Menu

Latest articles

This month in security with Tony Anscombe – August 2026 edition
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month’s cybersecurity news
Apache Fory serialization framework adds JSON support for Kotlin and Scala
The Apache Fory community has announced the release of Fory 1.7.0, an update of the multi-language serialization framework that adds Fory JSON support for [...]
OpenClaw rolls out system-wide overhaul, updates security controls across agent platform
OpenClaw has released what it describes as the largest update in its history, introducing a system-wide overhaul spanning runtime behavior, plugins, and [...]
33-hour BGP hijack of Softaculous traffic prompts security scramble
Softaculous and Virtualizor customers are being urged to reset credentials and inspect their servers after a 33-hour BGP hijacking incident diverted [...]
Why tech needs a new kind of English major
I saw Spider-Man: Brand New Day last week. I struggled to enjoy it. I guess I hit CGI overload, although its 89% score on Rotten Tomatoes suggests others [...]
A look at AWS’s agentic toolkit for cloud migration
Amazon Bedrock AgentCore is an AWS technology that deserves a closer look because it is not simply another migration automation tool. It is an agentic AI [...]
4 standards solve agent identity. None solves the harder question: Is it still the agent you approved?
I’ve stopped being surprised by the service account nobody can explain. It was created for a migration that finished years ago. It still holds credentials. [...]
Moburst Targets Fortune 500 Brands as AEO Partner
Moburst, a digital growth agency, is positioning its Answer Engine Optimization practice specifically at enterprise and Fortune 500 brands, arguing that [...]
Compose Multiplatform 1.12.0 welcomes coding agents with MCP server
JetBrains has released Compose Multiplatform 1.12.0, an update to the declarative framework for sharing Kotlin UI code across platforms. Highlights of the [...]
openSUSE Unbound Important DoS Threat Resolution 2026-3885-1
openSUSE yast2-samba-client Important Command Injection Issue 2026-3887-1
openSUSE Yast2-Samba-Client Important Command Injection Fix 2026-3888-1
openSUSE yast2-samba-client Important Command Injection Vuln 2026-3889-1
openSUSE 15.4 yast2-auth-client Key OS Command Injection Patch 2026-3894-1
openSUSE 2026 yast2-auth-client Important OS Command Injection Fix
Broadcom says that enterprise AI agents need two things: Data they can trust and boundaries they can’t cross
For enterprises deploying AI agents, security and trust are top-of-mind issues. When given the authority to act autonomously, they can inadvertently leak [...]
openSUSE Python-httplib2 Important Memory Overflow Vuln 2026-3898-1
openSUSE yast2-auth-client Important OS Command Injection Fix 2026-3901-1
Ubuntu OpenZFS Important Authorization Bypass Risk USN-8705-2
Healthcare cyberattacks hit pacemakers and millions of patient records
Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global [...]
Rocky Linux 9 nodejs Important Memory & Access Issues RLSA-2026-61383
Rocky Linux Node.js Significant Memory Exhaustion Risk – RLSA-2026-61386
Debian LTS Expat Security Update DLA-4765-1 for Various CVEs
Debian 11 to 12 libdbd-csv-perl Regression Fix Update DLA-4764-2
SUSE OpenSSL Vital Security Update Addressing Multiple Vulnerabilities
SUSE OpenSSL Important Memory Abuse Heap Overflow Advisory 2026-3877-1
SUSE openssl-1_1 Important Memory Issue Buffer Overflow Vuln 2026-3878-1
SUSE vim Important Arbitrary Code Exec Denial of Service Vuln 2026-23346-1
SUSE SSSD Moderate Out-of-Bounds Memory Issues Vuln 2026-23347-1
SUSE Unbound Important DoS Vulnerabilities Fix Advisory 2026-23349-1
SUSE Curl Moderate Password Leak and Auth Issues Vuln 2026-23350-1
SUSE Micro 6.1 Advisory 2026-23351-1 Highlights CVE-2026-3886 Risk
SUSE Linux Micro 6.1 cpio Moderate Archive Issues Vuln 2026-23355-1
SUSE gzip Moderate Buffer Overflow Vulnerability 2026-23356-1
SUSE openssl-3-livepatches Important DoS Vulnerability Fix 2026-23358-1
SUSE Unbound Important DoS Issues Fixed in Advisory 2026-23360-1
SUSE Curl Moderate Password Leak SMB Connection Flaw SUSE-SU-2026-23361-1
SUSE 2026-23362-1 QEMU Important Local Escalation Fix CVE-2026-3886
SUSE gzip Moderate Buffer Overflow Fix Vulnerability 2026-23363-1
SUSE c-ares Important Remote Access Denial of Service Update 2026-23364-1
SUSE 2026 23365 1 Major Security Update Released For Vim Software
eBPF Security Research Misses eBPF’s Own Attack Surface
An eBPF security system can produce precise Linux telemetry while leaving a harder question unanswered: what happens if the eBPF layer itself is [...]
Linux CPU Hotplug Exposes Regmap IRQ Use-After-Free Path
Linux interrupt maintainer Thomas Gleixner traced a Kernel Address Sanitizer report to incomplete regmap IRQ cleanup on Aug 30, 2026. The crash appeared [...]
Linux GPU Security Issue: DRM Patch Addresses Cross-Driver Fence UAF Reads
Jonghyuk Kim submitted a Linux Direct Rendering Manager scheduler patch series on Aug 28, 2026 that targets a use-after-free read shared by several GPU [...]
OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
OpenClaw has unveiled what its makers call its largest ever update – large enough to earn a 2.0 moniker – with usability taking center stage, along with [...]
Attack hides malware in PNGs and drops custom reverse tunnel on victims’ machines
An unknown miscreant is using “TerminalFix” to trick unsuspecting users into running PowerShell commands that infect their computers with a [...]
SUSE Go1.25 Important Denial Of Service Advisor SUSE-SU-2026-23300-1
SUSE Security Update for go1.26 Addresses Critical Denial of Service Issues
SUSE Python313 Notable Command Injection and DoS Flaws 2026-23303-1
SUSE MozillaFirefox Moderate Security Update Advisory 2026-23304-1
SUSE Qt6-SVG Vital Update Handling Use-After-Free CVE-2025-10729
SUSE gstreamer-plugins-bad Moderate Parser Desync CVE-2026-52718
SUSE libarchive Fixes Moderate Memory Leak and Buffer Overflow Issue
SUSE xmlrpc-c Moderate XSS Vulnerability Fix Advisory 2026-23311-1
SUSE ImageMagick Moderate Buffer Overwrite and Memory Leak Fix 2026-23312-1
SUSE liboqs Moderate Security Fix for Multiple Issues 2026-23313-1
SUSE Linux 16.0 dracut Important Remote Code Execution Fix 2026-23314-1
SUSE 2026-23316-1 PCP Moderate Command Injection Privilege Escalation
SUSE 7zip Important Heap Overflow Remote Code Execution Vuln 2026-23317-1
SUSE python-pip Moderate Improper URL Handling Vuln 2026-23319-1
SUSE libheif Moderate Integer Underflow and Out-of-Bounds 2026-23320-1
SUSE rmt-server Important Denial of Service Issues Fixed 2026-23321-1
SUSE rsync Important Security Update for 41 Vulnerabilities 2026-23323-1
SUSE Linux Enterprise Server wget Security Issues Resolved in 2026-23326-1
SUSE snphost Important OpenSSL Issues Fix Advisory 2026-23327-1
SUSE Linux Enterprise 16.0 Kernel Important Security Update 2026-23328-1
Anthropic cracks down on hijacked user accounts mining AI tokens
Rather than paying for their own Claude usage, crims are using malware to steal access to other people’s accounts. Aware of this issue, Anthropic has [...]
Cursor customers will lose access to OpenAI coding models in November
OpenAI will stop AI coding platform Cursor from accessing its models from November 12, following the acquisition of Cursor parent Anysphere by Elon Musk‘s [...]
Mageia 10 Golang Critical Security Issues Advisory 2026-0341 CVE-2026-56865
Debian Trixie Linux Kernel Security Fix DSA-6477-1 for Privilege Escalation
Debian LTS Roundcube Important XSS Remote Code Exec Vuln DLA-4760-1
Governance by design: Turning AI policy into executable controls
Governance determines whether a generative AI program remains a set of pilots or becomes a durable capability. I treat governance as engineering work. The [...]
Hands-on with Unsloth Desktop, for running and training LLMs locally
LM Studio makes it easy to run LLMs on one’s own hardware, whether as a desktop app or a server for others in one’s organization. But LM Studio isn’t the [...]
DSA-6477-1 linux – security update
Debian Roundcube Important Info Disclosure XSS Denial of Service DSA-6479-1
Debian Starlette DSA-6478-1 Security Fixes for Denial of Service and Bypass
Debian LTS DLA-4761-1 libnet-dns-perl Critical DoS CVE-2026-64194
openSUSE mozjs102 Moderate Denial of Service NULL Pointer Vulnerabilities
openSUSE – Moderate Memory Weakness in python-PyPDF2 Resource Exhaustion
openSUSE Trivy Moderate Vulnerability Fix Advisory CVE-2026-72815-72817
openSUSE libopenssl-3-devel Important Security Fix 2026-11623-1
openSUSE java-25-openjdk Important Security Issues Advisory 2026-11621-1
openSUSE Tumbleweed Grafana Important Security Update 2026-11619-1
openSUSE coturn Moderate Security Update Vuln 2026-11617-1
openSUSE gh Important Fixes for Multiple Security Issues 2026-0309-1
openSUSE Tor Significant Security Update 2026-0306-1 Released Now
openSUSE v2ray-core Important Security Update Buffer Overflow 2026-0307-1
openSUSE Pyenv Moderate File Handling Vulnerability CVE-2026-68939 Advisory
openSUSE Git-lfs Important Update for Multiple Security Issues 2026-0305-1
Linux Kernel 7.1-rc5 Tracing Reader Use-After-Free Bug Discovery
Removing a Linux trace instance should end its lifetime. An open tracefs reader can currently keep using that instance after another task removes it, [...]
eBPF Security Research Adds State-Aware Syscall Filtering
A Linux service may need broad system-call access while it starts, then only a smaller set while it handles requests. A single policy loaded before startup [...]
KubeCap Finds Excess Linux Capabilities in Kubernetes Workloads
A Kubernetes workload can run with more Linux capabilities than its code needs. When capability settings are missing or broad, that excess authority may [...]
SUSE python36 Important Security Update Vuln 2026-3855-1
openSUSE rsyslog Important Heap Buffer Overflow Vuln 2026-3859-1
SUSE Rsyslog Important Heap Overflow Fix Advisory SUSE-2026-3860-1
SUSE Rsyslog Important Buffer Overflow Fix SUSE-SU-2026-3861-1
SUSE Python Security Update Addresses DoS Vulnerabilities and More Issues
SUSE 2026-3863-1 Significant Apptainer Filesystem Vulnerability Found
SUSE Kernel Important Update for Live Patch 15 with 6 Security Fixes
SUSE Kernel Live Patch 13 Important Security Update SUSE-SU-2026-23280-1