Menu

Monthly Archives: February 2026

Windows PCs fade away

MGASA-2026-0032 – Updated python-django packages fix security vulnerabilities

MGAA-2026-0011 – Updated yt-dlp packages fix bugs

Google unveils API and MCP server for developer documentation

This update bumps the bundled lodash to 4.17.23 to ensure openQA is protected against CVE-2025-13465. It likely was not vulnerable in any case, though, as I don’t believe the vulnerable codepaths were exposed by openQA’s use of lodash.

Regenerate vendor tarball. Fixes CVE-2025-13465.

Regenerate vendor tarball. Fixes CVE-2025-13465.

Version 12.5.8 – 2026-01-27 Changed To prevent Poisoned Pipeline Execution (PPE) attacks using prepared .coverage files in pull requests, a PHPT test will no longer be run if the temporary file for writing code coverage information already exists before the test runs

Ad blocking is alive and well, despite Chrome’s attempts to make it harder
OpenClaw reveals meaty personal information after simple cracks
Visual Studio Code update shines on coding agents
OfferUp scammers are out in force: Here’s what you should know

The mobile marketplace app has a growing number of users, but not all of them are genuine. Watch out for these common scams.

Incognito Market admin sentenced to 30 years for running $105 million dark web drug empire
Substack says intruder lifted emails, phone numbers in months-old breach
Asia-based government spies quietly broke into critical networks across 37 countries
Betterment breach may expose 1.4M users after social engineering attack

Multiple vulnerabilities were discovered in containerd, an open-source container runtime, used by e.g. Docker or Kubernetes. CVE-2024-25621 Overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri`

What’s new in post-quantum cryptography in RHEL 10.1
IT automation with agentic AI: Introducing the MCP server for Red Hat Ansible Automation Platform
Italy claims cyberattacks ‘of Russian origin’ are pelting Winter Olympics
n8n security woes roll on as new critical flaws bypass December fix
Cloud sovereignty is no longer just a public sector concern
Databricks adds MemAlign to MLflow to cut cost and latency of LLM evaluation
The ‘Super Bowl’ standard: Architecting distributed systems for massive concurrency
How to reduce the risks of AI-generated code
Beyond NPM: What you need to know about JSR
What is context engineering? And why it’s the new AI architecture
Deno Sandbox launched for running AI-generated code
Three clues that your LLM may be poisoned with a sleeper-agent back door

MGAA-2026-0010 – Updated libformula & ant-contrib packages fix bug

Satya Nadella decides Microsoft needs an engineering quality czar
What Is AppArmor? A Practical Look for Linux Admins

Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution

Regenerate vendor tarball. Fixes CVE-2025-13465.

Regenerate vendor tarball. Fixes CVE-2025-13465.

Version 12.5.8 – 2026-01-27 Changed To prevent Poisoned Pipeline Execution (PPE) attacks using prepared .coverage files in pull requests, a PHPT test will no longer be run if the temporary file for writing code coverage information already exists before the test runs

Smashing Security podcast #453: The Epstein Files didn’t hide this hacker very well

https://security-tracker.debian.org/tracker/DSA-6118-1

AWS intruder achieved admin access in under 10 minutes thanks to AI assist, researchers say
Apple’s Xcode 26.3 brings integrated support for agentic coding
Critical SolarWinds Web Help Desk bug under attack
Nitrogen ransomware is so broken even the crooks can’t unlock your files
GitHub eyes restrictions on pull requests to rein in AI-based code deluge on maintainers
Universal £7,500 payout offered to PSNI staff over major data breach
Azure outage disrupts VMs and identity services for over 10 hours
4 self-contained databases for your apps
AI is not coming for your developer job
Six reasons to use coding agents

A security issue was discovered in Thunderbird, which could result in information disclosure. For Debian 11 bullseye, this problem has been fixed in version 1:140.7.1esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

Several security issues were fixed in ImageMagick.

Several security issues were fixed in MySQL.

Clouds rush to deliver OpenClaw-as-a-service offerings

MGAA-2026-0009 – Updated subversion packages fix bug

What Is SELinux? A Practical Take for Linux Admins
Vercel revamps AI-powered v0 development platform
AI agents can’t yet pull off fully autonomous cyberattacks – but they are already very helpful to crims
Critical React Native Metro dev server bug under attack as researchers scream into the void
CISA updated ransomware intel on 59 bugs last year without telling defenders
A slippery slope: Beware of Winter Olympics scams and other cyberthreats

It’s snow joke – sporting events are a big draw for cybercriminals. Make sure you’re not on the losing side by following these best practices.

X marks the raid: French cops swoop on Musk’s Paris ops
Microsoft finally sends TLS 1.0 and 1.1 to the cloud retirement home
Polish cops bail 20-year-old bedroom botnet operator
DIY AI bot farm OpenClaw is a security ‘dumpster fire’
British military to get legal OK to swat drones near bases

xrdp is an open source RDP server. It was found that xrdp contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code

Several security issues were fixed in CRaC JDK 21.

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 8.

Several security issues were fixed in OpenJDK 11.

15.x 15.1 (2026-01-24) Fix #15088: When building a new train, the refit button state may be incorrect (#15162) Fix #15160: Incorrect company names displayed in load game window (#15161)

Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor
StopICE hacked to send alarming text messages, admins accuse border patrol agent of sabotage
Russia-linked APT28 attackers already abusing new Microsoft Office zero-day
McDonald’s is not lovin’ your bigmac, happymeal, and mcnuggets passwords
OpenClaw patches one-click RCE as security Whac-A-Mole continues
Notepad++ update service hijacked in targeted state-linked attack

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Infrastructure cyberattacks are suddenly in fashion. We can buck the trend
How should AI agents consume external data?
AI will not save developer productivity

An update that solves five vulnerabilities and contains one feature can now be installed.

An update that solves five vulnerabilities and contains one feature can now be installed.

An update that solves three vulnerabilities can now be installed.

Why native cloud security falls short

An update that fixes one vulnerability is now available.

Open-source AI is a global security nightmare waiting to happen, say researchers
Enterprise Spotlight: Manufacturing Reimagined
AI security startup CEO posts a job. Deepfake candidate applies, inner turmoil ensues.

Multiple vulnerabilities have been found in Pillow, an image processing library for Python. CVE-2021-23437 The getrgb function is susceptible to a ReDoS. CVE-2022-24303

Ceph is a distributed object, block, and file storage platform. CVE-2022-0670 A flaw was found in Openstack manilla owning a Ceph File system “share”, which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the

Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2025-67724 Custom reason phrases can cause multiple vulnerabilities (like XSS, header injection, …) due to being used unescaped in HTTP headers.

Security fix for CVE-2026-24049

Update to 0.46.3, fixes CVE-2026-24049.

Fix CVE-2025-15536