Menu

Latest articles

Attack hides malware in PNGs and drops custom reverse tunnel on victims’ machines
An unknown miscreant is using “TerminalFix” to trick unsuspecting users into running PowerShell commands that infect their computers with a [...]
Anthropic cracks down on hijacked user accounts mining AI tokens
Rather than paying for their own Claude usage, crims are using malware to steal access to other people’s accounts. Aware of this issue, Anthropic has [...]
Cursor customers will lose access to OpenAI coding models in November
OpenAI will stop AI coding platform Cursor from accessing its models from November 12, following the acquisition of Cursor parent Anysphere by Elon Musk‘s [...]
Mageia 10 Golang Critical Security Issues Advisory 2026-0341 CVE-2026-56865
Debian Trixie Linux Kernel Security Fix DSA-6477-1 for Privilege Escalation
Debian LTS Roundcube Important XSS Remote Code Exec Vuln DLA-4760-1
Governance by design: Turning AI policy into executable controls
Governance determines whether a generative AI program remains a set of pilots or becomes a durable capability. I treat governance as engineering work. The [...]
Hands-on with Unsloth Desktop, for running and training LLMs locally
LM Studio makes it easy to run LLMs on one’s own hardware, whether as a desktop app or a server for others in one’s organization. But LM Studio isn’t the [...]
DSA-6477-1 linux – security update
Debian Roundcube Important Info Disclosure XSS Denial of Service DSA-6479-1
Debian Starlette DSA-6478-1 Security Fixes for Denial of Service and Bypass
Debian LTS DLA-4761-1 libnet-dns-perl Critical DoS CVE-2026-64194
openSUSE mozjs102 Moderate Denial of Service NULL Pointer Vulnerabilities
openSUSE – Moderate Memory Weakness in python-PyPDF2 Resource Exhaustion
openSUSE Trivy Moderate Vulnerability Fix Advisory CVE-2026-72815-72817
openSUSE libopenssl-3-devel Important Security Fix 2026-11623-1
openSUSE java-25-openjdk Important Security Issues Advisory 2026-11621-1
openSUSE Tumbleweed Grafana Important Security Update 2026-11619-1
openSUSE coturn Moderate Security Update Vuln 2026-11617-1
openSUSE gh Important Fixes for Multiple Security Issues 2026-0309-1
openSUSE Tor Significant Security Update 2026-0306-1 Released Now
openSUSE v2ray-core Important Security Update Buffer Overflow 2026-0307-1
openSUSE Pyenv Moderate File Handling Vulnerability CVE-2026-68939 Advisory
openSUSE Git-lfs Important Update for Multiple Security Issues 2026-0305-1
Linux Kernel 7.1-rc5 Tracing Reader Use-After-Free Bug Discovery
Removing a Linux trace instance should end its lifetime. An open tracefs reader can currently keep using that instance after another task removes it, [...]
eBPF Security Research Adds State-Aware Syscall Filtering
A Linux service may need broad system-call access while it starts, then only a smaller set while it handles requests. A single policy loaded before startup [...]
KubeCap Finds Excess Linux Capabilities in Kubernetes Workloads
A Kubernetes workload can run with more Linux capabilities than its code needs. When capability settings are missing or broad, that excess authority may [...]
SUSE python36 Important Security Update Vuln 2026-3855-1
openSUSE rsyslog Important Heap Buffer Overflow Vuln 2026-3859-1
SUSE Rsyslog Important Heap Overflow Fix Advisory SUSE-2026-3860-1
SUSE Rsyslog Important Buffer Overflow Fix SUSE-SU-2026-3861-1
SUSE Python Security Update Addresses DoS Vulnerabilities and More Issues
SUSE 2026-3863-1 Significant Apptainer Filesystem Vulnerability Found
SUSE Kernel Important Update for Live Patch 15 with 6 Security Fixes
SUSE Kernel Live Patch 13 Important Security Update SUSE-SU-2026-23280-1
SUSE Kernel Important Live Patch 12 Security Update 2026-23281-1
SUSE Linux Enterprise Important Kernel Live Patch 11 Advisory 2026-23282-1
SUSE Kernel Important Security Update 2026-23283-1 19 Fixes Installed
SUSE Enterprise 16 Important Kernel Live Patch Security Update 2026-23284-1
SUSE Kernel Important Security Update for 20 Vulnerabilities 2026-23285-1
SUSE Linux Enterprise 16 Kernel Important Patch 2026-23286-1
SUSE Linux Enterprise 16 Kernel Important Security Fix 2026-23287-1
SUSE Kernel Live Patch 5 Important Security Update 2026-23288-1
SUSE rsync Vital Security Update 41 Vulnerabilities Resolved 2026-23289-1
SUSE Kernel Important Security Update Live Patch 2026-23290-1 CVE Fixes
SUSE Kernel Important Security Fix Advisory 2026-23291-1
SUSE Linux Enterprise 16 Kernel Important Security Update 2026-23292-1
SUSE Linux Enterprise Kernel Important Patch for 24 Issues 2026-23293-1
SUSE Linux Enterprise 16 Kernel Important Update for 12 Issues 2026-23295-1
SUSE Linux Enterprise 16 Important Kernel Update SUSE-SU-2026-23296-1
SUSE Wget Important Heap Corruption and Buffer Overflow Fix 2026-23297-1
SUSE Python310 Important Path Traversal Fix Vuln 2026-3851-1
SUSE 2026-3852-1 Important Update for Rekor Application Security
SUSE podman Important Security Update 2026-3853-1 Released Today
SUSE Podman Significant Security Patch SUSE-SU-2026-3854-1
Debian LTS xrdp Critical Buffer Overflow Vulnerability Alerts DLA-4759-1
openSUSE rsyslog Important Heap Overflow Fix Advisory 2026-3859-1
openSUSE Rsyslog Important Heap Buffer Overflow Issue 2026-3860-1
Critical Advisory for openSUSE Apptainer Filesystem Issue CVE-2026-17106
openSUSE python310 Important Path Traversal Vulnerability Fix CVE-2026-7774
openSUSE 2026-3852-1 Rekor Major Security Update Released Today
Significant security patch update 2026-3853-1 launched for openSUSE Podman
openSUSE Podman Significant Security Patch SUSE-2026-3854-1
Rocky Linux libxml2 Moderate Update Buffer Overflow Vuln RLSA-2026-60394
Fedora 44 python-pynitrokey Critical Update CVE-2026-69247
Fedora 44 python-cryptography Critical Fix CVE-2026-69247 Advisory
Fedora 44 BlueZ Local DoS Buffer Overflow Vulnerability 2026-1fba3f22c9
Turns out Brits would quite like their private messages to stay private
Brits have delivered a fairly unambiguous verdict on giving the government access to their encrypted messages: no, thanks. New polling commissioned by the [...]
DSA-6479-1 roundcube – security update
DSA-6478-1 starlette – security update
openSUSE Broot Moderate Bug Fix Advisory CVE-2026-72847
openSUSE CoreDNS Moderate Denial of Service Fix 2026-21674-1
openSUSE Vim High Priority Fix for Service Disruption and Code Execution
Mageia Python-NLTK Important Multiple Issues Fixes 2026-0340
openSUSE Tumbleweed Pyenv Moderate Security Fix CVE-2026-68939 2026-11613-1
openSUSE Authlib Moderate Security Issue Fix 2026-11614-1 CVE-2024-37568
openSUSE Tumbleweed cadvisor Moderate CVE-2026-41178 Advisory 2026-11606-1
openSUSE Distribution-Registry Important CVE-2026-41178 2026-11609-1
Gentoo Freenet Important XSS Deanonymization Vulnerability GLSA 202608-33
Gentoo Tor Significant Various Risks Remote Code Execution GLSA 202608-32
Rust language adds algebraic floating-point methods
The Rust team has released Rust 1.98.0, an update to the language that introduces algebraic methods for floating-point operations. Developers who have a [...]
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
Anthropic’s Claude Code running Opus 5 in Auto Mode can be tricked into executing attacker-controlled code simply by asking the coding agent to summarize a [...]
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.
US government snitch-finder pleads guilty to leaking state secrets to foreign spies
The former Defense Intelligence Agency (DIA) IT specialist previously accused of trying to pass secret and top-secret information to foreign spies has [...]
Oracle Linux 9 Advisory ELSA-2026-59723 Important Kernel Bug Fixes
Oracle mingw-openssl Low Buffer Overread Fix ELSA-2026-60329-0
Oracle Linux 8 ELSA-2026-59821 Kernel Bug Fix Important
CISA: Most exploited vulnerabilities should have been eradicated decades ago
CISA is still crying out for software vendors to adopt Secure by Design (SBD) development practices, and says in its latest review that longstanding [...]
Streamlining container security: Red Hat Hardened Images now supported in AWS InspectorScan API and ECR Basic scanning
Software security teams can face an overwhelming influx of vulnerability alerts, often stemming from non-essential packages bundled inside traditional [...]
Preparing OpenStack for the post-quantum era: A systematic approach to crypto-agility
OpenStack powers clouds used by some of the most security-sensitive organizations on the planet: government agencies, telecommunications providers, [...]
Industry that built the problem offers to sell you the solution
OpenAI has gathered more than 100 of the world’s biggest tech and infosec companies to warn that cyber defense is in trouble – a reassuring [...]
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Why enterprise AI projects keep failing
Over the past three years, as an independent cloud and AI consultant, advisor, and industry influencer, I have worked with numerous companies seeking my [...]
Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood
Nothing smarts like a paper cut, but being attacked after leaving an application’s web interface exposed to the internet might be just as painful. Such [...]
Australian cops cuff alleged TeamPCP masterminds
The Australian city of Perth is by some measures the world’s most isolated major metropolis, but is still sufficiently connected to US law enforcement [...]
Fedora 43 rust-h2 Security Update Resolving RUSTSEC-2026-0258 Issue
SUSE Important Wicked Out-of-Bounds Issues CVE-2026-71401 CVE-2026-71402
openSUSE Wicked Important DHCP Out-of-Bounds Reads Vuln 2026-3839-1
SUSE important wicked Security Update CVE-2026-71401 CVE-2026-71402
openSUSE Wicked Important Indirect Shell Command Injection Fix 2026-3840-1