Menu

Monthly Archives: January 2026

Best of British: UK’s infosec envoys include Cisco, Palo Alto, and Accenture
Pro-Russian denial-of-service attacks target UK, NCSC warns
How to use Pandas for data analysis in Python
Tailwind meets AI headwind
Curl shutters bug bounty program to remove incentive for submitting AI slop
Three vulnerabilities in Anthropic Git MCP Server could let attackers tamper with LLMs
Cloudflare whacks WAF bypass bug that opened side door for attackers
Remember VoidLink, the cloud-targeting Linux malware? An AI agent wrote it
The AI Fix #84: A hungry ghost trapped in a jar gains access to the Pentagon’s network
AI framework flaws put enterprise clouds at risk of takeover
Anthropic quietly fixed flaws in its Git MCP server that allowed for remote code execution
For the price of Netflix, crooks can now rent AI to run cybercrime

An update that solves nine vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

A first look at XAML Studio 2.0
AI is rewriting the sustainability playbook

An update that solves 17 vulnerabilities, contains one feature and has one security fix can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

Akamai CEO wants help to defeat piracy, reckons he can handle edge AI alone
Broker who sold malware to the FBI set for sentencing
Don’t underestimate pro-Russia hacktivists, warns UK’s cyber crew
Windows 11 shutdown bug forces Microsoft into out-of-band damage control
Ingram Micro admits summer ransomware raid exposed thousands of staff records
ClickHouse buys Langfuse as data platforms race to own the AI feedback loop
UK prime minister stares down barrel of ban on social media for kids
Warwickshire school to reopen after cyberattack crippled IT
Royal Navy’s helicopter drone makes its first autonomous flight
Edge AI: The future of AI inference is smarter local compute
AI coding requires developers to become better managers

An update that contains one feature can now be installed.

An update that contains one feature can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves seven vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

ATM maintenance tech broke the bank by forgetting to return a key
Microsoft hiring energy strategists to power its Asian datacenters
Mandiant releases quick credential cracker, to hasten the death of a bad protocol

An update that solves 10 vulnerabilities and has one bug fix can now be installed.

New efficiency upgrades in Red Hat Advanced Cluster Management for Kubernetes 2.15

Update to 144.0.7559.59 * CVE-2026-0899: Out of bounds memory access in V8 * CVE-2026-0900: Inappropriate implementation in V8 * CVE-2026-0901: Inappropriate implementation in Blink * CVE-2026-0902: Inappropriate implementation in V8

This update adds a patch to fix CVE-2025-56225, a flaw in the bundled version of fluidsynth.

Upgrade to libtpms 0.10.2 fixing CVE-2026-21444

Update to 144.0.7559.59 * CVE-2026-0899: Out of bounds memory access in V8 * CVE-2026-0900: Inappropriate implementation in V8 * CVE-2026-0901: Inappropriate implementation in Blink * CVE-2026-0902: Inappropriate implementation in V8

Upgrade to libtpms 0.10.2 fixing CVE-2026-21444

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

The business social networking site is a vast, publicly accessible database of corporate information. Don’t believe everyone on the site is who they say they are.

Fast Pair, loose security: Bluetooth accessories open to silent hijack

Several vulnerabilities were discovered in python-urllib3, a HTTP library with thread-safe connection pooling for Python3, which could result in denial of service or request forgery. For the oldstable distribution (bookworm), these problems have been fixed in version 1.26.12-1+deb12u2.

MGASA-2026-0012 – Updated gimp packages fix security vulnerabilities

MGASA-2026-0011 – Updated python-urllib3 packages fix security vulnerabilities

MGASA-2026-0010 – Updated libpng packages fix security vulnerabilities

MGASA-2026-0009 – Updated nodejs packages fix security vulnerabilities

MGAA-2026-0006 – Updated v4l2loopback packages fix bug

https://security-tracker.debian.org/tracker/DSA-6103-1

https://security-tracker.debian.org/tracker/DSA-6102-1

Astro web framework maker merges with Cloudflare

https://security-tracker.debian.org/tracker/DSA-6101-1

Visual Studio Code adds agent development extension
Google tests BigQuery feature to generate SQL queries from English
Sorry Dave, I’m afraid I can’t do that! PCs refuse to shut down after Microsoft patch
German cops add Black Basta boss to EU most-wanted list
RondoDox botnet linked to large-scale exploit of critical HPE OneView bug
Bankrupt scooter startup left one private key to rule them all
Probably not the best security in the world: Carlsberg wristbands spill visitor pics

USN-7916-1 introduced a regression in python-apt

Cisco finally fixes max-severity bug under active attack for weeks

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Chinese spies used Maduro’s capture as a lure to phish US govt agencies

https://security-tracker.debian.org/tracker/DSA-6100-1

Flipping one bit leaves AMD CPUs open to VM vuln
Contagious Claude Code bug Anthropic ignored promptly spreads to Cowork
Is it time for internet services to adopt identity verification?

Should verified identities become the standard online? Australia’s social media ban for under-16s shows why the question matters.

WEF: AI overtakes ransomware as fastest-growing cyber risk
The AI Fix #83: ChatGPT Health, Victorian LLMs, and the biggest AI bluffers
A simple CodeBuild flaw put every AWS environment at risk – and pwned ‘the central nervous system of the cloud’
Smashing Security podcast #450: From Instagram panic to Grok gone wild
US regulator tells GM to hit the brakes on customer tracking
Woman bailed as cops probe doctor’s surgery data breach
Improving VirtOps: Manage, migrate or modernize with Red Hat and Cisco
Manage clusters and applications at scale with Argo CD Agent on Red Hat OpenShift GitOps
Microsoft taps UK courts to dismantle cybercrime host RedVDS
Ofcom keeps X under the microscope despite Grok ‘nudify’ fix
When your platform team can’t say yes: How away-teaming unlocks stuck roadmaps
AWS flips switch on Euro cloud as customers fret about digital sovereignty
What is GitOps? Extending devops to Kubernetes and beyond
For agentic AI, other disciplines need their own Git
Getting started with GitHub Copilot in Visual Studio or VS Code

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

From typos to takeovers: Inside the industrialization of npm supply chain attacks