Menu

Monthly Archives: February 2026

Denizens of DEF CON are ‘fed up with government’
This month in security with Tony Anscombe – February 2026 edition

In this roundup, Tony looks at how opportunistic threat actors are taking advantage of weak authentication, unmanaged exposure, and popular AI tools

What Is ClamAV? A Linux Admins Guide to Risk, Monitoring, and Real-World Use

https://security-tracker.debian.org/tracker/DSA-6152-1

Double whammy: Steaelite RAT bundles data theft, ransomware in one evil tool
Suspected Nork digital intruders caught breaking into US healthcare, education orgs
Ransomware payments cratered in 2025, but attacks surged to record highs
French DIY etailer ManoMano admits customer data stolen
Cops back Dutch telco Odido after second wave of ShinyHunters leaks
Mobile app permissions (still) matter more than you may think

Start using a new app and you’ll often be asked to grant it permissions. But blindly accepting them could expose you to serious privacy and security risks.

Your staff are your biggest security risk: AI is making it worse
Rapid AI-driven development makes security unattainable, warns Veracode
Notorious ransomware gang allegedly blackmailed by fake FSB officer
Scattered Lapsus$ Hunters auditioning female voices to sharpen social engineering
Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover
Understanding the Snort NIDS: What It Changes in Your Monitoring and Risk Model
Claude collaboration tools left the door wide open to remote code execution
Smashing Security podcast #456: How to lose friends and DDoS people

https://security-tracker.debian.org/tracker/DSA-6151-1

https://security-tracker.debian.org/tracker/DSA-6150-1

https://security-tracker.debian.org/tracker/DSA-6149-1

The nervous system gets a soul: why sovereign cloud is telco’s real second act
Google catches Beijing spies using Sheets to spread espionage across 4 continents
Fake ‘interview’ repos lure Next.js devs into running secret-stealing malware
Ex-L3Harris exec jailed 7 years for selling exploits to Russia
Wynn Resorts takes attacker’s word for it that stolen staff data was deleted
OpenAI says Chinese cops used ChatGPT to plan and track smear ops against opponents
$10,000 bounty offered if you can hack Ring cameras to stop them sharing your data with Amazon
Threat intelligence supply chain is full of weak links, researchers find
What Is Fail2ban?

https://security-tracker.debian.org/tracker/DSA-6148-1

MCP security: The current situation
AI has gotten good at finding bugs, not so good at swatting them
Patch these 4 critical, make-me-root SolarWinds bugs ASAP
North Korea’s Lazarus Group targets healthcare orgs with Medusa ransomware
Go library maintainer brands GitHub’s Dependabot a ‘noise machine’
UK data watchdog fines Reddit £14.47M for letting kids slip past the gate
Korean cops charge teens over bike hire breach that exposed data on 4.62M riders
Faking it on the phone: How to tell if a voice call is AI or not

Can you believe your ears? Increasingly, the answer is no. Here’s what’s at stake for your business, and how to beat the deepfakers.

Spanish police say they have arrested hacker who booked luxury hotel rooms for just one cent
PromptSpy ushers in the era of Android threats using GenAI

ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow

Is Poshmark safe? How to buy and sell without getting scammed

Like any other marketplace, the social commerce platform has its share of red flags. It pays to know what to look for so you can shop or sell without headaches.

Smashing Security podcast #455: Face off: Meta’s Glasses and America’s internet kill switch
Dutch police arrest man for “hacking” after accidentally sending him confidential files
Is it OK to let your children post selfies online?

When it comes to our children’s digital lives, prohibition rarely works. It’s our responsibility to help them build a healthy relationship with tech.

Zero CVEs: The symptom of a larger problem
Extend trust across the software supply chain with Red Hat trusted libraries
Chasing the holy grail: Why Red Hat’s Hummingbird project aims for “near zero” CVEs
Urgent warnings from UK and US cyber agencies after Polish energy grid attack
Naming and shaming: How ransomware groups tighten the screws on victims

When corporate data is exposed on a dedicated leak site, the consequences linger long after the attack fades from the news cycle

Polish hacker charged seven years after massive Morele.net data breach
Smashing Security podcast #454: AI was not plotting humanity’s demise. Humans were
From challenge to champion: Elevate your vulnerability management strategy
Taxing times: Top IRS scams to look out for in 2026

It’s time to file your tax return. And cybercriminals are lurking to make an already stressful period even more edgy.

https://security-tracker.debian.org/tracker/DSA-6124-1

More than 135,000 OpenClaw instances exposed to internet in latest vibe-coded disaster
Dutch data watchdog snitches on itself after getting caught in Ivanti zero-day attacks
Taiwan tells Uncle Sam its chip ecosystem ain’t going anywhere
Salesforce may be prepping to phase out Heroku
How the GNU C Compiler became the Clippy of cryptography
Follow the money: Switzerland remains Europe’s top destination for tech pay
European Commission probes intrusion into staff mobile management backend
AI-augmented data quality engineering

Several security issues were fixed in pip.

An update that solves 76 vulnerabilities and contains one feature can now be installed.

An update that solves 76 vulnerabilities and contains one feature can now be installed.

An update that solves one vulnerability can now be installed.

Indian police commissioner wants ID cards for AI agents

Update to version 1.2026.1

Update to 1.10.2 Update was blocked by a ppc64 issue, but a workaround has been found.

https://security-tracker.debian.org/tracker/DSA-6127-1

https://security-tracker.debian.org/tracker/DSA-6126-1

https://security-tracker.debian.org/tracker/DSA-6125-1

Telcos aren’t saying how they fought back against China’s Salt Typhoon attacks
AI insights with actionable automation accelerate the journey to autonomous networks

Update to 144.0.7559.132 * CVE-2026-1861: Heap buffer overflow in libvpx * CVE-2026-1862: Type Confusion in V8

Update to version 0.50.18

Backport fixes for CVE-2026-1484, CVE-2026-1485, CVE-2026-1489.

Update to version 1.9.2. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.9.2

Release notes for xrdp v0.10.5 (2026/01/27) Security fixes CVE-2025-68670: Improper bounds checking of domain string length leads to Stack- based Buffer Overflow New features

Release notes for xrdp v0.10.5 (2026/01/27) Security fixes CVE-2025-68670: Improper bounds checking of domain string length leads to Stack- based Buffer Overflow New features

Fake Dubai Crown Prince tracked to Nigerian mansion after $2.5M romance scam
Study confirms experience beats youthful enthusiasm

Denis Skvortsov discovered that xrdp, a Remote Desktop Protocol (RDP) server, was susceptible to an unauthenticated stack-based buffer overflow vulnerability, which may result in remote execution of arbitrary code. For the oldstable distribution (bookworm), this problem has been fixed

What Is TLS (Transport Layer Security) in Linux Security?

Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY.

Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY.

Update to 13.0.10.

An update that fixes one vulnerability, contains one feature is now available.

https://security-tracker.debian.org/tracker/DSA-6123-1

Sudo, a program designed to allow a sysadmin to give limited root privileges to users and log root activity, was affected by multiple vulnerabilities. CVE-2023-28486 Sudo did not escape control characters in log messages.

Microsoft bumps .NET Framework 3.5 from Windows installers

https://security-tracker.debian.org/tracker/DSA-6122-1

https://security-tracker.debian.org/tracker/DSA-6121-1

https://security-tracker.debian.org/tracker/DSA-6120-1

https://security-tracker.debian.org/tracker/DSA-6119-1

Flickr emails users about data breach, pins it on 3rd party
DDoS deluge: Brit biz battered as botnet blitzes break records
Claude AI finds 500 high-severity software vulnerabilities
Python everywhere—but are we there yet?