026-81665
Fedora 43 DokuWiki RCE Object Injection Advisory 2026-046b69d591
Fedora grpcurl Update Severity Denial of Service Advisory 2026-275646ea83
Fedora 43 Rest Security Advisory CVE-2026-16615 Weak Random Number Fix
Fedora 44 curl Advisory for Critical Security Issues CVE-2026-10536
Fedora 44 bluez Advisory 2026-d4156b5fc5 Security Issues Addressed
Fedora 44 DokuWiki Backport Remote Code Execution Advisory Resolution
Fedora 44 grpcurl Denial of Service Risk Update 2026-fc26634b91
Fedora 44 rest Library Moderate Random Number Issue CVE-2026-16615
Ubuntu 20.04 Apache2 Denial of Service & Info Disclosure USN-8571-2
DSA-6493-1 libevent – security update
Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research
In the latest installment of “my AI model is more dangerous than yours,” Anthropic on Thursday warned that cybercriminals and state-sponsored [...]
SUSE Tomcat10 Major Security Update 11 Vulnerabilities Resolved 2026-4119-1
openSUSE opensc Moderate Buffer Overflow Vuln 2026-4122-1
SUSE opensc Moderate Buffer Overflow Vuln SUSE-SU-2026-4122-1
openSUSE opensc Moderate Stack Overflow Update 2026-4123-1
SUSE opensc Moderate Buffer Overflow Vulnerability 2026-4123-1
SUSE Linux Enterprise 15 SP7 Kernel Important Security Update 2026-4120-1
Debian Stable ruby-rack Important Access Restriction Issues DSA-6492-1
Watch out: Apple timepiece can grab snippets of conversation without both speakers’ consent
With the release of Apple Watch Series 12, Apple has decided that it’s ok to capture people’s conversations without their consent. The latest [...]
Why Linux Must Close File Descriptors Before a Filesystem Can Stall
A file descriptor is the numbered handle a running program uses to access an open file or similar resource. Linux can mark it to close automatically when [...]
Ubuntu Python Critical Denial of Service and Code Execution Vuln USN-8744-1
Linux Sandbox Bug Could Read a Freed Parent Directory
A Linux sandbox restricts which files a program can access. Landlock, a kernel facility that lets programs apply those restrictions to themselves, had a [...]
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
An unknown attacker used hundreds of AI agents to exploit two PaperCut MF/NG bugs and break into at least 395 organizations. The victims were concentrated [...]
Safe word: What is it and why do you need one?
AI scams are now hyper-realistic. But there’s one simple way to see through them.
Ubuntu 26.04 KissFFT Notable Denial of Service Vulnerability USN-8745-1
Ubuntu 26.04 Beets Media Injection Vulnerability USN-8747-1 CVE-2026-42052
Ubuntu libEBML Critical Buffer Overflow Denial of Service USN-8746-1
openSUSE waylyrics Important CVE-2026-25541 Security Update 2026-21815-1
openSUSE Helm Important Buffers And Authorization Exploits 2026-21809-1
openSUSE Leap 16.0 Critical Security Update libzypp zypper 2026-21808-1
Ubuntu Linux Kernel NVIDIA Important System Compromise Vuln USN-8748-1
openSUSE Tumbleweed ggml-devel Moderate Update for CVE-2026-52132
openSUSE libmariadb-devel Important CVE-2026-44172 Update 2026-11721-1
openSUSE Chromedriver Medium Update 38 Risks Resolved Advisory 2026-11714-1
openSUSE Corosync Moderate Security Issues Fixed in 2026-11715-1
Oracle Linux 10 qt6-qt5compat Important Out-of-Bounds Read CVE-2026-9499
Oracle Linux 9 qt5-qtbase Vital Out-of-Bounds Read Patch ELSA-2026-65993-0
Oracle Linux Important qt5-qtbase Fix for CVE-2026-9499 ELSA-2026-65897-0
Oracle ThunderBird Important Update ELSA-2026-65160-0 CVE-2026-74934
Oracle Linux 8 ELSA-2026-62667-0 perl-DBI Important Buffer Overflows
Oracle Linux 7 Python-urllib3 Critical Buffer Overflow Alert ELSA-2026-9031
Oracle gstreamer1-plugins-bad-free Important Update ELSA-2026-54752
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
Ubuntu PHP Critical SQL Injection and DoS Vulnerabilities USN-8743-1
Ubuntu 24.04 LTS GNU C Library Security Advisory USN-8737-2 Details
ShinyHunters expose 6.4M in attack on medical supplier McKesson
McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service [...]
SUSE openSUSE Moderate Patch for python-Authlib CVE-2026-41479
SUSE Libzypp Zypper Critical Update Security Fixes SUSE-SU-2026-4112-1
Moderate Severity Alert for SUSE Python-aiohttp Due to HTTP Smuggling Risk
SUSE tomcat11 Important Security Update for 11 Bugs SUSE-SU-2026-4114-1
SUSE Linux Important strongswan Security Update 2026-4115-1
SUSE bzip2 Critical Off-By-One Vulnerability Advisory 2026-23494-1
The Lightwell reality check
We’ve been talking with business leaders about Lightwell for the past few months, and the conversation always starts with enthusiasm. AI-driven exploits [...]
Accelerating post-quantum security migration with Red Hat Certificate System
The realities of quantum computing and its inevitable impact on enterprise cryptography are already taking shape:Red Hat Enterprise Linux has been [...]
Beyond container boundaries: Kernel-level agent security in Red Hat OpenShift AI 3.5
77% of organizations now have AI agents running in production.1 The adoption curve is steep. The governance curve is not. Agents operate over-permissioned [...]
Linux Security Visibility: What Your Logs Need to Tell You
Suppose an application setting has changed on a Linux server, but nobody remembers changing it. The application still works, and the usual health checks [...]
Unveiling Operation DreamJob: A New Threat for Linux Users
Security researchers have recently discovered that Linux users targeted with malware in the new “Operation DreamJob” Lazarus campaign for the first time.
SpaceX: 32,000 Linux Systems Deployed in Starlink Constellation
Assuming the second-generation satellites carry the same number of Linux computers, it would mean SpaceX plans to send at least two million Linux computers [...]
Effective Infrastructure Monitoring for Downtime Prevention
Infrastructure monitoring is an integral part of infrastructure management. It is an IT manager’s first line of defense against surprise downtime.
Linux cgroup Memory Limits Can Miss Kernel Network Use
A Linux cgroup, or control group, limits how much memory a group of processes can use. Yet its counters can look normal while those processes cause the [...]
Linux NFS Control File Can Reach Freed Kernel Memory
A program can keep a Linux file open even after the separate networking environment behind it has started shutting down. That environment is called a [...]
Linux IPv6 Segment Routing Bug Can Write to Freed Packet Memory
Linux can move a network packet’s data in memory while some networking code still holds its old address. That saved address is called a pointer. A [...]
Why enterprises should start with on-site AI agents
When I talk to people about agents interacting with websites, the conversation almost always starts with perception: how does an agent “see” a page? Is it [...]
Build your AI stack like you will need to replace it
Every AI feature you’re building is based on a price that isn’t real. Current AI services are heavily subsidized as model providers seek to expand their [...]
Your frontend observability has an accessibility blind spot
Frontend teams have become pretty good at monitoring what happens after an application reaches production. We track JavaScript errors, API failures, [...]
Dental contractor set up secret account with access to 4,000 patient records then left the company
PWNED Welcome back to PWNED, the weekly column where we highlight examples of how not to handle your security. This week’s tale of woe comes from a very [...]
Anthropic reveals fourth likely crime committed by its AI
Amid industry soul-searching¹ about the possibility of AI improving itself to the point that it kills everyone, Anthropic has revealed yet another incident [...]
Smashing Security podcast #484: How websites are tracking you with silence
Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one [...]
DSA-6490-1 fort-validator – security update
Mageia Thunderbird Privilege Escalation and Isolation Flaws MGASA-2026-0388
Mageia Firefox Important Use-After-Free Escapes 2026-0387 CVE-2026-75874
Mageia wget Important Denial of Service Fix for CVE-2026-16599
SUSE 2026-23454-1 Systemd Moderate Local Privilege Escalation Fix
SUSE Linux Micro 6.0 Security Update for Helm Moderate CVE-2026-33630
SUSE Linux Micro 6.2 Intel Microcode Important Security Update 2026-23459-1
SUSE Libvirt Important Threats and Security Update Advisory 2026-23460-1
SUSE Linux Micro OpenSSL-3 Important Memory Overflow Patch 2026-23463-1
SUSE cpio Moderate Denial of Service and Injection Fix 2026-23464-1
SUSE Linux Micro Security Advisory 2026-23465-1 for sssd Moderate Issues
SUSE Linux Micro Critical dracut Command Injection Flaw 2026-23466-1