Menu

Latest articles

AI-assisted reconnaissance: Why everyone could be a viable target for fraud
It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.
US government snitch-finder pleads guilty to leaking state secrets to foreign spies
The former Defense Intelligence Agency (DIA) IT specialist previously accused of trying to pass secret and top-secret information to foreign spies has [...]
CISA: Most exploited vulnerabilities should have been eradicated decades ago
CISA is still crying out for software vendors to adopt Secure by Design (SBD) development practices, and says in its latest review that longstanding [...]
Streamlining container security: Red Hat Hardened Images now supported in AWS InspectorScan API and ECR Basic scanning
Software security teams can face an overwhelming influx of vulnerability alerts, often stemming from non-essential packages bundled inside traditional [...]
Preparing OpenStack for the post-quantum era: A systematic approach to crypto-agility
OpenStack powers clouds used by some of the most security-sensitive organizations on the planet: government agencies, telecommunications providers, [...]
Industry that built the problem offers to sell you the solution
OpenAI has gathered more than 100 of the world’s biggest tech and infosec companies to warn that cyber defense is in trouble – a reassuring [...]
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Why enterprise AI projects keep failing
Over the past three years, as an independent cloud and AI consultant, advisor, and industry influencer, I have worked with numerous companies seeking my [...]
Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood
Nothing smarts like a paper cut, but being attacked after leaving an application’s web interface exposed to the internet might be just as painful. Such [...]
Australian cops cuff alleged TeamPCP masterminds
The Australian city of Perth is by some measures the world’s most isolated major metropolis, but is still sufficiently connected to US law enforcement [...]
Fedora 43 rust-h2 Security Update Resolving RUSTSEC-2026-0258 Issue
SUSE Important Wicked Out-of-Bounds Issues CVE-2026-71401 CVE-2026-71402
openSUSE Wicked Important DHCP Out-of-Bounds Reads Vuln 2026-3839-1
SUSE important wicked Security Update CVE-2026-71401 CVE-2026-71402
openSUSE Wicked Important Indirect Shell Command Injection Fix 2026-3840-1
SUSE Wicked Important Indirect Remote Shell Injection Vuln 2026-3840-1
SUSE Wicked Important Security Update CVE-2026-71401 CVE-2026-71402
openSUSE Wicked Important Buffer Overflow Patch 2026-3842-1
SUSE 15.4 Important Wicked Security Issue CVE-2026-71401 CVE-2026-71402
openSUSE suseconnect-ng Moderate Security Fix Advisory 2026-3843-1
SUSE suseconnect-ng Moderate Security Update SUSE-SU-2026-3843-1
SUSE python36-pip Moderate URL Handling Arbitrary File Issue 2026-3846-1
openSUSE texlive Moderate Use-After-Free Vulnerability CVE-2026-63729
openSUSE Texlive Moderate Use-After-Free Vuln 2026-3847-1
Visual Studio Code 1.135 introduces Rubber Duck agent
Microsoft’s latest update to Visual Studio Code, released August 26, features a Rubber Duck agent for a second model opinion as well as UX improvements to [...]
Ubuntu 20.04 LTS Kernel Update Moderate WiFi Issue 2026-8666-3
Ubuntu 22.04 LTS Kernel Critical Network Flaw Update USN-8661-3
Ubuntu 20.04 Linux Kernel Azure CVM Security Update USN-8658-4
Ubuntu Linux Kernel Azure Critical Flaws Fixed USN-8644-3
Ubuntu 24.04 LTS 8643-5 Important Security Update for Linux Kernel
CRPx0 hacking service for dummies claims victim count more than quintupled
CRPx0, a cybercrime crew that has rapidly evolved from a scam service to a ClickFix-delivered ransomware and crypto-theft business over the summer, claims [...]
Ubuntu 24.04 LTS PAM Bypass Vulnerability Announcement USN-8688-1
Debian LTS Chromium Important Code Exec DoS Info Disclosure DLA-4758-1
Linux Patching Best Practices: Designing a Patch Validation Workflow
Patch work often gets declared finished at the package manager. The update installs, version inventory changes, the service restarts, and the ticket begins [...]
openSUSE librest Moderate PKCE OAuth Vulnerability 2026-3834-1
SUSE librest0_7 Moderate PKCE Crypto Issue Vuln 2026-3834-1
SUSE OpenSSL Important Security Fixes Advisory 2026-3835-1
Go 1.27 brings support for generic methods
Google’s Go programming language has been updated with changes across the language, toolchain, runtime, and standard library. Released August 19, Go 1.27 [...]
Mageia 10 python-django Important DoS Cross-Site Scripting Vuln 2026-0339
Mageia Avahi Important Security Flaws CVE-2025-59529 CVE-2026-24401
Mageia yt-dlp Bugfix Security Upgrade Released in January 2026
Mageia 10 fs-uae Security Patch Problem Report 2026-0113 Update
Mageia 10 Guayadeque Security Update 2026-0112 with Bug Fixes
Mageia 10 Mnemosyne Patch Update Released for January 11 2026
Mageia opencpn Bugfix Security Advisory 2026-0110 Core Dump Issue
Mageia 10 Viking Security Advisory 2026-0109 Segmentation Fault Fix
Mageia 10 Advisory 2026-0108 serd Security Update on Rebuilt Packages
Mageia 10 opencpn-o-charts-plugin Bugfix Advisory 2026-0107
Mageia 10 Advisory php8.5-gmagick Module Conflict Fix 2026-0106
AI girlfriend review site’s secrets were exposed to the world for three weeks
PWNED Welcome back to PWNED, the weekly column where we explore the frightening and amusing world of foolish infosec errors. This week, it’s all [...]
Debian Chromium Important Code Exec Denial of Service Vuln DSA-6476-1
Omarchy distro gains serious backing
The controversial Omarchy distro is attracting both criticism and fans – and financial support, too. Omarchy is an opinionated respin of Arch Linux and a [...]
Rocky Linux 10 golang Important Denial of Service Fix RLSA-2026-60306
Rocky Linux AssertJ-Core Moderate Info Disclosure DoS Issue RLSA-2026-60215
Rocky Linux 9 Golang Important DoS XSS Issues RLSA-2026-60304
Rocky Linux 9 Kernel Important Security Bug Fix Update RLSA-2026-59723
Rocky Linux 9 Moderate Symlink Traversal Escalation Fix RLSA-2026-60226
Rocky Linux 8 kernel-rt Important Security Fixes RLSA-2026-59737
openSUSE Leap 16.0 gh Important Issues Patch 2026-21663-1
openSUSE Leap 16.0 rsync Important Security Issues Resolved 2026-21650-1
Ubuntu 24.04 openCryptoki Important Access Issues USN-8686-1
openSUSE rmt-server Important Denial of Service Issues 2026-21640-1
openSUSE Leap 16.0 Advisory 2026-21639-1 dracut Important Root Code Exec
ATF responds to ‘major’ cybersecurity incident after ransomware gang’s claims
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) said it’s responding to a “major” cybersecurity incident shortly after the Qilin ransomware [...]
Schrödinger’s backup: not actually recovered until you try to restore IT
Schrödinger’s Cat, the famous 1935 thought experiment, imagines a cat that, for reasons rooted in quantum physics we need not dwell on here, is [...]
Linux Kernel Vulnerability News: Linux Security Roundup
Linux kernel vulnerability news dominated the security updates published from August 20 through August 27. Ubuntu, Debian, Fedora, Mageia, Oracle Linux, [...]
Ubuntu Kernel Security Vulnerabilities Resolved in Releases 16.04 to 24.04
Cybercrooks jet off with Manchester Airports Group customer data
The company behind three of the UK’s busiest airports says “a quantity” of data was stolen by an extortion group during a recent “cybersecurity [...]
AppArmor Credential Fix Prevents In-Hook Use-After-Free Risk
A Linux security hook should be able to check a task without invalidating the identity data that surrounding kernel code is still using. AppArmor broke [...]
SUSE Evince Moderate Heap Use-After-Free Vulnerability SUSE-2026-3831-1
SUSE python310-pip Moderate Arbitrary File Write Vuln 2026-3832-1
NFS Client Cleanup Fix Removes Orphaned rpc_pipefs Files
Linus Torvalds merged a Linux NFS client update on Aug 26, 2026, that includes a fix for rpc_pipefs files left attached to an RPC client after the client [...]
Nvidia eyes $12.9 bn Hugging Face deal to expand AI platform control
Nvidia is moving to acquire AI platform Hugging Face in a deal valued at about $12.9 billion, a move that would extend its reach beyond chips into how AI [...]
AWS acquires DuckLabs, but what does it want from the team behind DuckDB?
Open-source software has given cloud providers a way to adopt popular technologies without having to own the companies behind them. AWS, however, has [...]
Nuisance-call blocker fined £190k for being a nuisance caller
The UK’s data protection watchdog has fined a nuisance call blocking biz £190,000 ($258,000) for bombarding elderly people with hundreds of thousands of [...]
Debian Trixie libdbi-perl Important Code Execution and DoS DSA-6473-1
US Navy tells sailors and their families: scrub your social media, enemies are watching
Debian trixie bubblewrap Critical Symlink Traverse Issue DSA-6472-1
How to implement HMAC authentication in ASP.NET Core
Security is a major concern for web applications and services that use the HTTP protocol. Although HTTP is a versatile protocol that can be used in many [...]
Why digital twins need memory as much as AI agents
Digital twins began as virtual counterparts to physical systems. In aerospace, manufacturing, and other high-stakes environments, they gave engineers a [...]
AI coding agents vs. big balls of mud
Big balls of mud are inevitable, right? I’ve written about where these sprawling, difficult-to-maintain codebases come from and how you might deal with [...]
Debian Wireshark Important Denial Of Service Arbitrary Code DSA-6471-1
Debian GIMP Important Denial of Service or Code Execution DSA-6470-1
IPMI Security Patch Restores a Lost Linux RCU Grace Period
The Linux IPMI maintainer accepted a patch on Aug 26, 2026 that restores an RCU grace period before command-receiver objects are freed. The one-line change [...]
Debian xrdp Advisory DSA-6469-1 Multiple Threats CVE-2026-32105
Linux Uevent Leak Exposes Freed Memory in Synaptics RMI4
A Linux uevent can carry bytes from freed kernel memory when one object survives longer than the allocation behind its name. A new Synaptics RMI4 patch [...]
Rocky Linux 10 Ruby Important Bug Fixes Buffer Overflow RLSA-2026-50778
Rocky Linux 10 ruby4.0 Important Buffer Overflow Advisory RLSA-2026-50773
Rocky Linux 9 Ruby Important RLSA-2026-50827 Security Updates
Rocky Linux Ruby 3.3 Important Security Updates RLSA-2026-50828
Rocky Linux Ruby Important Buffer Overflow Advisory RLSA-2026-50728
Fedora 43 Rust-Cargo-Util-Schemas Advisory – Critical Information Leak
Fedora 43 rust-cargo-util-terminal Info Disclosure Advisory 2026-ce685f40fe
Fedora 43 Rust-Rustfix Information Disclosure CVE-2026-5222 Advisory
Fedora 43 rust-cargo-c Information Disclosure Advisory 2026-ce685f40fe
Fedora 43 Important Info Disclosure in Rust-Crates-IO CVE-2026-5222
Fedora 43 rust-cargo-util Information Disclosure Vuln 2026-ce685f40fe
Fedora 43 rust-cargo Information Disclosure CVE-2026-5222 2026-ce685f40fe
Fedora 43 rust-cargo-credential-libsecret Important Info Disclosure
Fedora 43 rust-anstyle-progress Information Disclosure CVE-2026-5222 Alert