Menu

Latest articles

DSA-6549-1 xz-utils – security update
High-severity Nvidia bug could crash GPU monitoring on exposed servers
Researchers found thousands of GPU servers exposing Nvidia’s DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity [...]
Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise
The credential-hijacking Shai-Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK. Multiple security researchers [...]
Inside a brand deal scam targeting YouTube creators
A plausible-sounding sponsorship offer could mask an attempt to compromise your Google account
Fighting GenAI with GenAI: The New Email Security Landscape
The use of phishing emails as a means of stealing information or implanting damaging malware dates back to the mid-1990s. Although almost as old as the [...]
Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code
UK and Germany team up against Russian cyberattacks as Brexit rethink looms
Britain and Germany have announced a partnership to counter cyberattacks and sabotage, particularly from Russia, as Prime Minister Andy Burnham heads to [...]
FBI, French Police Seize CSAM Site Domains, Suspected Admin Arrested
AWS takes aim at runaway AI agent behavior with Strands Box
Amazon Web Services (AWS) has introduced an open-source sandbox for AI agents that allows developers to restrict their actions based on previous behavior, [...]
AI-powered data pipeline observability: Stop monitoring and start preventing
Devops tools are making it increasingly easy to monitor data pipeline failures. But in many cases, those alerts are already too late. Take marketing [...]
Cheapskates wouldn’t pay for security help, got hit by ransomware, and went bust months later
Welcome back to PWNED, the weekly column where we highlight some of the lowlights in corporate security. This week, we’ll talk about two scenarios, one [...]
Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead
The United States Department of Justice has charged a man with fraud after he allegedly told clients he could decrypt files locked up by ransomware but [...]
Smashing Security podcast #487: Clippy’s crypto comeback
DSA-6548-1 node-shell-quote – security update
DSA-6547-1 ruby-jwt – security update
DSA-6546-1 rails – security update
Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
Imagine going to a Google website at its correct URL, only to be redirected to a crim’s illegitimate copy. Attackers hijacked top-level domains, [...]
Dread Dark Web Forum Hijacked, Operators Claim Control of Domain Keys (Updated)
AWS launches open-source AI agent sandbox to prevent YOLO mode disasters
AWS has offered multiple open-source strategies for holding AI agents accountable, and now it’s adding a full-on sandbox to this stack. Dubbed Strands Box, [...]
US states sue popular kitmaker TP-Link over China risks
The attorneys general of Florida, Iowa, Montana, and Nebraska have sued ubiquitous networking and smart home tech maker TP-Link, alleging its security [...]
How DNS, Firewalls and Endpoint Tools Block Websites
The quest for simplicity: Why SMBs want advanced protection without the complexity
The cybersecurity market is often making it tougher for SMBs to keep threats at bay
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI [...]
FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet [...]
100+ Ukrainian Websites Hacked to Install Lunex Stealer with ClickFix Lure
South Korean president calls for creation of tools that stop all cyber-attacks
South Korean president Lee Jae Myung has told the nation’s cabinet that it’s time to develop AI-powered defensive tools to combat AI-wielding attackers. [...]
Anthropic reconfigures its cool kids security program
Only a week after warning about the perils of competitor Z.ai’s GLM-5.3 model and its advanced cybersecurity capabilities, Anthropic has expanded its [...]
ASOS Hackers Hijack App Notifications, Claim Snowflake Data Breach
Karina Portugal Makes the Case for Know Your Agent
Trump Mobile customers’ data dumped – and some never even received their gold device
If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the [...]
FBI Removes Accenture Contractor Over ShinyHunters Job Site Data Breach
One week to TechCrunch Disrupt: What’s next for AI and software development
First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code [...]
Microsoft extends the Outlook naughty step with two more file types
Microsoft is adding two extra file types to its Outlook block list to strengthen security. The file types are .msix and .msixbundle, used for Windows [...]
5 Astrix and Aembit Alternatives for AI Agent Identity Security
Aembit Extends Access Controls to Personal AI Agents
Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
AppViewX Adds Shadow AI Visibility and a Runtime Kill Switch to Agent Identity Security
Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets
GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent [...]
ServiceNow takes aim at enterprise AI’s workflow bottleneck with AI Workflow Factory
ServiceNow has launched two AI solutions that can help enterprises identify business processes ripe for automation, build the workflows to address them, [...]
Asos app delivers a data leak threat instead of fast fashion
Asos customers have reported receiving a rogue app notification claiming the online clothing retailer’s Snowflake instance has been compromised and [...]
Denmark’s ID register spills more people’s details than the country has residents
An unauthorized party abused a private Danish company’s legitimate access to the country’s Central Population Register (CPR), exposing names, [...]
Search Exposure Linux Security Threats Impacting Personal Data
Search-indexed personal data increases security risk in Linux environments. When email addresses, usernames, phone numbers, and role information are easy [...]
Understanding Internal vs External Pen Testing for Your Business
Penetration tests are like fire drills for your network. They expose weak spots, test defenses, and help prevent real damage when threats come knocking. [...]
Using Technology to Fight Distraction and Improve Focus
FBI Confirms Multiple Arrests in ShinyHunters Investigation
Money can’t buy enterprise trust
I thought the AI boom was producing a new level of bad behavior, what with MongoDB CEO CJ Desai peacing out, not to mention Google’s earlier controversial [...]
Don’t buy a consultant’s AI framework
Every major consulting firm offers its own prebuilt architectural framework, model, or reference architecture for generative AI and agentic AI. The pitch [...]
Linux Kernel Vulnerability Fixed in Binder Device Creation
Linux developers have merged a fix for a Linux kernel vulnerability that can leave Binder device creation writing to memory the kernel has already released.
Citrix NetScaler Vulnerability Is Being Exploited: Check SAML Systems
Citrix has confirmed targeted attacks involving a Citrix NetScaler vulnerability and urged affected customers to update.
OpenOffice Vulnerability Can Run Code From Malicious Documents
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Apache Thrift 0.25.0 Adds Memory Limits for Network Messages
Apache released Thrift 0.25.0 on Sep 30, 2026 with memory checks for several C++, Java, and Python components.
Apache Directory LDAP API 2.1.9 Security Update for CVE-2026-103877
Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.
OpenSSL Vulnerability Can Leak Server Memory Through DTLS
OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.
Fedora version 43 Kernel 7.2.9 Critical System Upgrade 2026-754bab2c40
Fedora 43 fixes a critical Type Confusion Buffer Overflow flaw in Chromium
Fedora 43 Update on Security Improvements for Python 3.12 Release
Fedora 45 Kernel 7.2.9 Important Fixes Advisory 2026-8dc7d1def3
Fedora 45 zenon Security Advisory CVE-2026-28364 Integrity Bypass
Fedora 45 virt-v2v Critical Buffer Overflow Remote Exec CVE-2026-28364
Fedora 45 why3 Essential Fixes for Critical Remote Code Execution and Flaws
Fedora 45 Xen Critical OCaml Fix for Multiple CVEs 2026-403bcf6fd8
Fedora 45 z3 High Critical Integrity Bypass And Proof Fixes 2026-403bcf6fd8
Fedora 45 virt-top Critical Buffer Over-read Vulnerability 2026-403bcf6fd8
Fedora 45 Utop Crucial Buffer Over-Read Code Execution Flaw 2026-403bcf6fd8
Fedora 45 Rocq Critical Integrity Bypass and Logic Flaws 2026-403bcf6fd8
Fedora 45 Supermin Critical Integrity Evasion Flaw 2026-403bcf6fd8
Fedora 45 Plplot Important OCaml Fixes Vulnerabilities 2026-403bcf6fd8
Fedora 45 rocq-stdlib Critical Code Execution Bugs Vuln 2026-403bcf6fd8
Fedora 45 Unison Critical Remote Code Exec Vuln 2026-403bcf6fd8
Fedora 45 Prooftree Significant RCE Update 2026-403bcf6fd8 Released
Fedora 45 opam Critical Buffer Over-Read Fixes 2026-403bcf6fd8
Fedora 45 Celestial Security Patch for OCaml 5.5.1 RCE Fix 2026-403bcf6fd8
Significant Issue Resolutions and Enhancements for Fedora 45 ocaml-yamlx
Fedora 45 ocaml-zmq Critical Remote Exec Flaws 2026-403bcf6fd8
Fedora 45 ocaml-yaml Critical RCE Buffer Overflow Vuln 2026-403bcf6fd8
Fedora 45 ocaml-zip Critical Buffer Overflow Code Exec Fix 2026-403bcf6fd8
Fedora 45 ocaml-zed Critical Buffer Over-read Issue Vuln 2026-403bcf6fd8
Fedora 45 ocaml-yojson Major Remote Code Execution Risk – 2026-403bcf6fd8
Fedora 45 ocaml-zarith Critical Buffer Over-read Vuln 2026-403bcf6fd8
Fedora 45 ocaml-xmlm Resolves Serious Remote Code Execution Vulnerabilities
Fedora 45 ocaml-xmlrpc-light Major Vulnerability Remote Code Exec Risk 2026
Fedora 45 OCaml XML Light Critical Bugs Fix Advisory 2026-403bcf6fd8
Fedora 45 OCaml-uunf Addresses Key Unicode Buffer Over-Read Vulnerability
Fedora 45 OCaml Variantslib Critical Buffer Over-read and Integrity Risk
Fedora 45 ocaml-uuseg Security Bugs Advisory CVE-2026-28364
Fedora OCaml-uutf Serious Remote Code Execution and Integrity Bypass
Fedora 45 ocaml-trie Important Remote Exec Flaw Fix 2026-403bcf6fd8
Fedora 45 OCaml Unionfind Fixes Critical Remote Code Exec and Logic Flaws
Fedora 45 OCaml Version Update Addresses Serious Remote Code Execution Risk
Fedora 45 ocaml-uucp Serious Buffer Overflow Resolution 2026-403bcf6fd8
Fedora 45 ocaml-uucd Serious Buffer Overflow and Integrity Vulnerabilities
Fedora 45 ocaml-topkg Important Remote Code Execution Fix CVE-2026-28364
Fedora 45 OCaml-Time-Now Critical Buffer Overflow Advisory 2026-403bcf6fd8
Fedora 45 OCaml-swhid-core Critical Remote Code Exec Audit 2026-403bcf6fd8
Fedora 45 ocaml-testo Critical Security Issues and Fixes 2026-403bcf6fd8
Fedora 45 ocaml-stdcompat Important Buffer Over-Read Vulnerability Fix
Fedora 45 ocaml-stdio Critical Buffer Overflow and Remote Execute Fix
Fedora 45 ocaml-store Severe Buffer Over-Read Vulnerability 2026-403bcf6fd8
Fedora 45 OCaml-Stdlib-Random Severe Buffer Overflow and Integrity Issues
Fedora 45 ocaml-ssl Important Integrity Bypass and RCE 2026-403bcf6fd8