Menu

Monthly Archives: March 2026

Don’t open that WhatsApp message, Microsoft warns
Iran targets M365 accounts with password-spraying attacks
CI/CD Pipelines Vulnerabilities in Trusted Execution Paths March 2026
Announcing Red Hat Advanced Cluster Security for Kubernetes 4.10

Several security issues were fixed in Pillow.

Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines
A GitHub tinkerer teaches Claude to talk less, and that may matter more than it seems
How Apache Kafka flexed to support queues
What front-end engineers need to know about AWS
Enterprises demand cloud value
Azure’s new AI modernization tools

An update that solves 25 vulnerabilities can now be installed.

An update that solves 25 vulnerabilities can now be installed.

Several security issues were fixed in pyasn1.

Several security issues were fixed in ImageMagick.

Iranian hackers breach FBI director’s personal email, and post his CV and photos online

MGAA-2026-0024 – Updated zynaddsubfx packages fix bug

OpenAI patches ChatGPT flaw that smuggled data over DNS
Telnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach
Citrix NetScaler bug exploited in days, may be multiple flaws in a trench coat

Multiple vulnerabilities were discovered in asterisk, an Open Source Private Branch Exchange (PBX) and telephony toolkit. CVE-2026-23738 XSS vulnerability in the /httpstatus page. Cookie names/values and GET parameter names/values are rendered without HTML-escaping, allowing

An update that solves 655 vulnerabilities, contains four features and has 57 fixes can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves seven vulnerabilities can now be installed.

Leak reveals Anthropic’s ‘Mythos,’ a powerful AI model aimed at cybersecurity use cases
European Commission admits attackers broke into public web systems, but says little else
How to build an enterprise-grade MCP registry
The starkly uneven reality of enterprise AI adoption
Security contractor blew the whistle on support crew’s viral indifference
US foreign router ban criticized for being ‘industrial policy disguised as cybersecurity’

https://security-tracker.debian.org/tracker/DSA-6187-1

https://security-tracker.debian.org/tracker/DSA-6186-1

https://security-tracker.debian.org/tracker/DSA-6185-1

https://security-tracker.debian.org/tracker/DSA-6184-1

https://security-tracker.debian.org/tracker/DSA-6183-1

MGASA-2026-0073 – Updated python-ujson packages fix security vulnerabilities

MGASA-2026-0072 – Updated strongswan packages fix security vulnerability

Security fix for CVE-2026-4519.

Security fix for CVE-2026-4519.

Rebuilt with rust-tar 0.4.45 for CVE-2026-33056

Rebuilt with rust-tar 0.4.45 for CVE-2026-33056

https://security-tracker.debian.org/tracker/DSA-6181-1

RSAC 2026 wrap-up – Week in security with Tony Anscombe

This year, AI agents took the center stage – as a defensive capability, but more pressingly as a risk many organizations haven’t caught up with

A cunning predator: How Silver Fox preys on Japanese firms this tax season

Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them

AI security: Identity and access control

MGASA-2026-0071 – Updated nodejs packages fix security vulnerabilities

MGASA-2026-0070 – Updated libpng packages fix security vulnerabilities

Update to 146.0.7680.164 * High CVE-2026-4673: Heap buffer overflow in WebAudio * High CVE-2026-4674: Out of bounds read in CSS * High CVE-2026-4675: Heap buffer overflow in WebGL * High CVE-2026-4676: Use after free in Dawn

Update to v2.0.52

Update to 1.23.1

Update to 1.23.1

https://security-tracker.debian.org/tracker/DSA-6182-1

Kotlin 2.3.20 harmonizes with C, JavaScript/Typescript

https://security-tracker.debian.org/tracker/DSA-6180-1

https://security-tracker.debian.org/tracker/DSA-6179-1

Final training of AI models is a fraction of their total cost

An update that solves seven vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

AFC Ajax drops ball as flaws let hackers play admin with tickets and bans
OpenAI adds plugin system to Codex to help enterprises govern AI coding agents
Anthropic throttles Claude subscriptions to meet capacity
Iran war drives urgent need to counter underwater attack drones
On the pleasures and dangers of open source Python
Edge clouds and local data centers reshape IT
Security boffins scoured the web and found hundreds of valid API keys
Context Hub vulnerable to supply chain attacks, says tester
Visual Studio Code previews chat customizations editor

https://security-tracker.debian.org/tracker/DSA-6178-1

World Leaks data extortion: What you need to know
Virtual machines, virtually everywhere – and with real security gaps

Cloud VMs offer unmatched speed, scale and flexibility – all of which could eventually count for little if they’re left to fend for themselves

Databricks pitches Lakewatch as a cheaper SIEM — but is it really?
Brit lawmaker targeted by AI deepfake fails to get answers from US Big Tech
What does “AI security” mean and why does it matter to your business?
Smashing Security podcast #460: Never knock on the door of a nuclear submarine base and ask for a selfie
Google targets AI inference bottlenecks with TurboQuant
UK wants to know if banning under-16s from social media does anything useful
Basic and advanced Java serialization
Rethinking VM data protection in cloud-native environments
Swift 6.3 boosts C interoperability, Android SDK

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

Indian government probes CCTV espionage operation linked to Pakistan

Update to 146.0.7680.164 * High CVE-2026-4673: Heap buffer overflow in WebAudio * High CVE-2026-4674: Out of bounds read in CSS * High CVE-2026-4675: Heap buffer overflow in WebGL * High CVE-2026-4676: Use after free in Dawn

Claude Code AI tool getting auto mode
AI supply chain attacks don’t even require malware…just post poisoned documentation
Scammers have virtual smartphones on speed dial for fraud
Jen Easterly, cybersecurity’s ‘relentless optimist,’ hopes feds come back to RSAC next year
Only Trump can decide when cyberwar turns into real war
Cloud workload security: Mind the gaps

As IT infrastructure expands, visibility and control often lag behind – until an incident forces a reckoning

PyPI warns developers after LiteLLM malware found stealing cloud and CI/CD credentials
Cloudflare launches Dynamic Workers for AI agent execution