Menu

Monthly Archives: April 2026

Raspberry Pi OS ends open-door policy for sudo
108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users
UK told its Big Tech habit is now a national security risk
Tap into the AI APIs of Google Chrome and Microsoft Edge
Where will developer wisdom come from?

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

Agents hooked into GitHub can steal creds – but Anthropic, Google, and Microsoft haven’t warned users
Curity looks to reinvent IAM with runtime authorization for AI agents

https://security-tracker.debian.org/tracker/DSA-6213-1

https://security-tracker.debian.org/tracker/DSA-6212-1

Commvault has a Ctrl+Z for rogue AI agents
Microsoft’s massive Patch Tuesday: It’s raining bugs

https://security-tracker.debian.org/tracker/DSA-6209-1

GitHub adds Stacked PRs to speed complex code reviews
No honor among thieves as 0APT threatens rival ransomware gang Krybit

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Important: fontforge security update

Important: perl-XML-Parser security update

It was discovered that gdk-pixbuf, the GDK Pixbuf library, does not properly validate color component counts in the JPEG image loader, which may result in the execution of arbitrary code or denial of service if specially crafted JPEG images are processed. For Debian 11 bullseye, this problem has been fixed in version

Several security issues were fixed in polkit.

HTMX 4.0: Hypermedia finds a new gear
The hyperscalers are pricing themselves out of AI workloads
Zombie Microsoft bugs rise from the dead, pave way for crims and ransomware scum
Fake Linux leader using Slack to con devs into giving up their secrets
Google Cloud introduces QueryData to help AI agents create reliable database queries
Why Your “Shadow IT” Developer Tools Are the Biggest Risk to Your Linux Systems
Booking.com warns reservation data may have checked out with intruders
Critical flaw in Marimo Python notebook exploited within 10 hours of disclosure
Gym giant Basic-Fit confirms data on a million members stolen in cyberattack
Rockstar Games gets a taste of grand theft data

BIND a popular name server (DNS) was affected by a vulnerability. If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers

NHS pays £46K to prep next Microsoft licensing round
Hands-on with the Google Agent Development Kit
Are AI certifications worth the investment?
AI has to be dull before it can be sexy

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

China wants AI to prepare school lessons and mark homework
Anthropic’s mysterious Mythos AI threatens to upend the infosec world

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure or incomplete permission checks. For the oldstable distribution (bookworm), these problems have been fixed in version 1:1.39.17-1+deb12u2.

Multiple security vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps, which could allow a Flatpak app to delete arbitrary hosts on the host or break out of the sandbox resulting in code execution in the host context. For the stable distribution (trixie), these problems have been fixed in

MGASA-2026-0096 – Updated libpng12 packages fix security vulnerability

MGASA-2026-0095 – Updated tomcat packages fix security vulnerabilities

MGASA-2026-0094 – Updated squid packages fix security vulnerabilities

Moderate: kernel security update

https://security-tracker.debian.org/tracker/DSA-6208-1

https://security-tracker.debian.org/tracker/DSA-6207-1

Recovery scammers hit you when you’re down: Here’s how to avoid a second strike

If you’ve been the victim of fraud, you’re likely already a lead on a ‘sucker list’ – and if you’re not careful, your ordeal may be about to get worse.

Navigating the Mythos-haunted world of platform security
MCP security: Logging and runtime security measures

Important: kea security update

Two different attackers poisoned popular open source tools – and showed us the future of supply chain compromise

Several vulnerabilities were discovered in the inetutils implementation of telnetd and telnet, which may result in privilege escalation or information disclosure. CVE-2026-28372 Ron Ben Yizhak from SafeBreach found that the fix for CVE-2026-24061 was

Hungarian government creds left in the safe hands of ‘FrankLampard’

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 140.9.1esr-1~deb11u1.

https://security-tracker.debian.org/tracker/DSA-6206-1

Swift for Visual Studio Code comes to Open VSX Registry

https://security-tracker.debian.org/tracker/DSA-6204-1

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

AI and cryptocurrency scams are costing Americans billions, FBI reports
CPUID site hijacked to serve malware instead of HWMonitor downloads
AWS targets AI agent sprawl with new Bedrock Agent Registry
Project Glasswing and open source software: The good, the bad, and the ugly
Britain seeks views before it drops the hammer on signal jammers
Cloud degrees are moving online
AI agents aren’t failing. The coordination layer is failing

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

Unpacking AI security in 2026 from experimentation to the agentic era

New upstream release (#2442363) fixing various security issues

Update to latest upstream

Microsoft’s reauthentication snafu cuts off developers globally

https://security-tracker.debian.org/tracker/DSA-6205-1

Anthropic rolls out Claude Managed Agents
Crypto? Huh. Good gawd y’all, what is it good for? $45M in this case
‘Several dozen’ high-value corporations hit by new extortion crew in helpdesk phishing spree
Meta’s Muse Spark: a smaller, faster AI model for broad app deployment
Chevin pulls the handbrake on FleetWave software after security scare
Months-old Adobe Reader zero-day uses PDFs to size up targets
Microsoft locks out VeraCrypt and WireGuard devs, blames verification process
Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

Important: fontforge security update

Moderate: ncurses security update