Menu

Latest articles

Beyond the screenshot: Why you should verify what you see
The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine
The most famous brand in physical security got pwned by ShinyHunters
A leading name in home and business physical security, Brinks Home, recently said it identified unauthorized access to a portion of its IT systems, an [...]
Anthropic and OpenAI are competing to see whose agents can go rogue harder
One company’s inventive campaign for an unreleased product has become a contest between Anthropic and OpenAI to see which can shout the loudest about [...]
Charities remain locked out of CAF Bank online accounts
A week after suspending online banking, CAF Bank still has no timetable for restoring access to its 14,000 UK charity customers. The bank updated customers [...]
Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs
Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure [...]
The $5 million threat: AI Is supercharging phishing attacks
No time to lose: Why post-quantum security for financial services must start now
Post-quantum cryptography: The emerging threatThe transition to post-quantum cryptography (PQC) is becoming an urgent priority for the global financial [...]
Lights on! Real-time threat response with Red Hat Advanced Cluster Security
Part 2 of a series on implementing zero trust in Red Hat OpenShift with the layered zero trust validated pattern (ZTVP)In our previous article, we explored [...]
JetBrains says a crafted HTTP request could break TeamCity
JetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary [...]
OpenAI drops GPT-5.6 Luna and Terra API prices by up to 80%
OpenAI has cut API prices for its GPT-5.6 Terra and Luna models by 20% and 80%, respectively, while also reducing the number of usage credits the models [...]
Rocky Linux perl Important DoS Security Fix RLSA-2026-48225 CVE-2026-9538
Why observability matters to frontend teams more than they think
For a long time, I thought of observability as something mainly owned by backend, platform or site reliability teams. Frontend engineers built the [...]
UK says the cloud is financial infrastructure
Every cloud architect, every financial services executive, and frankly every enterprise CTO should be paying attention to what is going on in the United [...]
The platform team isn’t a cost center, it’s product infrastructure
A few years ago, I sat in a postmortem that I still think about. We’d had a production incident where a routine deploy had quietly shipped with the wrong [...]
Debian LTS gsasl Important Memory Disclosure Fix DLA-4707-1 CVE-2026-56968
Anthropic’s Claude escaped test sandbox to attack three organizations
Anthropic has admitted that its Claude models escaped sandboxes to access the open internet and attack three organizations – but has also advanced decent [...]
Fedora 43 Unbound Critical DNS Denial of Service Fixes 2026-3170ee6a1c
Fedora 43 Pack Security Update 2026-e6e0368149 Addresses CVEs
Fedora 43 dokuwiki Security Advisory FEDORA-2026-68853bb50c Backport Fixes
The Fedora update for DokuWiki enhances its security by backporting patches, ensuring the wiki remains easy to use while storing content in plain text files.
Fedora 43 NASM Critical Heap Vulnerability Fixes Addressed 2026-9af234bcd6
Fedora 43 Lego Off-path Poisoning CVE-2026-10846 Advisory 5.3.1
Fedora 43 Valkey 8.1.9 Important Remote Code Exec Fixes 2026-9de44775c7
Fedora 43 libnbd Security Advisory 2026-045e6f85c6 Command Injection
Fedora 44 Pack Critical Local Privilege Escalation and SSH DoS Updates
Fedora 44 DokuWiki Security Fixes Advisory 2026-d37b1b981a
Fedora 44 Valkey Important TLS Remote Code Exec Vuln 2026-3d18a65cc4
Ubuntu OpenSSL Critical Denial of Service Issue USN-8625-1
DSA-6405-1 linux – security update
JetBrains open sources KotlinLLM runtime code generator
KotlinLLM, a research prototype for delegating runtime logic to a large language model (LLM) from Kotlin code, is now going open source and public, [...]
Rocky Linux openssh Important Denial of Service Threat RLSA-2026-47756
Rocky Linux 9 Kernel Important Security Fixes RLSA-2026-47040
openSUSE python3-pyOpenSSL Low Unhandled Exception CVE-2026-27448
SUSE python3-pyOpenSSL Low Issue Bypass Risk Advisory 2026-3424-1
openSUSE python-urwid Important Insecure Web Session IDs CVE-2026-9323
SUSE python-urwid Important Web Session Security Fix 2026-3425-1
SUSE Bind Important DNSSEC Cache Poisoning Vulnerabilities 2026-3426-1
SUSE Valkey Important Remote Code Exec Vulnerabilities 2026-3427-1
SUSE Runc Low Integrity Risk Fix Advisory 2026-3428-1 CVE-2026-41579
openSUSE libarchive Moderate Denial of Service and Other Issues 2026-3429-1
SUSE libarchive Moderate File Handling Issues Advisory 2026-3429-1
openSUSE Tomcat Important Security Issues Update CVE-2026-59083 59084
SUSE Tomcat 11 Important Security Update CVE-2026-59083 CVE-2026-59084
DSA-6403-1 nss – security update
Debian LTS ruby-rack Security Update Denial of Service DLA-4706-1
From Dirty COW to DirtyDecrypt: Why Linux Keeps Rediscovering Memory Ownership Bugs
Dirty COW. Dirty Pipe. Dirty Frag. DirtyDecrypt.
Mageia libxfont2 Important Heap Buffer Overflows Vuln 2026-0311
Mageia 389-ds-base Critical CPU Amplification Dos Vulnerability 2026-0310
Mageia 10 9 nghttp2 Important HTTP Smuggling Fix CVE-2026-58055
Mageia perl-DBI Moderate Multiple Security Issues Advisory 2026-0308
SUSE ImageMagick Moderate Code Injection Buffer Overflow Vuln 2026-3412-1
SUSE ImageMagick Moderate Heap Buffer Code Injection Vulnern 2026-3413-1
SUSE Important Update for Prometheus-Ha Cluster Exporter CVE-2026-39821
openSUSE 16.0 s2n Moderate Memory Leak Man-in-the-Middle Fix 2026-21474-1
openSUSE Leap 16.0 Apptainer Important Update CVE-2026-39821 CVE-2026-56852
openSUSE Keybase Client Low ASCII Punycode Issue Advisory 2026-21471-1
openSUSE GraphicsMagick Low Heap Buffer Overwrite Issue 2026-21468-1
openSUSE Java-25-OpenJDK Important Denial of Service Fix 2026-21467-1
openSUSE Python313 Important Update for Multiple Issues 2026-21459-1
openSUSE logcli Moderate CVE-2026-39822 Package Update 2026-11393-1
openSUSE kubevirt1.8-container-disk Moderate Security Update 2026-11392-1
openSUSE Tumbleweed Kubernetes Moderate APIServer Update CVE-2020-8561
openSUSE Tumbleweed Kubernetes Medium CVE-2020-8561 Advisory 2026-11389-1
openSUSE Tumbleweed Kubernetes Medium CVE-2020-8561 Advisory 2026-11390-1
openSUSE Tumbleweed ffmpeg Moderate CVE-2026-8461 Security Update
openSUSE Helm Moderate Security Update CVE-2026-63308 2026-11386-1
openSUSE freerdp Moderate Patch for 3 Vulnerabilities 2026-11385-1
Jailed Flock vandal wipes out three cameras, racks up thousands in damages
Note to privacy-conscious vandals: If you’re going to destroy Flock license plate readers, make sure you also take out the other CCTV cameras in the [...]
Ubuntu 22.04 LTS Sinatra Denial of Service Vulnern 2026-8624-1
Ubuntu 22.04 20.04 libinput Important Code Execution Issue USN-8602-1
Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
A critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by [...]
New Databricks tool uses AI agents to rewrite legacy SQL at scale
Databricks is adding an agentic code conversion capability to its Lakebridge toolkit, using Genie Code to provide its new customers another way to move [...]
Debian expat Critical Memory Corruption Denial of Service Vuln DSA-6404-1
Rocky Linux openssh Medium Risk Resolution RLSA-2019-3702
Rocky Linux perl Important Denial of Service Vuln RLSA-2026-48225
Rocky Linux GStreamer Important Buffer Overflow Fix RLSA-2026-47731
SUSE GIMP Important Buffer Overflow Threat Advisory 2026-3399-1
SUSE PackageKit Moderate Improper Authorization Issue Advisory 2026-3405-1
SUSE Python-Dulwich Important SSH Host Key Update CVE-2026-38974
SUSE PackageKit Moderate Authorization Manipulation Vuln 2026-3404-1
SUSE Rsyslog Important Denial of Service Fix Advisory 2026-3398-1
SUSE WebKit2GTK3 Important Memory Corruption Process Crash Fix 2026-3396-1
SUSE Python-urllib3 Moderate Denial of Service Vuln 2026-3397-1
SUSE 15.6 OpenVPN Significant DoS Security Patch 2026-3407-1
SUSE Java 17 Important Security Update CVE-2026-41254 2026-3406-1
SUSE Kernel 2026-3392-1 Important Live Patching CVE-2026-53366
SUSE GraphicsMagick Low Heap Buffer Issue Vuln 2026-3395-1
SUSE OpenSUSE Leap 15.6 Important python-ujson Memory Leak Vuln 2026-3402-1
Russian spies take their half-click email attack from Zimbra to Outlook
The Russian espionage crew that turned simply reading an email into a security risk has expanded beyond Zimbra, with Proofpoint saying it’s now [...]
North Korea’s elite hackers turned on their own government – and got caught
How AI can improve site reliability engineering
One percent of AI-active developers now generate 46 times more AI-written lines of code per day than the median active user, according to the Cursor [...]
Shipping an MCP test agent: The boring parts nobody demos
The demo videos always end at the same moment. A figma frame turns into a passing test in twelve minutes. Someone in the room says the word “productivity.” [...]
AI agents need security regression testing, not another checklist
AI agents are being connected to real systems faster than most organizations are learning how to secure them. That should concern us. The first wave of AI [...]
Headteacher had the most guessable username-password combo you could imagine
PWNED Welcome, once again, to PWNED, the weekly column where we show you how not to use your computer or your network. In this week’s fable of [...]
Excuses like ‘AI did it’ don’t exist in the eyes of the law
The OpenAI rogue agent behind the Hugging Face hack accessed four accounts on four services, according to updated company disclosures about the intrusion. [...]
Fedora 44 libssh 0.12.2 Update Notification FEDORA-2026-c60881e04b
Fedora 44 unbound Critical DoS Issues Fixed in Update 2026-e495bd59ef
Fedora 44 ProFTPD Update Addresses ACL Bypass CVE-2026-35025
Fedora 44 Squid 7.6 Memory Fix Advisory 2026-e6bbab8aa8
Fedora 44 Node.js Updated to 24.18.0 with Denial of Service April 2026
Fedora 44 Fixes Critical SQL Injection and Remote Code Execution Issue