Menu

Monthly Archives: January 2026

UK regulators swarm X after Grok generated nudes from photos
Maximum-severity n8n flaw lets randos run your automation server
OpenAI putting bandaids on bandaids as prompt injection problems keep festering
Yes, criminals are using AI to vibe-code malware
Logitech macOS mouse mayhem traced to expired dev certificate
The hidden devops crisis that AI workloads are about to expose

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Cloudflare pours cold water on ‘BGP weirdness preceded US attack on Venezuela’ theory

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

AI-built Rue language pairs Rust memory safety with ease of use
Smashing Security podcast #449: How to scam someone in seven days
IBM’s AI agent Bob easily duped to run malware, researchers show
ESA calls cops as crims lift off 500 GB of files, say security black hole still open
Stalkerware slinger pleads guilty for selling snooper software to suspicious spouses
Microsoft scraps Exchange Online spam clamp after customers cry foul
Red Hat Hybrid Cloud Console: Your questions answered
Ministry of Justice splurged £50M on security – still missed Legal Aid Agency cyberattack
Jaguar Land Rover wholesale volumes plummet 43% in cyberattack aftermath
Microsoft acquires Osmos to ease data engineering bottlenecks in Fabric
HSBC app takes a dim view of sideloaded Bitwarden installations
Generative UI: The AI agent is the front end
What the loom tells us about AI and coding

An update that solves three vulnerabilities and has two security fixes can now be installed.

An update that solves three vulnerabilities and has two security fixes can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

MGAA-2026-0003 – Updated isodumper packages fix bugs

MGAA-2026-0002 – Updated sddm-theme-coffee-ng packages fix bug

AI won’t replace human devs for at least 5 years
Automated data poisoning proposed as a solution for AI theft threat
Red Team Blue Team Insights for Linux Admins: Key Security Roles Explained
HackerOne ‘ghosted’ me for months over $8,500 bug bounty, says researcher

https://security-tracker.debian.org/tracker/DSA-6095-1

Ruby 4.0.0 introduces ZJIT compiler, Ruby Box isolation
Brightspeed investigates breach as crims post stolen data for sale

https://security-tracker.debian.org/tracker/DSA-6094-1

Fake Windows BSODs check in at Europe’s hotels to con staff into running malware
Crypto wallet shop Ledger confirms customer data lifted in Global-e snafu
Open WebUI bug turns the ‘free model’ into an enterprise backdoor
Students bag extended Christmas break after cyber hit on school IT
UK injects just £210M into cyber plan to stop Whitehall getting pwnd
Generative AI and the future of databases
What drives your cloud security strategy?
Coinbase insider who sold customer data to criminals arrested in India

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

One criminal, 50 hacked organizations, and all because MFA wasn’t turned on

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

C# wins Tiobe Programming Language of the Year honors for 2025

https://security-tracker.debian.org/tracker/DSA-6093-1

Congrats, cybercrims: You just fell into a honeypot

An update that solves 70 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

Moderate: postgresql:15 security update

Playing Koi: Palo Alto isn’t saying if it will buy security start-up
Gmail preparing to drop POP3 mail fetching
New Zealand orders review into ManageMyHealth cyberattack
6 incredibly hyped software trends that failed to deliver
How to make AI agents reliable

A vulnerability was found in Curl, an easy-to-use client-side URL transfer library and command line tool. It can cause a crash or potentially a memory out of bounds read. For Debian 11 bullseye, this problem has been fixed in version 7.74.0-1.3+deb11u16.

Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed XCF, JPEG 2000 or PNM files are opened. For the oldstable distribution (bookworm), these problems have been fixed

Trump admin sends heart emoji to commercial spyware makers with lifted Predator sanctions
Palo Alto Networks security-intel boss calls AI agents 2026’s biggest insider threat

Update to 1.148.0

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Bitfinex crypto thief who was serving five years thanks Trump for early release
Cybercrook claims to be selling infrastructure info about three major US utilities
Brit lands invite-only Aussie visa after uncovering vuln in government systems
LockBit takedown architect gets New Year award from King Charles
Back to the future: The most popular JavaScript stories and themes of 2025
Cisco XDR in 30: Turning Security Signals Into Confident Action

https://github.com/wb2osz/direwolf/releases/tag/1.8.1

Correctly handle the program name passed to the sleep disabler. Ensure GStreamer is initialized before using the Quirks. Fix several crashes and rendering issues. Fix CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531, CVE-2025-43535, CVE-2025-43536, CVE-2025-43541

Update to 2.83.2

Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442

https://github.com/wb2osz/direwolf/releases/tag/1.8.1

Two vulnerabilities were discovered in smb4k, a KDE desktop utility which allows unprivileged mounting of Samba/CIFS network shares, which may result in local denial of service or local privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 4.0.0-1+deb13u1.

What is cloud computing? From infrastructure to autonomous, agentic-driven ecosystems
Enterprise Spotlight: Setting the 2026 IT agenda
What’s next for Azure containers?
Critical vulnerability in IBM API Connect could allow authentication bypass

Rebuilt for CVE-2025-47906

Rebuilt for CVEs