Menu

Latest articles

DSA-6527-1 rsync – security update
Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
The public still doesn’t know who is abusing a critical Citrix vulnerability exploited as a zero-day weeks before disclosure, but we now know that the [...]
The devil is still in the email – but wearing a new mask
When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack
AI models keep posting screenshots showing sensitive data from inside tech companies
Amid the growing concern about AI models escaping security simulations to hack websites comes word that these “superintelligent” blobs of code [...]
Meta’s ex launches agent rival to Meta’s Muse
Manus’s relationship with Meta? It’s complicated. Just months after they called off their merger, they find themselves competing in the market for agentic [...]
OpenAI pulls the plug on GPT 6.1 Astra as agents keep crossing lines
OpenAI has scrapped the planned October release of GPT-6.1 Astra after internal testing found the model did not meet the company’s safety and alignment [...]
AMD agrees to buy World Labs to fill out its AI stack
Advanced Micro Devices (AMD) has agreed to buy World Labs, a developer of AI “world models” that incorporate knowledge of the physical world, to extend the [...]
Apple patches CoreGraphics zero-day already exploited in targeted attacks
Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen [...]
OpenAI benches GPT-6.1 Astra for overstepping the mark
OpenAI has killed off the planned release of GPT-6.1 Astra after the model got better at doggedly pursuing tasks but worse at knowing when it should stop. [...]
Phishing Exposure Nears 70% Across Key US Industries. What Should Security Teams Do?
Former X-Force hackers chase the offensive cyber gold rush
Two former leaders of IBM’s X-Force Red team have launched RemoteThreat, an offensive cybersecurity startup backed by $7 million in pre-seed funding. [...]
Teen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows
Why faster AI coding can mean harder engineering
We keep asking whether AI can make developers more productive, but that’s the wrong question. We should instead be asking what happens when it does. All [...]
What happens when the cloud blows up?
I’ve covered cloud computing for a long time, and one of the most persistent myths I encounter is that public clouds exist above the laws of physics that [...]
OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon
OpenAI has detailed the extent of the dirty deeds its agents indulged in Down Under in a Tuesday blog post titled How we will do better for Australia, [...]
Ubuntu 14.04 LTS curl Important Regression Security Issues USN-8487-2
Nvidia releases Open Agent Safety Platform to monitor and govern agentic AI
Nvidia on Monday rolled out an agentic governance system called the Open Agent Safety Platform that combines software with out-of-band DPU-based silicon in [...]
Fedora 44 VLC 3.0.24 Important Insights on Information Leak and Code Risks
Fedora 44 perl-Dancer2 Major Deserialization Vulnerability 2026-3b893ccf2d
Fedora 44 perl-Catalyst-Plugin-Static-Simple Security Alert 2026-2d96cf2594
Fedora 44 perl-HTML-FormFu Key Resource Exhaustion Patch 2026-18537daffc
Fedora 44 NetworkManager-iodine Fix for Privilege Escalation CVE-2026-91837
Fedora 44 NetworkManager-l2tp Critical CVE Fixes 2026-3a264a1bb3
Fedora 44 python-urllib3 High Severity TLS Memory Vulnerabilities Report
Security Update for Fedora 44 – Critical Issues in Python Streamlink
openSUSE erlang27 Key Denial of Service and Buffer Overflow Fix 2026-4358
openSUSE erlang27 Important DoS Buffer Overflow Vuln 2026-4358-1
SUSE hplip Critical Remote Execution Denial of Service Vuln 2026-4362-1
openSUSE libtpms Moderate Heap Overflow CVE-2026-85769 SUSE-2026-4363-1
SUSE libtpms Moderate Heap Overflow CVE-2026-85769 Advisory 2026-4363-1
openSUSE hplip Critical Remote Code Execution Fix 2026-4364-1
SUSE 2026 4364 1 hplip Critical Remote Code Exec Denial of Service
openSUSE 2026 4365-1 Python Soupsieve Moderate Denial of Service
SUSE python-soupsieve Moderate DoS Vulnerabilities Advisory 2026-4365-1
openSUSE libsodium Moderate CVEs 2025-15444 2025-69277 Advisory 2026-4368-1
SUSE libsodium Moderate Security Update CVE-2025-15444 2026-4368-1
SUSE Kernel Important Security Update for 133 Issues SUSE-2026-4369-1
Fedora 43 Chromium Important Security Flaws 2026-8729b61cd3
Fedora 43 perl-HTML-FormFu Denial of Service Fix Advisory 2026-219b6aef6c
Fedora 43 perl-Catalyst-Plugin-Static-Simple Key Cache Vulnerability 2026
Fedora 43 NetworkManager-iodine Security Advisory CVE-2026-91837
Fedora 43 NetworkManager-l2tp Critical CVE Fixes 2026-1b63888725
Fedora 43 FreeIPA Security Update CVE-2026-79678 CVE-2026-76578
SUSE Redis Important Out-Of-Bounds Issue Vuln 2026-4370-1
SUSE HPLIP Remote Code Execution Privilege Escalation Alert 2026-4371-1
SUSE Amazon-SSM-Agent Important DoS Issues Fix Advisory 2026-4372-1
SUSE 15 SP7 gnome-shell Moderate Out-of-Bounds Read CVE-2026-91786
SUSE exiv2 Important Heap Overflow Issues Advisory 2026-4374-1
SUSE Redis7 Significant Buffer Read Vulnerability CVE-2026-92925 Alert
SUSE ImageMagick Important Buffer Overflow and Memory Leak Fix 2026-4376-1
SUSE Redis7 Important Out-of-Bounds Exploit Advisory 2026-4377-1
SUSE 15 SP7 libheif Important Security Fix Advisory 2026-4378-1
Fedora 45 GRUB Security Fix for Serial Command FEDORA-2026-72dbe745c7
Fedora 45 FreeRDP Update Advisory for version 2026-ff8f6f4444
Fedora 45 perl-Dancer2 Critical Deserialization Exploit 2026-5e3eab9a07
Fedora 45 perl-Catalyst-Plugin-Static-Simple Security Info Leak Fix
Fedora 45 perl-HTML-FormFu Resource Exhaustion Fix 2026-94d32d2e8e
Fedora 45 NetworkManager-iodine CVE-2026-91837 Privilege Elevation Alert
Fedora 45 python-streamlink Faces High Severity TLS and Memory Issues
Fedora 45 python-urllib3 Urgent Advisory on TLS Memory Vulnerabilities 2026
Fedora 45 Python Quart Trio Memory Issues Vulnerability 2026-9a652403b1
DSA-6528-1 linux – security update
Linux eBPF Security Fixes Stop Interpreter Paths From Changing During Program Launch
Two Linux fixes show how extended Berkeley Packet Filter (eBPF) security can fail when mutable map data crosses into the exec path, where Linux starts a program.
Linux GPU Security Fix Prevents Stale Mappings Across Containers
A Linux GPU security fix changes how AMD’s Kernel Fusion Driver (KFD) tracks shared mappings when several containers use one device.
Slackware pcre2 Important Out-of-Bounds Write Fix Advisory 2026-271-02
Slackware groff Significant Command Injection Resolution 2026-271-01
runc 1.5.2 Shields Containers From a Linux cgroup v2 Memory-Corruption Bug
runc 1.5.2 adds a workaround for a Linux cgroup v2 memory-corruption bug that can make the privileged container runtime crash unpredictably.
Linux KVM Security Fixes Close Memory Isolation Gaps in Protected Virtual Machines
A new arm64 Kernel-based Virtual Machine (KVM) merge tightens two ordinary-looking mechanisms with major security weight: page mappings for [...]
Debian LTS lxml Significant Data Leak Privilege Escalation DLA-4799-1
Debian Libdbi-perl Medium Memory Corruption DoS CVE-2026-78030 DLA-4798-1
Exclusive: ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatum Ends
Managed Detection and Response for Manufacturing: How to Evaluate Providers
Manufacturing security tends to fail at the seam between information technology and operational technology. 
Debian rsync Important Local Escalation Info Disclosure Issues DSA-6527-1
DSA-6522-1 exim4 – security update
JadePuffer crims hijacked Azure identities and used them to blow up cloud resources
The cyber criminal behind JadePuffer, the first known agentic ransomware infection reported over the summer, has also used stolen Azure identities to [...]
Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe
OpenAI pauses AI model training after another agent bypasses network restrictions
OpenAI has paused training, evaluation, and inference involving tool use for its most-capable AI models after an agent bypassed network restrictions to [...]
Fake Email Thread Tricks AI Summarizer Without Hidden Text
Starfleet will fly Postgres AI apps from prototype to production, says pgEdge
The move from proof of concept or prototype to production is a common stumbling block for AI projects, and one that database services provider pgEdge is [...]
Starfleet will fly Postgres AI apps from prototype to production, says pgEdge
The move from proof of concept or prototype to production is a common stumbling block for AI projects, and one that database services provider pgEdge is [...]
Ex-soldier’s telecom hacking spree earns him 70 months
A former US Army soldier has been sentenced to 70 months in prison for hacking telecoms companies, stealing sensitive records, and trying to extort more [...]
Beyond Account-Level Risk: An Evidence-to-Action Pipeline for Detecting Fraud Rings
Tech Support Scam Kit Uses Google Ads to Deliver Fake Security Alerts
Rocky Linux 8 Firefox Important Security Update RLSA-2026-68549
Rocky Linux Firefox Important Security Fixes RLSA-2026-67133
Rocky Linux addresses significant Firefox security update RLSA-2026-67129
Mageia 10 Erlang Critical Denial of Service Issues CVE-2026-54886 2026-0457
Mageia Libreswan Security Update CVE-2026-14957 FIPS Mode Threat
Nine unlikely trends shaping software development
“It ain’t what you don’t know that gets you into trouble. It’s what you know for sure that just ain’t so.” Was Mark Twain thinking of software development [...]
AI ROI beyond pilots: Measuring outcomes in production
Generative AI pilots often look successful. Teams collect positive feedback, the tool sees steady usage, and the organization expects a fast path to scale. [...]
Certainties in life: Death, taxes, and critical Citrix vulns under attack
Death and taxes are said to be the only certainties in life. Perhaps it’s time to add attackers targeting newly discovered critical flaws in Citrix’s [...]
OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thought
The AI safety debate advanced at high speed over the weekend, amid new allegations that rogue agents have behaved more badly than first thought – and in [...]
Ubuntu Libwebsockets Update USN-8822-1 Critical SSH DoS Threats
Fedora 43 Nextcloud Denial of Service Fix FEDORA-2026-c495e95154
Fedora 44 Suricata Bugfix Security Update FEDORA-2026-5588cdf367
Fedora 44 Nextcloud 34.0.4 Denial of Service XSS Advisories 2026-362f1943c8
Fedora 45 dnf5 Translation Update Advisory FEDORA-2026-4284af73e4
Fedora 45 Nemo Update Security Advisory FEDORA-2026-c4d5a488fe
Fedora 45 Cinnamon Update Available – Version 2026-c4d5a488fe Released
Fedora 45 Advisory nemo-extensions Update 2026-c4d5a488fe