Menu

Latest articles

Bypassing AI guardrails is so easy a script kiddie can do it
If you want to bypass AI guardrails designed to stop models from assisting with cyberattacks, you often just have to ask the right way, according to [...]
AWS’s Kiro Crew aims to turn AI coding agents into autonomous engineering teams
AWS on Tuesday released Kiro Crew, an open-source orchestration platform designed to help enterprises move beyond interactive AI coding assistants toward [...]
This one time, at Hacker Summer Camp …
As the entire security industry descends on Las Vegas this week for Hacker Summer Camp – not one, but three conferences – attendees can count on two hot [...]
Feds get 3 days to patch N-able God mode flaw under active exploit
The US Cybersecurity and Infrastructure Security Agency (CISA) has added an exploited N-able vulnerability to its Known Exploited Vulnerabilities (KEV) [...]
AI helps Microsoft bug hunters chase a record $20M payday
Microsoft announced this week that between July 1, 2025, and June 30, 2026, the company had paid more than $20 million in bug bounties to 562 researchers. [...]
Tennessee congressional hopeful accused of shooting license plate cameras
An independent congressional candidate in Tennessee faces four felony vandalism charges after allegedly shooting four automated license plate reader (ALPR) [...]
Google ADK flaws reveal what happens when AI agents trust the wrong message
Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger [...]
CAF Bank reopens online service but warns of further outages
CAF Bank has told customers its online banking service is back after being shuttered for more than ten days following what it described as “attempted [...]
Fake IRS letters target cryptocurrency holders
When you should use AI, and when you shouldn’t
Most folks seem happy to let AI write their LinkedIn posts for them. Others, myself included, have AI draft their work memos or slide decks. And some, [...]
When the cloud control plane fails
Not long ago, I worked with an enterprise that believed it had done everything right. The company had spread workloads across multiple regions, replicated [...]
Debian LTS ruby2.7 Important DNS Buffer Overflow Threat DLA-4716-1
Cloudflare has mostly ditched third party security tools, suggests not trying that at home
Cloudflare has used AI to automate processing of incoming reports to its bug bounty program for $58 a month using Anthropic’s Claude Sonnet model and chose [...]
Fedora 43 BorgBackup CVE-2026-62268 Bugfix Update 2026-5a13ef79cc
GitHub pushes stacked pull requests into public preview
Advancing on software development, GitHub has announced the public preview of stacked pull requests. The public preview was announced July 30. Stacked pull [...]
Fedora 44 python-nh3 Update Advisory RUSTSEC-2026-0193 RUSTSEC-2026-0213
Fedora 44 rust-ammonia Update RUSTSEC-2026-0193 RUSTSEC-2026-0213
Fedora 44 Nebula 1.11.0 Patch Fixing Security Issues December 2026
SUSE perl-DBI Important SQL Handling Issues Vuln 2026-3461-1
openSUSE Leap 15.4 Xen Important Buffer Overflow Vuln 2026-3462-1
SUSE 2026-3462-1 Critical Xen Buffer Overflow Security Update
openSUSE libssh Moderate Denial of Service and Integrity Issues 2026-3463-1
SUSE libssh Moderate Denial of Service and Info Disclosure Vuln 2026-3463-1
Oracle Linux 10 p11-kit Moderate Security Issue ELSA-2026-49668
Oracle Linux 10 ELSA-2026-49523 perl-Archive-Tar Important Memory DoS Fix
Oracle 10 perl-DBI Important Threat Fix Advisory ELSA-2026-49514
Oracle Linux 10 gstreamer1-plugins-good Critical Integer Overflow Issue
Oracle Linux 10 php Low Advisory ELSA-2026-48170 CVE-2026-14355
Oracle9 perl-DBI Important Security Advisory ELSA-2026-49612
Oracle Linux 9 ELSA-2026-49527 frr Important Input Validation Fix
Oracle Linux 9 perl-Archive-Tar Vital Memory Management DoS ELSA-2026-49525
Oracle Linux 9 Libreswan Important Vulnerability Advisory ELSA-2026-46397
Oracle Linux 8 Nodejs Important Security Advisory ELSA-2026-47060
Oracle Linux Node.js Important Security Update ELSA-2026-47059
Oracle Linux 8 pki-deps Important Security Update ELSA-2026-43218
Oracle Linux 8 javapackages-tools Important Update Advisory ELSA-2026-41948
Oracle Linux 7 compat-libtiff3 Key Buffer Underflow Fix ELSA-2026-24992
Moderate CVEs for Oracle Linux 7 Python Tornado ELSA-2026-24342
SUSE Nginx Important Heap Overflow Denial of Service Vuln 2026-3448-1
SUSE RRDTool Important Buffer Overflow Risk Advisory 2026-3449-1
SUSE Containerd Moderate Denial of Service Fix Advisory 2026-3450-1
SUSE Linux 12 SP5 Important Xen Security Update 2026-3451-1
SUSE 2026-3452-1 Bind Important Denial of Service Vulnerabilities
SUSE Java 11 Important Security Update Denial of Service CVE-2026-47057
SUSE perl-HTTP-Date Moderate CPU Exhaustion Fix Advisory 2026-3454-1
SUSE gawk Moderate Buffer Overflow Integer Overflow Vuln 2026-3455-1
SUSE perl-Net-DNS Important DoS Issue Advisory 2026-3456-1
SUSE OpenSSL Addresses Significant DoS Risk with Patch 2026-3457-1
SUSE vim Important Code Execution Flaws Vuln 2026-3458-1
SUSE Python3-Dulwich Important SSH Key Issue 2026-3459-1
SUSE Important python-urwid Security Update 2026-3460-1
SUSE Python3 Important Security Update Vulnern 2026-22959-1
SUSE Kernel RT Vital Security Patch for CVE-2026-53359 and CVE-2026-53366
SUSE Kernel RT Important KVM and IPv4 Vulnerabilities 2026-22962-1
SUSE Kernel RT Important KVM and IPv4 Security Patch 2026-22963-1
Google dev kit spurs first-ever agent-on-agent violence
In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the [...]
Gleam update shines on language server
Gleam, a type-safe and scalable language for the Erlang virtual machine and JavaScript runtimes, has reached version 1.18.0. The update brings full support [...]
Mageia Perl Unicode Line Break Security Fix CVE-2026-8594 2026-0320
Mageia Squid Important Heap Overflow FTP Gateway Vuln 2026-0319
Mageia perl-GD Medium OS Command Injection Vuln 2026-0318
Mageia 10 Perl Important Security Fixes CVE-2026-13221 57432 57433
Mageia Unbound Security Patch 1.25.2 Released for 2026-0316 CVE-2026-14586
Mageia libvncserver Important Heap Out-of-Bounds Vulnerabilities 2026-0315
Mageia 2026-0314 Librabbitmq Critical Local Attacks Issue CVE-2023-35789
Mageia corosync Critical DoS Information Exposure Vulnerabilities 2026-0313
AI slop pollutes the CVE pipeline with fake vulns
Now AI is making fake vulnerabilities and polluting the ecosystem. A batch of critical- and high-rated SQLite CVEs that appeared in the NVD with [...]
Russian spies turn public Wi-Fi into malware delivery systems
Conference-goers may want to think twice about connecting to public Wi-Fi after Microsoft disclosed that Russian foreign intelligence operatives (SVR) are [...]
Responding to a Web Server Compromise
Your website isn’t acting normally. Users report errors. Monitoring detects unexpected outbound connections. You discover a recently modified PHP file in [...]
What Is Fuzzing? Inside the Search for Hidden Linux Kernel Bugs
If you spend time reading Linux kernel bug reports or security patches, that line is everywhere. It sits quietly at the bottom of code fixes across the [...]
Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
Georgia and Michigan are the latest US states to report cyberattacks on water systems, as the FBI investigates incidents across at least seven states. [...]
Hashimoto’s Superlogical bets that agentic software development needs more than a better terminal
The rise of AI coding agents is beginning to expose a longstanding weakness in software development: work remains fragmented across developer terminals, CI [...]
Alibaba takes aim at OpenAI and Anthropic with Qwen3.8-Max launch
Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight [...]
Same goals, different clocks: What Red Hat’s 2025 Risk Report reveals about global compliance gaps
In April 2026, Red Hat’s Product Security team published its annual Risk Report . I encourage everyone involved in building, shipping, securing, or [...]
UK government investment arm cops to 40-hour leak of officials’ contact details
The UK government’s corporate finance adviser has admitted that an employee left an internal file containing the names and work email addresses of [...]
What Business Owners Need to Know About Linux Security
Business owners can effectively manage Linux security by shifting their focus from technical commands to strategic risk management and operational oversight.
Debian libssh Important Denial of Service Arbit Code Exec DSA-6410-1
Oracle Linux 10 Kernel Important Bug Fix Advisory ELSA-2026-47017
Oracle Linux 8 Kernel Important Update for CVE-2026-53006 ELSA-2026-47011
Oracle Linux 9 Advisory ELSA-2026-47040 Kernel Important Bug Fix
Oracle OpenSSH Moderate Denial of Service MitM Vuln ELSA-2026-47755
Oracle Linux Node.js24 Important Security Update ELSA-2026-35841
Oracle Linux 10 Java Important ELSA-2026-42899 Security Update
Fedora 43 lemonldap-ng Update Open Redirect Fix CVE-2026-12804
Fedora 43 PostgreSQL 16.14-1 Update Notification for Client Programs
Fedora 43 Coturn 4.15.0 Security Advisory Fixes STUN Issues 2026-02d5b68472
openSUSE Keybase Application Low ASCII Injection Resolution 2026-0272-1
Fedora 44 Curl Addresses Critical SSH Password Leak and State Leak Fixes
Fedora 44 Xen Important Security Buffers and Updates 2026-bf1da84dfc
Fedora GitHub CLI Security Advisory 2026-4e77362489 Denial of Service Risks
Fedora 44 LemonLDAP-ng Update 2.23.2 Open Redirect CVE-2026-12804
Fedora Coturn 4.15.0 Security STUN Attributes Issue 2026-8856c5be6f
Rocky Linux 9 Kernel Important Security Fix RLSA-2026-49212 CVE-2026-52923
Rocky Linux 10 Kernel Important Security Update RLSA-2026-49211
Get started with the Typst programming language for documents
When we think of documents, or documentation, they tend to fall into two circles. First are business documents, typically composed with an office [...]
Why your context layer breaks the minute you use it for something new
Every developer who has worked with an LLM-powered application has hit a familiar wall. You hard-code context into a prompt, and it works great for the [...]
Three scary AI security mistakes haunting enterprises
There is a lot of talk about the coming enterprise AI reality, in which AI finally arrives in production systems. You might not know it, but this [...]
AI is ‘both the weapon and the target’ in latest wave of cyberattacks
AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrike. The [...]
Fedora 43 GoAccess 1.11 Important Buffer Overflow Fix 2026-a488a993d1
Fedora 43 nsd Bug Fixes CVE-2026-12490 DoS Heap Overflow 2026-0b77a23312
Fedora 44 BorgBackup Fix CVE-2026-62268 Security Advisory