Menu

Latest articles

IBM’s agentic AI platform is under active attack – patch now
A critical vulnerability in IBM-owned, low-code AI builder Langflow lets unauthenticated attackers execute code remotely on vulnerable default deployments, [...]
AWS updates DynamoDB with native vector search to ease AI application development
AWS is finally adding native vector search to its managed NoSQL database DynamoDB, which is typically used to store high-volume operational and [...]
London cops handed victim’s new address and number to her stalker, watchdog says
UPDATED The UK’s data protection regulator has criticized London’s Metropolitan Police Service (MPS) after its officers handed a victim’s [...]
UK charities count the cost of Beacon CRM cyberattack
Beacon CRM has confirmed it was hit by a cyberattack that exposed data belonging to a growing list of UK charities. The company, which markets its software [...]
Debian DLA-4717-1 Linux Priv Escalation DoS Info Leak Severity Critical
Five ways to evaluate AI agent orchestration platforms
AI agent orchestration platforms coordinate role-based and task-based AI agents, along with the tools, data, and people they depend on, into multistep [...]
A trip down shareware lane
I hope you’ll indulge me this week as I take a break from my usual rantings about agentic coding and meander down memory lane. I learned to code BASIC in [...]
Rocky Linux Kernel Moderate RXSA-2026-49857 CVE-2026-52923 Security Update
Debian botan3 Important Denial of Service Bypass Issues DSA-6412-1
Debian aom Critical Denial of Service CVE-2026-56208 DSA-6411-1
Ruby on Rails critical bug puts every image upload under scrutiny
A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066, could turn a seemingly innocuous image into a front [...]
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project
The UK’s AI Security Institute has observed AI models performing what it calls “unsanctioned action” 19 times during security tests. The Institute (AISI) [...]
Fedora 43 open62541 Denial of Service Updates 2026-1435f05fde
Fedora 43 doctl Security Update Denial of Service Vuln 2026-a36bdff8d7
Fedora 44 Kernel Important Fix Security Advisory 2026-864f36550e
Fedora 44 Perl Update Addresses Critical Buffer Overflow Vulnerabilities
Fedora perl-Devel-Cover Important Heap Overflow Info CVE-2026-8376
Fedora 44 perl-PAR-Packer Critical Buffer Overflow and Disclosure Fix
Fedora 44 Perl Critical Heap Buffer Overflow Information Leak Advisory
Fedora 44 abrt Vulnerability in Content Injection and Race Condition
Fedora 44 Coreutils Denial of Service CVE-2026-56391 Advisory
Fedora 44 open62541 v1.5.6 Denial of Service Advisory ID 2026-23b21104ef
Fedora 44 doctl Update Denial of Service Vulnerabilities 2026-7ca1b24b3c
Slackware 15.0 stunnel Critical Memory Access Issues Fix SSA-2026-216-01
DSA-6412-1 botan3 – security update
DSA-6411-1 aom – security update
SnapLogic introduces agentic assistant for data integration
SnapLogic has introduced its new SnapGPT, an agentic assistant that helps enterprise teams plan, build, understand, and operate integrations through [...]
Rocky Linux Kernel Low Denial of Service Issue RXSA-2026-49870
SUSE 15-SP7 rsyslog Important Buffer Overflow Vuln 2026-3478-1
SUSE Kubevirt Important Addressing Four Issues 2026-3480-1
SUSE netty Important Resource Exhaustion Security Update 2026-3482-1
openSUSE Valkey Important Remote Code Execution Threat 2026-3483-1
SUSE Linux 15 SP6 Important RCE TLS Issues Fix Vuln 2026-3483-1
SUSE bind Important DNS Cache Poisoning Fix Advisory 2026-3484-1
openSUSE spice-vdagent Important Buffer Overflow Threats 2026-3485-1
SUSE spice-vdagent Important Heap Buffer Overflow Fix Advisory 2026-3485-1
openSUSE openssl-3 Moderate DoS Risk Advisory 2026-3486-1
SUSE openssl-3 Moderate DoS Security Update 2026-3486-1
SUSE openssl-1_1 Important DoS Threat Advisory SUSE-SU-2026-3487-1
SUSE OpenSSL Important DoS Threat Fix SUSE-SU-2026-3488-1
SUSE openSUSE Leap 15.5 Advisory ID 2026-3489-1 Moderate kpartx Update
SUSE wpa_supplicant Low RADIUS Issue Advisory 2026-3490-1
openSUSE libgcrypt Moderate Buffer Overflow Denial of Service 2026-3491-1
SUSE Alsa Moderate Double-Free Memory Corruption Vuln 2026-3492-1
openSUSE perl-HTTP-Tiny Important Cross-Origin Redirect Fix 2026-0274-1
openSUSE Thrift Important Security Fix 2026-0275-1 CVE-2026-41602
openSUSE perl-YAML-Syck Important Mem Safety Crash Fixes 2026-0273-1
Mageia PHP Security Update CVE-2026-7260 CVE-2026-17543
Mageia acl attr Critical Buffer Overflow Vuln 2026-0321
Bypassing AI guardrails is so easy a script kiddie can do it
If you want to bypass AI guardrails designed to stop models from assisting with cyberattacks, you often just have to ask the right way, according to [...]
AWS’s Kiro Crew aims to turn AI coding agents into autonomous engineering teams
AWS on Tuesday released Kiro Crew, an open-source orchestration platform designed to help enterprises move beyond interactive AI coding assistants toward [...]
Oracle Linux 10 Thunderbird Major Update ELSA-2026-49621
Oracle Linux 10 nodejs22 Important Multiple Issues ELSA-2026-48033
Oracle Linux 10 ELSA-2026-48032 Nodejs Nodemon Important Security Update
Oracle Firefox Important Vulnerabilities Advisory ELSA-2026-47101
Oracle Linux 10 Node.js Important Bug Fix Advisory ELSA-2026-35842
Oracle Linux 10 Kernel Significant Security Patch ELSA-2026-23329
Oracle Linux 8 perl-Archive-Tar Important DoS Fix ELSA-2026-49524
Oracle Linux 8 FRR Important Packet Parsing Fix ELSA-2026-49511
Oracle 8 PHP Low Memory Corruption Vuln ELSA-2026-47750
Oracle Linux 8 PHP 8.2 Low Bug Fix Advisory ELSA-2026-47749
Oracle Linux 8 ELSA-2026-46396 Libreswan Important Fixes
Oracle Linux 8 Kernel Important Threat Fixes ELSA-2026-500121
Oracle Linux 7 Rsync Important CVE-2026-41035 Advisory ELSA-2026-25172
This one time, at Hacker Summer Camp …
As the entire security industry descends on Las Vegas this week for Hacker Summer Camp – not one, but three conferences – attendees can count on two hot [...]
Feds get 3 days to patch N-able God mode flaw under active exploit
The US Cybersecurity and Infrastructure Security Agency (CISA) has added an exploited N-able vulnerability to its Known Exploited Vulnerabilities (KEV) [...]
AI helps Microsoft bug hunters chase a record $20M payday
Microsoft announced this week that between July 1, 2025, and June 30, 2026, the company had paid more than $20 million in bug bounties to 562 researchers. [...]
AI Is Already Performing Linux Security Work. What Happens When It Escapes Containment?
Nearly everyone following technology has heard about the recent security incidents involving OpenAI and Anthropic. The headlines focused on the containment [...]
OpenStack IPA Flaws Highlight a Hidden Bare-Metal Security Risk
OpenStack disclosed a flaw in its bare-metal management tool, the Ironic Python Agent (IPA), showing that it could accidentally fall back to local network [...]
Tennessee congressional hopeful accused of shooting license plate cameras
An independent congressional candidate in Tennessee faces four felony vandalism charges after allegedly shooting four automated license plate reader (ALPR) [...]
Google ADK flaws reveal what happens when AI agents trust the wrong message
Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger [...]
CAF Bank reopens online service but warns of further outages
CAF Bank has told customers its online banking service is back after being shuttered for more than ten days following what it described as “attempted [...]
Fake IRS letters target cryptocurrency holders
When you should use AI, and when you shouldn’t
Most folks seem happy to let AI write their LinkedIn posts for them. Others, myself included, have AI draft their work memos or slide decks. And some, [...]
When the cloud control plane fails
Not long ago, I worked with an enterprise that believed it had done everything right. The company had spread workloads across multiple regions, replicated [...]
Debian LTS ruby2.7 Important DNS Buffer Overflow Threat DLA-4716-1
Cloudflare has mostly ditched third party security tools, suggests not trying that at home
Cloudflare has used AI to automate processing of incoming reports to its bug bounty program for $58 a month using Anthropic’s Claude Sonnet model and chose [...]
Fedora 43 BorgBackup CVE-2026-62268 Bugfix Update 2026-5a13ef79cc
GitHub pushes stacked pull requests into public preview
Advancing on software development, GitHub has announced the public preview of stacked pull requests. The public preview was announced July 30. Stacked pull [...]
Fedora 44 python-nh3 Update Advisory RUSTSEC-2026-0193 RUSTSEC-2026-0213
Fedora 44 rust-ammonia Update RUSTSEC-2026-0193 RUSTSEC-2026-0213
Fedora 44 Nebula 1.11.0 Patch Fixing Security Issues December 2026
SUSE perl-DBI Important SQL Handling Issues Vuln 2026-3461-1
openSUSE Leap 15.4 Xen Important Buffer Overflow Vuln 2026-3462-1
SUSE 2026-3462-1 Critical Xen Buffer Overflow Security Update
openSUSE libssh Moderate Denial of Service and Integrity Issues 2026-3463-1
SUSE libssh Moderate Denial of Service and Info Disclosure Vuln 2026-3463-1
Oracle Linux 10 p11-kit Moderate Security Issue ELSA-2026-49668
Oracle Linux 10 ELSA-2026-49523 perl-Archive-Tar Important Memory DoS Fix
Oracle 10 perl-DBI Important Threat Fix Advisory ELSA-2026-49514
Oracle Linux 10 gstreamer1-plugins-good Critical Integer Overflow Issue
Oracle Linux 10 php Low Advisory ELSA-2026-48170 CVE-2026-14355
Oracle9 perl-DBI Important Security Advisory ELSA-2026-49612
Oracle Linux 9 ELSA-2026-49527 frr Important Input Validation Fix
Oracle Linux 9 perl-Archive-Tar Vital Memory Management DoS ELSA-2026-49525
Oracle Linux 9 Libreswan Important Vulnerability Advisory ELSA-2026-46397
Oracle Linux 8 Nodejs Important Security Advisory ELSA-2026-47060
Oracle Linux Node.js Important Security Update ELSA-2026-47059
Oracle Linux 8 pki-deps Important Security Update ELSA-2026-43218
Oracle Linux 8 javapackages-tools Important Update Advisory ELSA-2026-41948