Menu

Monthly Archives: March 2026

Rename from golang-honnef-tools and update to 2026.1

MCP C# SDK 1.0 arrives with improved authorization server discovery
Firefox taps Anthropic AI bug hunter, but rancid RAM still flipping bits
Spyware disguised as emergency-alert app sent to Israeli smartphones
How hackers bypassed MFA with a $120 phishing kit – until a global takedown shut it down
Cisco warns of two more SD-WAN bugs under active attack
Microsoft spots ClickFix campaign getting users to self-pwn on Windows Terminal
Son of government contractor arrested after alleged $46M crypto heist from US Marshals
Microsoft finally gets around to fixing Windows 10 Recovery Environment after breaking it in October
Microsoft finally gets around to fixing Windows 10 Recovery Environment after breaking it in October
Transport for London says 2024 breach affected 7M customers, not 5,000
Transport for London says 2024 breach affected 7M customers, not 5,000
Why enterprises are still bad at multicloud
Why local-first matters for JavaScript

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 145.0.7632.159-1~deb12u1.

Important: postgresql16 security update

Important: postgresql16 security update

Rust 1.94 arrives with array windows to iterate slices
Google says spyware makers and China-linked groups dominated zero-day attacks last year
Google says spyware makers and China-linked groups dominated zero-day attacks last year
Visual Studio Code previews agent plugins
Iran intelligence backdoored US bank, airport, software outfit networks
Iran intelligence backdoored US bank, airport, software outfit networks
UK watchdog eyes Meta’s smart glasses after workers say they ‘see everything’
UK watchdog eyes Meta’s smart glasses after workers say they ‘see everything’
How SMBs use threat research and MDR to build a defensive edge

We speak to Director of ESET Threat Research Jean-Ian Boutin about where solutions that blend advanced technology with human expertise provide the most practical value for businesses

What I learned as an undercover agent on Moltbook
The revenge of SQL: How a 50-year-old language reinvents itself
OpenAI developing GitHub rival as AI coding platform race intensifies
Smashing Security podcast #457: How a cybersecurity boss framed his own employee
WebAssembly proposal touted to improve Wasm web integration

https://security-tracker.debian.org/tracker/DSA-6157-1

MCP security: Implementing robust authentication and authorization
‘Hundreds’ of Iranian hacking attempts have hit surveillance cameras since the missile strikes
‘Hundreds’ of Iranian hacking attempts have hit surveillance cameras since the missile strikes
Malware-laced OpenClaw installers get Bing AI search boost
LexisNexis confirms data breach at Legal & Professional arm, some customer records affected
Kaspersky dismisses claims Coruna iPhone exploit kit is connected to NSA-linked operation
Linux Security Strategies for Cloud and IoT Environments
Protecting education: How MDR can tip the balance in favor of schools

The education sector is notoriously short on cash, but rich in assets for threat actors to target. How can managed detection and response (MDR) help learning institutions regain the initiative?

What I learned using Claude Sonnet to migrate Python to Rust
The right way to architect modern web applications
An ode to craftsmanship in software development
Google feels the need for security speed, so will ship Chrome updates every two weeks
Angular releases patches for SSR security issues
Dev stunned by $82K Gemini bill after unknown API key thief goes to town
Postman API platform adds AI-native, Git-based workflows
Chat at your own risk! Data brokers are selling deeply personal bot transcripts
Cyberwarriors elevated to big leagues in US war with Iran
They seized $4.8m in crypto… then gave the master key to the internet
Turns out most cybercriminals are old enough to know better
Until last month, attackers could’ve stolen info from Perplexity Comet users just by sending a calendar invite
Chrome Gemini panel became privilege escalator for rogue extensions
Cybercriminals swipe 15.8M medical records from French doctors ministry
Why AI requires rethinking the storage-compute divide
Under the hood with .NET 11 Preview 1
Cloud architects earn the highest salaries
Gamers furious as indie studio Cloud Imperium quietly admits to data breach
Phish of the day: Microsoft OAuth scams abuse redirects for malware delivery

https://security-tracker.debian.org/tracker/DSA-6156-1

https://security-tracker.debian.org/tracker/DSA-6155-1

Rust developers have three big worries – survey
Iran’s cyberwar has begun
UK businesses told to brace cyber defenses amid Iran conflict risk
Buyer’s guide: Comparing the leading cloud data platforms
Memory scalpers hunt scarce DRAM with bot blitz
Scammers try to SIM-swap Dubai citizens hours after Iranian missile strikes
FinOps for agents: Loop limits, tool-call caps and the new unit economics of agentic SaaS
AI makes networking matter again
UK government’s Vulnerability Monitoring System is working – fixes flow far faster
South Korea’s tax office apologizes for leaking seed phrase to seized crypto

https://security-tracker.debian.org/tracker/DSA-6154-1

AI trust through open collaboration: A new chapter for responsible innovation

https://security-tracker.debian.org/tracker/DSA-6153-1