Menu

Latest articles

Safe word: What is it and why do you need one?
AI scams are now hyper-realistic. But there’s one simple way to see through them.
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
ShinyHunters expose 6.4M in attack on medical supplier McKesson
McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service [...]
The Lightwell reality check
We’ve been talking with business leaders about Lightwell for the past few months, and the conversation always starts with enthusiasm. AI-driven exploits [...]
Accelerating post-quantum security migration with Red Hat Certificate System
The realities of quantum computing and its inevitable impact on enterprise cryptography are already taking shape:Red Hat Enterprise Linux has been [...]
Beyond container boundaries: Kernel-level agent security in Red Hat OpenShift AI 3.5
77% of organizations now have AI agents running in production.1 The adoption curve is steep. The governance curve is not. Agents operate over-permissioned [...]
Linux Security Visibility: What Your Logs Need to Tell You
Suppose an application setting has changed on a Linux server, but nobody remembers changing it. The application still works, and the usual health checks [...]
Unveiling Operation DreamJob: A New Threat for Linux Users
Security researchers have recently discovered that Linux users targeted with malware in the new “Operation DreamJob” Lazarus campaign for the first time.
SpaceX: 32,000 Linux Systems Deployed in Starlink Constellation
Assuming the second-generation satellites carry the same number of Linux computers, it would mean SpaceX plans to send at least two million Linux computers [...]
Effective Infrastructure Monitoring for Downtime Prevention
Infrastructure monitoring is an integral part of infrastructure management. It is an IT manager’s first line of defense against surprise downtime.
Linux cgroup Memory Limits Can Miss Kernel Network Use
A Linux cgroup, or control group, limits how much memory a group of processes can use. Yet its counters can look normal while those processes cause the [...]
Linux NFS Control File Can Reach Freed Kernel Memory
A program can keep a Linux file open even after the separate networking environment behind it has started shutting down. That environment is called a [...]
Linux IPv6 Segment Routing Bug Can Write to Freed Packet Memory
Linux can move a network packet’s data in memory while some networking code still holds its old address. That saved address is called a pointer. A [...]
Why enterprises should start with on-site AI agents
When I talk to people about agents interacting with websites, the conversation almost always starts with perception: how does an agent “see” a page? Is it [...]
Build your AI stack like you will need to replace it
Every AI feature you’re building is based on a price that isn’t real. Current AI services are heavily subsidized as model providers seek to expand their [...]
Your frontend observability has an accessibility blind spot
Frontend teams have become pretty good at monitoring what happens after an application reaches production. We track JavaScript errors, API failures, [...]
Dental contractor set up secret account with access to 4,000 patient records then left the company
PWNED Welcome back to PWNED, the weekly column where we highlight examples of how not to handle your security. This week’s tale of woe comes from a very [...]
Anthropic reveals fourth likely crime committed by its AI
Amid industry soul-searching¹ about the possibility of AI improving itself to the point that it kills everyone, Anthropic has revealed yet another incident [...]
Smashing Security podcast #484: How websites are tracking you with silence
Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one [...]
DSA-6490-1 fort-validator – security update
Mageia Thunderbird Privilege Escalation and Isolation Flaws MGASA-2026-0388
Mageia Firefox Important Use-After-Free Escapes 2026-0387 CVE-2026-75874
Mageia wget Important Denial of Service Fix for CVE-2026-16599
SUSE 2026-23454-1 Systemd Moderate Local Privilege Escalation Fix
SUSE Linux Micro 6.0 Security Update for Helm Moderate CVE-2026-33630
SUSE Linux Micro 6.2 Intel Microcode Important Security Update 2026-23459-1
SUSE Libvirt Important Threats and Security Update Advisory 2026-23460-1
SUSE Linux Micro OpenSSL-3 Important Memory Overflow Patch 2026-23463-1
SUSE cpio Moderate Denial of Service and Injection Fix 2026-23464-1
SUSE Linux Micro Security Advisory 2026-23465-1 for sssd Moderate Issues
SUSE Linux Micro Critical dracut Command Injection Flaw 2026-23466-1
SUSE Fuse-OverlayFS Moderate Privilege Escalation Fix 2026-23469-1
SUSE Systemd Moderate Local Privilege Escalation Resolution 2026-23470-1
SUSE Linux Micro Moderate wget Server-Controlled Loop CVE-2026-16599
SUSE openssl-3 Important Security Update Patch 2026-23473-1
SUSE NetworkManager Important Local Privilege Escalation Vuln 2026-23475-1
SUSE Multipath-Tools Moderate Heap Denial Of Service Fix 2026-23476-1
SUSE Kernel Important Security Update Addressing 588 Vulnerabilities
Serial Microsoft 0-day hunter drops yet another Defender exploit
Zero-day researcher Nightmare Eclipse, aka MSNightmare, published yet another Microsoft Defender proof-of-concept exploit for a zero-day dubbed [...]
SUSE Linux Micro Moderate opensc Buffer Overflow Vuln 2026-23478-1
SUSE Linux Micro Critical Kernel Livepatch Upgrade 2026-23479-1
SUSE Micro 6.0 Important Kernel Livepatch Update 29 Advisory 2026-23480-1
SUSE Linux Micro 6.0 Kernel Important Update Vulnerability Fixes 2026-23481
SUSE Linux Micro 6.0 Key Kernel RT Live Patch 14 Advisory 2026-23482-1
SUSE Linux Micro Important Kernel Update CVE-2026-23240 to CVE-2026-64600
SUSE Linux Micro 6.0 Kernel Important Patch 2026-23484-1
SUSE Linux Micro 6.0 Kernel Important Security Update 2026-23485-1
SUSE Linux Micro 6.0 Important Kernel Live Patch 24 Advisory 2026-23486-1
SUSE Linux Micro 6.0 Kernel Important Security Update 2026-23487-1
SUSE Linux Micro 6.0 Important Kernel Live Patch 26 Advisory 2026-23488-1
SUSE Linux Micro 6.0 Important Kernel Security Patch 2026-23489-1
Rocky Linux 10 python3.14-cryptography Security Update RLSA-2026-64795
Rocky Linux 10 389-ds-base Critical Error Fixes RLSA-2026-64785
Rocky Linux Skopeo Key Denial of Service Vulnerability RLSA-2026-64818
Rocky Linux 10 git-lfs Important Denial of Service Update RLSA-2026-64788
Rocky Linux 10 RLSA-2026-64796 Valkey Important Remote Code Execution Fixes
Rocky Linux Thunderbird Significant Security Patch RLSA-2026-65159
Rocky Linux glib2 Moderate Buffer Overflow Resolution RLSA-2026-64799
Rocky Linux 10 Expat Moderate Arbitrary Code Execution RLSA-2026-64810
Rocky Linux 10 xz Moderate Buffer Overflow Fix RLSA-2026-64787
Rocky Linux OpenTelemetry Collector Denial of Service Fix RLSA-2026-65116
Rocky Linux 10 RLSA-2026-65162 gpsd Important Command Execution
Rocky Linux 10 buildah Important Denial of Service and XSS RLSA-2026-64777
Rocky Linux 10 Kernel Important Bug Fix Update RLSA-2026-64775
Rocky Linux glib2 Moderate Heap Overflow Vuln RLSA-2026-64800
Rocky Linux 9 Kernel Important Security Update 2026-64808
Rocky Linux 9 Redis Important RLSA-2026-64824 Remote Code Execution
Rocky Linux pam Moderate Authentication Timing Fix RLSA-2026-64815
Rocky Linux 9 Expat Moderate Heap Buffer Overflow Risk RLSA-2026-64812
Rocky Linux 9 RLSA-2026-65153 osbuild-composer Important DoS XSS Risks
Rocky Linux 9 RLSA-2026-64774 python3.14-cryptography Important Threats
Databricks unveils adaptive AI retrieval model to cut search costs and latency
Databricks on Wednesday introduced Adaptive Instructed-Retriever, a new retrieval model designed to improve enterprise AI search by taking additional steps [...]
WeChat worm could pwn a friend before they even answered the call
Tencent has patched up a zero-click vulnerability that security researchers used to create a worm capable of spreading through calls on WeChat. With more [...]
Google Patches Actively Exploited Chrome Vulnerability Affecting Linux
Chrome release notes can be a blur of version numbers. This one deserves a closer look. In the Linux build published on September 3, 2026, Google fixed [...]
Linux Open vSwitch 2026-47916db6c7 RCU Race Condition Fix
A proposed patch fixes a bug in Open vSwitch, a virtual network switch with an in-kernel Linux packet-processing path. An ordering race can free a [...]
Linux OCFS2 Use After Free Risk Advisory 2026-47916db6c7
A reported race in OCFS2, a Linux clustered file system for shared storage, can trigger a use-after-free while administrators configure a heartbeat region. [...]
Linux Advisory Timer Vulnerabilities Leading to Use-After-Free Issues
A proposed Linux repair addresses two timer bugs that can trigger use-after-free conditions while one program replaces itself with another through exec(). [...]
Important Security Update on PHP Denial of Service for Ubuntu 16.04 LTS
Mageia freerdp Critical Security Update DoS CVE-2026-22851 2026-0383
Mageia Tor Critical Out-Of-Bounds and Memory Issues Advisory 2026-0382
Fedora 44 libsoup3 Important HTTP Library Update CVE Fixes 2026-3f60ccf61f
Fedora 44 Corosync Critical Buffer Overflow Resolution CVE-2026-81666
Fedora 44 Chirp – Resolution for Critical Arbitrary Code Execution Issue
Fedora 44 Baresip Update 2026-27c291e67c – Enhanced Audio and Video Support
Fedora 44 Libre Security Advisory Update 2026-27c291e67c
Fedora 44 perl-Net-OAuth Important Timing Attack Fix 2026-e33554bf9f
Fedora 44 perl-XML-Bare Critical Infinite Loop Fix CVE-2026-57074
Fedora 44 nsd Access Control Bypass and DoS Bug Fixes 2026-bf1539678e
Fedora 43 Chromium Critical Buffer Flaws Advisory FEDORA-2026-c3be138e4c
Fedora 43 chirp Important Arbitrary Code Exec Fix 2026-23b8df7771
Fedora 43 Baresip Update Announcement – Advisory 2026-3edf59885d
Fedora 43 Libre Baresip v4.11.0 Security Advisory FEDORA-2026-3edf59885d
Fedora 43 perl-Net-OAuth Critical Timing Attack Fix Vuln 2026-370bd8b5f0
Fedora 43 perl-XML-Bare Critical Denial of Service Fix CVE-2026-57074
Fedora 43 Emacs Important Local Shell Command Injection CVE-2026-79992
Fedora 43 nsd High Risk Access Control Bypass and DoS Patches 2026
Fedora 43 GitPython Denial of Service Advisory 2026-e6bd4d25ab
SUSE openssl-1_1-livepatches Important DoS Heap Overflow Patch 2026-4036-1
SUSE OpenSSL-1_1-Livepatches Important Heap Overflow Fix 2026-4037-1