Menu

Latest articles

DSA-6452-1 designate – security update
US Bank investigates LockBit’s claims as ransomware crims set pay-or-leak deadline
US Bank says that it’s investigating ransomware crew LockBit’s claims that it breached the financial institution and stole data, which the crims [...]
Researcher tricks Apple’s Find My into sharing location data with Linux
A young security researcher figured out a way to enroll a Linux device into Apple’s Find My network and read live location data from it. Find My is Apple’s [...]
Ransomware crook poses as recovery firm to steal payments from fellow extortionists
A ransomware affiliate appears to have found a new way to squeeze victims for cash: pose as the good guy and undercut the criminals it was working with. [...]
Grok chat duped into swallowing injected instructions
xAI’s Grok web chat agent is currently vulnerable to a novel form of prompt injection, according to security researchers with Adversa AI. The [...]
TrueFoundry debuts open-source AI agent harness, claiming up to 75% lower costs
TrueFoundry has launched TrueForge, an open-source agent harness that lets developers build and run AI agents using models from different providers, [...]
French tax authority says break-in exposed data of 600K, including some private messages
France’s tax authority says attackers may have stolen the contents of messages exchanged with hundreds of taxpayers during the data raid it confirmed [...]
Anthropic’s Opus language problems may be creating a hidden cost for AI coding
AI coding assistants are supposed to reduce the work required to turn a developer’s intent into working software. But some users of Anthropic’s Opus 4.8 [...]
The five walls standing between a demo agent and a deployed one
Building an AI agent that looks impressive in a demo is now a weekend project. Building one that an enterprise will actually let touch its CRM, its data [...]
Introducing G#: A Go-like language for .NET
Microsoft’s open sourcing of .NET not only has sped up the development of the platform, but also has allowed new languages and features to be built on top [...]
Nobody’s agent fleet fails the way the vendors say it will
I run 49 scheduled AI agents on one laptop. Another 24 sit beside them, deliberately switched off. That distinction matters more than it sounds. After [...]
AI agent suggested installing a malware package. Engineer almost took its advice
PWNED Welcome back to PWNED, the column where we make fun of those who are security self-owned, so hopefully you don’t do the same. This week, we have a [...]
DSA-6454-1 sabnzbdplus – security update
DSA-6453-1 libgit2 – security update
Smashing Security podcast #481: Never say this to a robot dog
‘Not a theoretical risk,’ feds warn as attackers use AI-made code to hack critical infrastructure controllers
Attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, [...]
DSA-6450-1 srt – security update
DSA-6449-1 swift – security update
Linux Identity, Privilege & Administrative Access
Access to a Linux system involves several connected decisions. The system must determine who or what is requesting access, verify that identity, decide [...]
ICE boss to agents: Leave the Meta spy glasses at home
Some ICE employees seemingly needed a reminder not to wear their Meta pervert glasses to work. Because only ICE can spy on ICE. Meta smart glasses are [...]
Flock surveillance backlash mounts as fiendish Halloween plans circulate
Surveillance tech company Flock has struggled with its public image for years, but the problem has become particularly acute in recent weeks. Its network [...]
Mageia 10 lsp-plugins Bug Fix Advisory Release 2026-0101 Update
Ubuntu Bind9 Security Advisory USN-8648-1 CVE-2026-10723 CVE-2026-10822
Ubuntu Nginx Important DoS Injection Flaws USN-8563-3 CVE-2026-42533
Ubuntu libheif Important Denial of Service Vulnerabilities USN-8649-1
Comcast gives its Wi-Fi motion detector a security makeover
Comcast has folded its Wi-Fi-based intruder detection feature into Xfinity Shield, a repackaged bundle of physical and cybersecurity offerings. The US [...]
Ubuntu 26.04 introduces vital fixes for LibTIFF denial of service flaw
Ubuntu 26.04 libssh Important Denial of Service Vulnerability USN-8093-2
Decoding Origin: Cursor’s GitHub rival that was launched during the latter’s outage
AI coding tools are increasingly becoming the place where developers write and modify software. SpaceX-owned Cursor now wants to bring code hosting into [...]
Fix for Test Failure in Debian LTS ruby-grape DLA-4706-2 Update
Rocky Linux 8 pam Moderate Plaintext Recovery Threat RLSA-2026-56131
Rocky Linux 8 attr Medium Symlink Traversal Fix RLSA-2026-56133
Rocky Linux 8 sg3_utils Important Command Execution Fix RLSA-2026-56130
Rocky Linux 8 RLSA-2026-56219 Python3 Important Security Issue
Rocky Linux gstreamer1-plugins-bad-free Heap Overflow CVE-2026-19387 Alert
Rocky Linux 9 .NET 10.0 Important Security Update RLSA-2026-55857
Rocky Linux 9 RLSA-2026-55856 .NET 9.0 Important Security Update
AI inference: Five best practices for successful AI applications
While some organizations are still getting started with their AI strategies, others are in pilot purgatory, with few experiments or proofs of concept [...]
Coding agents make mistakes. So what?
Regular readers will probably have figured out that I’m generally an optimist. I think things are always getting better, and the future of the human race [...]
Prison for data analyst who tried to extort $2.5 million from his employer
Ubuntu dotnet Important Request Smuggling Information Disclosure 8641-1
Australian hotel chain leaks guests’ PII after breach at third-party database operator
Australian aparthotel chain Quest has revealed it leaked customer data. A Reg reader kindly shared an email from the chain with the subject line “Important [...]
AI’s attribution problem gets worse as models scale
Diffusion models are becoming sophisticated enough that they can reproduce an image even when they don’t have access to the original. In a series of ‘what [...]
Fedora 43 Python 3.14.7 Security Advisory 2026-7f32bbb5b0
Fedora 43 libnfs Security Advisory CVE-2026-57918 CVE-2026-53689
Fedora 43 Lemonldap-ng Update Advisory CVE-2026-19349 Security Fix
Fedora 43 perl-List-SomeUtils-XS Critical Heap Overflow Fix 2026-6217093b91
Fedora 43 radsecproxy Bug Fix Update 2026-057cd843d0 Released Now
Fedora 43 perl-Imager Important EXIF Decode Fix CVE-2026-19082
Fedora 44 Python 3.12 Update Critical Denial of Service Fix 2026-a9f0296a41
Fedora 44 libgit2 Update 1.9.7 Security Advisory 2026-86684eb696
Fedora 44 GitPython 3.1.59 Update Security Fixes 2026-166bfc4f18
Fedora Python 3.14.7 Important DoS Bypass Fix 2026-2c124fcf93
Fedora 44 lemonldap-ng 2.23.3 Security Update CVE-2026-19349
Fedora 44 perl-Imager Important EXIF Decoding Fix CVE-2026-19082
Fedora radsecproxy 1.11.4 Bug Fixes Update FEDORA-2026-099bb42b08
SUSE Snphost Important Information Leak Heap Overflow Vuln 2026-3642-1
How to Recover Authentication Platforms After Cyberattacks in Linux Environments
When an authentication platform goes down, downstream applications go with it. Employees can’t sign in, customers get locked out, and scheduled jobs [...]
DSA-6451-1 firefox-esr – security update
OpenAI’s overhead will rise 20 percent for some workloads as it hardens security
OpenAI on Tuesday said its decision to suspend model training work, implemented after unreleased, unsupervised AI models hacked HuggingFace, remains in [...]
Rocky Linux PostgreSQL Important Denial of Service Advisory RLSA-2026-52395
Rocky Linux PostgreSQL Important Denial of Service Issue RLSA-2026-52396
Ubuntu 24.04 LTS Linux Kernel Critical Issues Update USN-8636-2
Ubuntu 22.04 LTS Linux Kernel Security Update USN-8630-3
Ubuntu 24.04 LTS Linux Kernel Important Security Issues USN-8629-3
Accelerating AI innovation through open weights
Open-weight AI models are a big deal, as Nvidia and more than 200 other companies and organizations attested in their “Open Weights and American AI [...]
Debian SRT Important DoS Encryption Bypass Vulnerabilities DSA-6450-1
Debian Swift Significant SSRF Authorization Bypass Flaws DSA-6449-1
Expired credit cards revived by researchers to make unauthorized payments
Researchers affiliated with the University of Massachusetts Amherst have found that you can get payments out of certain expired contactless credit cards, a [...]
Debian SPIP Severe Remote Code Execution Vulnerability DSA-6448-1
Debian DSA-6447-1 Librabbitmq Important DoS Code Exec Vulnerabilities
Ubuntu 14.04 LTS Linux Kernel Security Advisory USN-8646-1
Ubuntu Linux Kernel Important WiFi Injection Flaws Addressed USN-8645-1
Ubuntu Kernel Security Notice USN-8644-1 CVE-2026-43071 to CVE-2026-53309
Ubuntu Linux Kernel Security Advisory USN-8643-1 Multiple Issues
DuckDB 2.0 coming this fall with client/server mode
DuckDB, the analytics database with high-end features in a single easily deployed binary, is due to release a major update, version 2.0, this fall. In a [...]
How QR-code phishing can slip past corporate security measures
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
Oracle Linux 8 haproxy Important NULL Pointer Threat ELSA-2026-55859
Oracle Linux 8 Unbound Important Fix for CVE-2026-44690 ELSA-2026-55784
Oracle Linux 8 ELSA-2026-55530 389-ds Important DoS Buffer Overflow
Oracle Linux 8 Node.js Important Security Update ELSA-2026-54530
Oracle Linux 10 ELSA-2026-55892 Unbound Important Buffer Overflow Threat
Oracle Linux ELSA-2026-55858 .NET 10.0 Important Bug Fix
Oracle Linux 10 libssh Important Advisory ELSA-2026-55855
Oracle haproxy Important Buffer Overflow Fix ELSA-2026-55679
Oracle Linux 10 Advisory ELSA-2026-55617 pcp Important Multiple Fixes
Oracle Linux 10 Nodejs Significant CVE Remedy ELSA-2026-55541
Oracle Linux 10 libXfont2 Important Fixes for CVEs 2026-44950 2026-59679
Oracle Linux 10 Bind Vital Security Announcement ELSA-2026-55437
Oracle Linux 10 GStreamer1 Plugins Key Integer Overflow Fix ELSA-2026-55435
Oracle Linux 10 gstreamer1-plugins-good Vulnerability CVE-2026-73433
Oracle Linux 10 gstreamer1-plugins-bad-free Major Update ELSA-2026-55433
Oracle Linux curl Important Fix ELSA-2026-55432 CVE-2026-8927
Oracle Linux 10 ELSA-2026-55424 389-ds-base Important LDAP Issues
Oracle Linux 9 gstreamer1 Plugins Important Security Fixes ELSA-2026-55865
Oracle Linux 9 Unbound Important Vulnerability Advisory ELSA-2026-55841
Oracle Linux 9 haproxy Important Buffer Overflow Vuln ELSA-2026-55772
Oracle Linux 9 libXfont2 Important CVE Fixes ELSA-2026-55447
Oracle Linux gstreamer1-plugins-good Moderate Fix for ELSA-2026-55436
CISA gives feds 3 days to fix actively exploited Ray RCE bug
CISA says attackers are exploiting a critical 2025 vulnerability in Ray, the widely used open source framework for scaling Python and machine-learning [...]