In this roundup, Tony looks at how opportunistic threat actors are taking advantage of weak authentication, unmanaged exposure, and popular AI tools
https://security-tracker.debian.org/tracker/DSA-6152-1
Start using a new app and you’ll often be asked to grant it permissions. But blindly accepting them could expose you to serious privacy and security risks.
https://security-tracker.debian.org/tracker/DSA-6151-1
https://security-tracker.debian.org/tracker/DSA-6150-1
https://security-tracker.debian.org/tracker/DSA-6149-1
https://security-tracker.debian.org/tracker/DSA-6148-1
Can you believe your ears? Increasingly, the answer is no. Here’s what’s at stake for your business, and how to beat the deepfakers.
ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow
Like any other marketplace, the social commerce platform has its share of red flags. It pays to know what to look for so you can shop or sell without headaches.
When it comes to our children’s digital lives, prohibition rarely works. It’s our responsibility to help them build a healthy relationship with tech.
When corporate data is exposed on a dedicated leak site, the consequences linger long after the attack fades from the news cycle
It’s time to file your tax return. And cybercriminals are lurking to make an already stressful period even more edgy.
https://security-tracker.debian.org/tracker/DSA-6124-1
Several security issues were fixed in pip.
An update that solves 76 vulnerabilities and contains one feature can now be installed.
An update that solves 76 vulnerabilities and contains one feature can now be installed.
An update that solves one vulnerability can now be installed.
Update to version 1.2026.1
Update to 1.10.2 Update was blocked by a ppc64 issue, but a workaround has been found.
https://security-tracker.debian.org/tracker/DSA-6127-1
https://security-tracker.debian.org/tracker/DSA-6126-1
https://security-tracker.debian.org/tracker/DSA-6125-1
Update to 144.0.7559.132 * CVE-2026-1861: Heap buffer overflow in libvpx * CVE-2026-1862: Type Confusion in V8
Update to version 0.50.18
Backport fixes for CVE-2026-1484, CVE-2026-1485, CVE-2026-1489.
Update to version 1.9.2. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.9.2
Release notes for xrdp v0.10.5 (2026/01/27) Security fixes CVE-2025-68670: Improper bounds checking of domain string length leads to Stack- based Buffer Overflow New features
Release notes for xrdp v0.10.5 (2026/01/27) Security fixes CVE-2025-68670: Improper bounds checking of domain string length leads to Stack- based Buffer Overflow New features
Denis Skvortsov discovered that xrdp, a Remote Desktop Protocol (RDP) server, was susceptible to an unauthenticated stack-based buffer overflow vulnerability, which may result in remote execution of arbitrary code. For the oldstable distribution (bookworm), this problem has been fixed
Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY.
Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY.
Update to 13.0.10.
An update that fixes one vulnerability, contains one feature is now available.
https://security-tracker.debian.org/tracker/DSA-6123-1
Sudo, a program designed to allow a sysadmin to give limited root privileges to users and log root activity, was affected by multiple vulnerabilities. CVE-2023-28486 Sudo did not escape control characters in log messages.
https://security-tracker.debian.org/tracker/DSA-6122-1
https://security-tracker.debian.org/tracker/DSA-6121-1
https://security-tracker.debian.org/tracker/DSA-6120-1
https://security-tracker.debian.org/tracker/DSA-6119-1
