Menu

Monthly Archives: March 2026

Update to new release, includes updated dependencies that fix for a number of CVEs

Rogue AI agents can work together to hack systems and steal secrets
Gemini CLI introduces plan mode

https://security-tracker.debian.org/tracker/DSA-6160-1

JetBrains unveils AI tracing library for Kotlin and Java
Why Postgres® has won as the de facto database: Today and for the agentic future
Operating Lightning takes down SocksEscort proxy network blamed for tens of millions in fraud
CISA warns max-severity n8n bug is being exploited in the wild

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

Your Signal account is safe – unless you fall for this trick
What’s missing from AI-assisted software development
Running agents in Amazon Bedrock AgentCore
Nvidia launches Nemotron 3 Super to power enterprise AI agents

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 37 vulnerabilities can now be installed.

An update that solves 37 vulnerabilities can now be installed.

Databricks buys Quotient AI to boost enterprise‑grade AI agent performance
China’s CERT warns OpenClaw can inflict nasty wounds
Smashing Security podcast #458: How not to steal $46 million from the US government
Iran plots ‘infrastructure warfare’ against US tech giants
Microsoft’s .NET 11 Preview 2 offers cleaner stack traces

https://security-tracker.debian.org/tracker/DSA-6159-1

Iran-linked cyber crew says they hit US med-tech firm
Sednit reloaded: Back in the trenches

The resurgence of one of Russia’s most notorious APT groups

Meta, international cops use handcuffs and AI to stop scammers
ICO fines Police Scotland over data-sharing debacle in gross misconduct case
Oracle rejects request it give up control of MySQL
Swiss e-voting pilot can’t count 2,048 ballots after USB keys fail to decrypt them
Dutch cops bust teen suspected of posing as bank staff to steal cards
EU legal eagle says banks should refund cybercrime victims first, argue later

GeoPandas could be vulnerable to SQL injection attacks.

Drive business productivity through open collaboration, AI and document creation
Building the UK’s next generation of cyber talent
First look: Electrobun for TypeScript-powered desktop apps
An LLM that will help you build a nuclear weapon
Pity the developers who resist agentic coding

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Amazon is linking site hiccups to AI efforts

0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS

0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS

Claude Code adds code reviews

https://security-tracker.debian.org/tracker/DSA-6158-1

TypeScript 6.0 reaches release candidate stage
Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack
Cybercrime isn’t just a cover for Iran’s government goons – it’s a key part of their operations
Crooks compromise WordPress sites to push infostealers via fake CAPTCHA prompts
Twitter suspended 800 million accounts last year – so why does manipulation remain so rampant?
JetBrains launches Air and Junie CLI for AI-assisted development
Fake job applications pack malware that kills EDR before stealing data

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

Ericsson blames vendor vishing slip-up for breach exposing thousands of records
Protecting democracy means democratizing cybersecurity. Bring on the hackers
Polish cops bust alleged teen DDoS kit sellers – youngest just 12
MariaDB taps GridGain to keep pace with AI-driven data demands
5 requirements for using MCP servers to connect AI agents
How developers can bring voice AI into telephony applications
Neoclouds run AI cheaper and better
Port Scanning Explained: Tools, Techniques, and Best Open-Source Port Scanners for Linux

Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools

Update to 1.3.2.

Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. Current versions of the module strip leading zeros from octets.

Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools

AI vs AI: Agent hacked McKinsey’s chatbot and gained full read-write access in just two hours
Ruby sinking in popularity, buried by Python – Tiobe
ShinyHunters claims more high-profile victims in latest Salesforce customers data heist
EV charger biz ELECQ zapped by ransomware crooks, customer contact data stolen
Dutch cops warn 100 alleged scammers: Turn yourselves in or we tell Grandma
Russian cybercrims phish their way into officials’ Signal and WhatsApp accounts
Microsoft Azure CTO set Claude on his 1986 Apple II code, says it found vulns
Anthropic debuts Claude Marketplace to target AI procurement bottlenecks
How generative UI cut our development time from months to weeks
Royal Navy races to arm ships against drone threat
19 large language models for safety or danger
Coding for agents

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves six vulnerabilities can now be installed.

Iran is the first out-loud cyberwar the US has fought
FBI is investigating breach that may have hit its wiretapping tools

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

AI agents now help attackers, including North Korea, manage their drudge work
What cybersecurity actually does for your business

The ability to continue operating safely in an unsafe environment where competitors cannot is a competitive advantage that is rarely measured or discussed

Update to 145.0.7632.116 * CVE-2026-3061: Out of bounds read in Media * CVE-2026-3062: Out of bounds read and write in Tint * CVE-2026-3063: Inappropriate implementation in DevTools

Update to 2.87.3

Update to 2.69.4

Rename from golang-github-prometheus and upgrade to 3.10.0

hex_core ver. 0.12.2