Menu

Latest articles

What we lose when every engineer can do everything
Four months ago, a front-end engineer on my team looking to make upgrades to a product or feature would have filed a ticket and waited for the [...]
Ransomware attacks spike as world distracted by AI
Ransomware attacks jumped nearly 20 percent in July, with UK firm Comparitech counting 799 incidents, up from 668 in June. Of those, 51 had been confirmed [...]
N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
N-able has confirmed attackers exploiting an N-central zero-day made it into customer networks, as the vendor pushes out a second mandatory hotfix just [...]
Moonshot’s Kimi AI model has also escaped from a test environment
Yet another AI model has escaped from a cybersecurity test lab: This time, it’s the Chinese company Moonshot’s Kimi K3 model on the run. Frontier Security [...]
Airtable joins Evernote, Brightcove, WeTransfer and AOL in Bending Spoons portfolio
Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo Airtable [...]
MIT boffins’ TONTOU attack slips through Spectre defenses on Intel and AMD CPUs
Two MIT researchers will present a new speculative execution attack at DEF CON 34 that uses precisely timed interrupts to bypass defenses against Spectre [...]
Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder
A Scottish NHS trust is investigating a data breach concerning the medical records of a nine-year-old girl who died earlier this week and was named [...]
Snowflake attacker pleads guilty to hack of 165 companies’ data
A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a [...]
DeepMind founder ascends to singular AI role at Google
Demis Hassabis, the driving force behind Google DeepMind, is ascending to the role of chief scientist at Alphabet, Google’s parent company, replacing Jeff [...]
Attacker phished way into US defense supplier’s Microsoft 365 account
US defense and aerospace supplier IEH Corporation ‘fessed up that a criminal managed to break into its Microsoft 365 mailbox in a filing with [...]
Rocky Linux Thunderbird Important Security Update RLSA-2026-49922
Rocky Linux Thunderbird Important Security Update RLSA-2026-49921
Rocky Linux Thunderbird Major Security Update RLSA-2026-49621
‘Asimov was right’ about rules for robots, says ex-US Cyber Director
EXCLUSIVE Don’t waste time worrying about AI models achieving sentience – they’re essentially already there, according to former US National [...]
Three concepts cloud architects overlook
After two decades of cloud architecture consulting, I see an unchanging pattern in enterprise deployments. Organizations approach me with unexpectedly high [...]
Debian bullseye linux-6.1 Security Update DLA-4723-1 Multiple Threats
Mageia Thunderbird Important Security Updates 2026-0326 CVE-2026-14899
Mageia 10 9 Rootcerts Security Update Vuln MGASA-2026-0325
Mageia Python-Django Medium Exposure Issues Vuln 2026-0324
Oracle Linux Kernel Important Update CVE-2026-64531 ELSA-2026-500135
Oracle Linux 10 ELSA-2026-51075 GPSD Important Command Injection Fix
Oracle Linux has released an update for version 10, addressing CVE-2026-58459, which fixes a command injection vulnerability in gpsprof and includes [...]
Oracle Linux 9 Kernel Important Vulnerability Fixes ELSA-2026-500135
Oracle Linux 9 Kernel Security Update ELSA-2026-500137 CVE-2026-64531
Oracle Linux 8 Kernel Important Update ELSA-2026-500137 CVE-2026-64531
Oracle Linux 8 Kernel Important Remote Access Flaws ELSA-2026-500136
Oracle7 Kernel Important Security Advisory ELSA-2026-500136 CVE-2026-68480
China launches mysterious probe into security of Palo Alto Networks’ products
China’s Cyberspace Administration (CAC) has conducted a review of Palo Alto Networks’ products. The regulator’s announcement of its review says it’s needed [...]
Rocky Linux microcode_ctl Significant Bug Resolution Update RLEA-2023-7117
Slackware p11-kit Overflow Fix SSA-2026-218-02 CVE-2026-18938
Slackware libXfont2 Important Buffer Overflow Encoding Fix 2026-218-01
Debian jq Security Advisory DoS and Arbitrary Code Execution DSA-6416-1
Fedora 43 FreeIPA Security Fixes Multiple CVEs 2026-8e7fa96cf3
Fedora 43 Samba 4.23.10 Critical Dos Buffer Overflow Fix 2026-8e7fa96cf3
Fedora 43 libXfont2 Important CVE Patch 2026-4f471dd34a
Fedora 43 curl Critical Auth Leak Fixes & Vulnerabilities 2026-097fb2e7e9
Fedora 43 abrt Critical Fix Content Injection Issue 2026-cccf5985b5
Fedora 43 Coreutils Denial of Service Risk CVE-2026-56391
Fedora 43 PHP Update Critical Out-of-Bounds Execution Fix 2026-d755ca77c4
Fedora 44 python-gstreamer1 Update Advisory 2026-d51eee8d48
Fedora 44 gstreamer1-plugins-good Security Advisory 2026-d51eee8d48
Fedora gstreamer1-plugins-bad-free Version 1.28.6 Report 2026-d51eee8d48
Fedora 44 gstreamer1-rtsp-server Patch Alert 2026-d51eee8d48
Fedora 44 GStreamer 1.28.6 Update Advisory 2026-d51eee8d48
Fedora 44 gstreamer1-plugins-base Update 1.28.6 Advisory 2026-d51eee8d48
Fedora 44 gst-editing-services Update Advisory 2026-d51eee8d48
Fedora 44 gst-devtools Update 1.28.6 FEDORA-2026-d51eee8d48
Fedora 44 GStreamer 1.28.6 Update Security Advisory 2026-d51eee8d48
Fedora 44 GStreamer Documentation Revision 2026-d51eee8d48
Fedora 44 gstreamer1-plugin-libav Update Advisory 2026-d51eee8d48
How the famed USENIX Security conf is managing a flood of papers in the AI era
The 35th USENIX Security Symposium (USS), which takes place next week in Baltimore, Maryland, hit an all-time high for paper submissions. While some of [...]
Microsoft releases open-source agent that generates unit tests
Microsoft has released code-testing-generator, an open-source agent for generating unit tests in any programming language, according to the company. [...]
Debian LTS Redis Remote Code Exec Vuln DLA-4722-1 CVE-2026-66373
Rocky Linux Kernel 5.14.0 Moderate Security Update RXSA-2026-51035
Rocky Linux 8 Kernel Important Fix Privilege Escalation RXSA-2026-50978
openSUSE Important openssl DoS Vulnerability Fix SUSE-SU-2026-3515-1
SUSE openssl-3 Important DoS Threat Advisory 2026-3516-1
Mageia 10 9 Telegram Update Bugfix Notification Advisory 2026-0079
Mageia 10-9 Font-Tools Bugfix Security Advisory 2026-0078
AI struggles to patch vulns without adult supervision
AI models may not be that good at fixing security flaws. Researchers at 1Password’s Off-by-1 Labs analyzed security patches generated by two frontier [...]
Oracle Linux freerdp Important Security Update ELSA-2026-50747
Oracle Linux 10 ELSA-2026-27288 Important Kernel Bug Fix
Oracle 9 gimp Important Fixes for CVE-2026-42169 and More ELSA-2026-50817
Fedora 44 libXfont2 Important Update CVE-2026-59679 Severity Important
Fedora 44 Samba Important DoS Memory Crash Fixes 2026-fcd4630c0d
Fedora FreeIPA Major Samba Security Fixes Vuln FEDORA-2026-fcd4630c0d
Fedora 44 Trafficserver Major ACL Bypass Memory Safety Vulnerabilities
Humans in the loop miss a third of dangerous AI coding agent requests
A browser-based game designed to test humans’ ability to safely approve AI coding agent requests suggests humans in the loop aren’t as good at [...]
Mak’s Weekly Security Roundup: Critical Linux Security Updates Admins Should Know
This week’s most important Linux security updates arrived through vendor advisories rather than major headline-making disclosures.
Kubernetes Maintainers Expand CSI Path Traversal Fixes Beyond Original Vulnerabilities
Kubernetes maintainers patched two path-traversal vulnerabilities in the NFS and SMB CSI drivers earlier this year. But repository histories show that the [...]
IT department put sticky notes on the laptops to help employees log in
PWNED Welcome back to PWNED, the weekly column where we lovingly poke fun at other organizations’ security screw-ups, in hopes the rest of us can [...]
Meta launches Muse Code for complex software work with persistent AI agents
Meta has released a beta coding agent designed to handle complex software assignments across large codebases. Available for macOS and Linux, Muse Code uses [...]
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Agents are coming for data (just slowly)
Agents have turned up just about everywhere in software this past year, with one conspicuous exception: data. That’s a little odd, because querying data is [...]
Microsoft Web IQ: Ground your AI agents with up-to-date web data
Microsoft has unveiled a suite of IQ products over the last few months. Work IQ, Fabric IQ, and Foundry IQ build on what Microsoft used to call its [...]
Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway
Chinese Wi-Fi router vendor Zbtlink has denied its products contain backdoors but paused firmware downloads while it fixes unspecified security [...]
Rocky Linux sg3_utils Important Command Execution Fix RLSA-2026-50142
Rocky Linux Kernel Moderate DoS Bug Fixes RLSA-2026-49871
Rocky Linux 10 ldns Important Off-Path Attack Fix RLSA-2026-49836
Rocky Linux Thunderbird Significant Security Patch RLSA-2026-49621
Rocky Linux 10 libgcrypt Moderate Denial of Service RLSA-2026-50144
Rocky Linux RLSA-2026-50747 freerdp Important Remote Code Execution Fix
Rocky Linux sg3_utils Important Command Execution Fix RLSA-2026-50141
Rocky Linux Thunderbird Update for Flaws RLSA-2026-49921 CVE-2026-14899
Rocky Linux libgcrypt Moderate DoS Buffer Overflow Risk RLSA-2026-50147
Rocky Linux 9 ldns Important Off-Path Poisoning Attack RLSA-2026-50108
Rocky Linux 9 fence-agents Important Denial of Service Fix RLSA-2026-50317
Fix for Low DoS Vulnerability in Kernel of Rocky Linux 9 RLSA-2026-49870
Rocky Linux 9 osbuild-composer Important DoS Fix RLSA-2026-49838
Rocky Linux kernel-rt Moderate IPC Security Issue RLSA-2026-49851
Rocky Linux Thunderbird Security Advisory RLSA-2026-49922 – Critical Update
Rocky Linux Moderate Info Disclosure Security Update RLSA-2026-49927
Rocky Linux 8 RLSA-2026-49857 Kernel Moderate Bug Fix and Security Update
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
The chain of events leading up to OpenAI’s agents attacking Hugging Face and other organizations in July began months earlier, and involved agents asking [...]
SUSE Wireshark Important Denial of Service Protocol Crash Vuln 2026-3501-1
openSUSE 15.5 SUSE-SU-2026-3502-1 OpenSSL Important DoS Issue
SUSE Python-Django Critical DoS And XSS Issues Resolution 2026-3503-1
SUSE Containerd Moderate Denial of Service Fix 2026-3504-1 CVE-2026-35469
SUSE openSUSE Leap 15.5 Critical pcp Security Update 2026-3505-1
SUSE pcp Critical DoS Command Injection Advisory 2026-3506-1
SUSE pcp Critical Command Injection and DoS Vulnerabilities Fix 2026-3507-1