Menu

Monthly Archives: March 2026

How one man used 10,000 bots to steal $8,000,000 from music artists
Oracle adds pre-built agents to Private Agent Factory in AI Database 26ai
Speed boost your Python programs with new lazy imports
Stop worrying: Instead, imagine software developers’ next great pivot
TypeScript 6.0 arrives

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 146.0.7680.164-1~deb12u1.

Enterprise PCs are unreliable, unpatched, and unloved compared to Macs

Update to release v1.9.1

Update to 146.0.7680.153 * CVE-2026-4439: Out of bounds memory access in WebGL * CVE-2026-4440: Out of bounds read and write in WebGL * CVE-2026-4441: Use after free in Base * CVE-2026-4442: Heap buffer overflow in CSS

Update to version 1.3.1 to fix CVE-2026-28356.

Update to release v1.9.1 Resolves: rhbz#2448053, rhbz#2423997, rhbz#2424031 Upstream fixes

Update to 146.0.7680.153 * CVE-2026-4439: Out of bounds memory access in WebGL * CVE-2026-4440: Out of bounds read and write in WebGL * CVE-2026-4441: Use after free in Base * CVE-2026-4442: Heap buffer overflow in CSS

https://security-tracker.debian.org/tracker/DSA-6177-1

New JetBrains platform manages AI coding agents
EFF has a new boss to lead the fight against privacy-sucking forces of doom
1K+ cloud environments infected following Trivy supply chain attack
LiteLLM loses game of Trivy pursuit, gets compromised
HackerOne slams supplier for delayed breach notice after staff data exposed

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that solves 11 vulnerabilities and has two security fixes can now be installed.

An update that solves 11 vulnerabilities and has two security fixes can now be installed.

An update that solves one vulnerability and has two security fixes can now be installed.

An update that solves one vulnerability and has two security fixes can now be installed.

Country that put backdoors into Cisco routers to spy on world bans foreign routers
New ‘StoatWaffle’ malware auto‑executes attacks on developers
Russian initial access broker who fed ransomware crews gets 81 months in US prison
An architecture for engineering AI context
7 safeguards for observable AI agents
Designing self-healing microservices with recovery-aware redrive frameworks
When Windows 11 sneezes, Azure catches cold
VS Code now updates weekly
Claude attacks were ‘Rorschach test’ for infosec community, scaring former NSA boss
Public-private partnerships vital in disrupting China’s Typhoons, says RSA panel with no government speakers
Lightning-fast exploits make it essential to patch fast, ask questions later

https://security-tracker.debian.org/tracker/DSA-6175-1

Google unleashes Gemini AI agents on the dark web
Smooth criminals talking their way into cloud environments, Google says
US chip testing firm shrugged off ransomware hit as minor – then came the data leak
RSAC 2026: Uncle Sam backs out, and AI agents are everywhere
Microsoft fixes broken Windows update days after vowing fewer broken updates

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The drone swarm is coming, and NATO air defenses are too expensive to cope
How to land a software development job in an AI-focused world
The agent security mess

Net-CIDR could allow unintended access to network services.

Debian Goodies could be made to crash or run programs as your login if it opened a specially crafted file.

# Security update for helm Announcement ID: SUSE-SU-2026:0948-1 Release Date: 2026-03-20T18:07:28Z Rating: important References:

https://security-tracker.debian.org/tracker/DSA-6176-1

Russians are posing as Signal support to launch phishing attacks

https://security-tracker.debian.org/tracker/DSA-6173-1

Jul Blobul discovered that SPIP, a website engine for publishing, is prone to a privilege escalation vulnerability. For the stable distribution (trixie), this problem has been fixed in version 4.4.13+dfsg-0+deb13u1. We recommend that you upgrade your spip packages.

Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

https://security-tracker.debian.org/tracker/DSA-6174-1

https://security-tracker.debian.org/tracker/DSA-6171-1

Move fast and save things: A quick guide to recovering a hacked account

What you do – and how fast – after an account is compromised often matters more than it may seem

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex

Upstream announcements: WordPress 6.9.2 Release WordPress 6.9.3 and 7.0 beta 4 WordPress 6.9.4 Release

Update to 1.73.3; Fixes: RHBZ#2426392, RHBZ#2415186

Update to 0.37.1 (rbhz#2445943) Fixes Denial of Service via malformed Content-Length header (CVE-2026-31870 Reenables 32-bit build Update to 0.37.0 (rhbz#2441656)

Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)

https://security-tracker.debian.org/tracker/DSA-6172-1

Cryptographers engage in war of words over RustSec bug reports and subsequent ban

https://security-tracker.debian.org/tracker/DSA-6170-1

https://security-tracker.debian.org/tracker/DSA-6169-1

OpenAI’s desktop superapp: The end of ChatGPT as we know it?
Google’s Stitch UI design tool is now AI-powered
EDR killers explained: Beyond the drivers

ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers

Stop using AI to submit bug reports, says Google
Denver’s crosswalks hacked to broadcast anti-Trump messages
UK police force presses pause on live facial recognition after study finds racial bias
Feds disrupt monster IoT botnets behind record-breaking DDoS attacks
Jaguar Land Rover’s cyber bailout sets worrying precedent, watchdog warns

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Introducing OpenShift Service Mesh 3.3 with post-quantum cryptography
LeakNet ransomware: what you need to know
Starmer’s digital ID reboot raises same old questions as its Blair-era ancestor
AI optimization: How we cut energy costs in social media recommendation systems
Cloud at 20: Cost, complexity, and control
Google adds vibe design to Stitch UI design tool
While you’re here, could you go out of your way to do an impossible job?

This is the March 2026 release of .NET 10. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.4/10.0.104.md Runtime: https://github.com/dotnet/core/blob/main/release-

CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex

Fix CVE-2026-31812: Bump quinn-proto to 0.11.14 – Closes rhbz#2446359

Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski

OpenAI buys Python tools builder Astral
OpenAI buys non-AI coding startup to help its AI to program

https://security-tracker.debian.org/tracker/DSA-6168-1

Unknown attackers exploit yet another critical SharePoint bug
Google gives Android users a way to install unverified apps if they prove they really, really want to
Lock down Microsoft Intune, feds warn after Stryker attack

An update that solves one vulnerability can now be installed.