Menu

Monthly Archives: April 2026

Zephyr Energy loses £700K in cyber hit that rerouted contractor payment
Bringing databases and Kubernetes together
Rethinking Angular forms: A state-first perspective
How Agile practices ensure quality in GenAI-assisted development
Sticky-note security turned gym into hall of ’80s horrors
Cryptographers place $5,000 bet whether quantum will matter
Minimus Welcomes Yael Nardi as CBO to Facilitate Strategic Growth
Visual Studio Code 1.115 introduces VS Code Agents app
Visual Studio Code 1.115 introduces VS Code Agents app
Smashing Security podcast #462: LinkedIn is spying on you, and you agreed to nothing

https://security-tracker.debian.org/tracker/DSA-6201-1

Criminal wannabes even more dangerous than the pros, says ex-FBI cyber chief
Microsoft announces end of support for ASP.NET Core 2.3
As breakout time accelerates, prevention-first cybersecurity takes center stage

Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.

AWS turns its S3 storage service into a file system for AI agents
Dutch healthcare software vendor goes dark after ransomware attack
Z.ai unveils GLM-5.1, enabling AI coding agents to run autonomously for hours
NHS Scotland-linked domains caught serving pr0n and dodgy sports streams
Microsoft’s new Agent Governance Toolkit targets top OWASP risks for AI agents
Get started with Python’s new frozendict type
The winners and losers of AI coding
Microsoft hints at bit bunkers for war zones

Important: fontforge security update

Important: fontforge security update

Moderate: kernel security update

Moderate: crun security update

Moderate: kernel security update

Moderate: crun security update

https://security-tracker.debian.org/tracker/DSA-6202-1

Anthropic: All your zero-days are belong to Mythos
Iran cyber actors disrupting US water, energy facilities, FBI warns
GitHub Copilot CLI adds Rubber Duck review agent

https://security-tracker.debian.org/tracker/DSA-6197-2

Hundreds of orgs compromised daily in Microsoft device code phishing attacks
US cybercrime losses pass $20B for first time as AI boosts online fraud
Russia’s Fancy Bear still attacking routers to boost fake sites, NCSC warns
The Terraform scaling problem: When infrastructure-as-code becomes infrastructure-as-complexity
Nvidia’s SchedMD acquisition puts open-source AI scheduling under scrutiny
Enterprise developers question Claude Code’s reliability for complex engineering
What enterprise devops teams should learn from SaaS
How to destroy a company quickly
Life imprisonment for Cambodian scam compound operators – but will it make a difference?
Rust team warns of WebAssembly change
Yahoo! Japan’s owner consolidating 164 OpenStack clusters into one

33.0.1 release

Update to 9.6.0. Fixes rhbz#2452087

Moderate: kernel-rt security update

Moderate: kernel-rt security update

Important: python3.12 security update

Moderate: 389-ds:1.4 security update

AI agents found vulns in this popular Linux and Unix print server
Visual Studio Code 1.114 streamlines AI chat
Attackers exploited this critical FortiClient EMS bug as a 0-day
How to choose the best LLM using R and vitals
Databricks launches AiChemy multi-agent AI for drug discovery
27 questions to ask when choosing an LLM
Multi-agent AI is the new microservices
Anthropic cuts OpenClaw access from Claude subscriptions, offers credits to ease transition

An update that solves six vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves three vulnerabilities and has two security fixes can now be installed.

An update that solves eight vulnerabilities can now be installed.

Several security issues were fixed in SPIP.

https://security-tracker.debian.org/tracker/DSA-6196-1

Anthropic sure has a mess on its hands thanks to that Claude Code source leak
Researchers didn’t want to glamorize cybercrims. So they roasted them

Update to 1.94.1

Backport fixes for multiple CVEs.

Update to gstreamer-1.26.11.

Update to gstreamer-1.26.11.

Update to gstreamer-1.26.11.

Update to gstreamer-1.26.11.

https://security-tracker.debian.org/tracker/DSA-6200-1

https://security-tracker.debian.org/tracker/DSA-6199-1

https://security-tracker.debian.org/tracker/DSA-6198-1

https://security-tracker.debian.org/tracker/DSA-6197-1

https://security-tracker.debian.org/tracker/DSA-6195-1

It was discovered that libxml-parser-perl, a Perl module for parsing XML files, was prone to an off-by-one heap buffer overflow in `st_serial_stack()`. This update also includes a follow-up improvement change for CVE-2006-10002 (buffer overwrite in `parse_stream()`.) For Debian 11 bullseye, these problems have been fixed in version

Security fix for CVE-2026-4519

The update fixes CVS-2026-25061

GSSAPI server: Boundary check gss_wrap token (read OOB)

Security fix for CVE-2026-4519.

Security fix for CVE-2026-4519.

Trump wants to take a battle axe to CISA again and slash $707M from budget

https://security-tracker.debian.org/tracker/DSA-6192-1

Internet Bug Bounty program hits pause on payouts
Claude Code is still vulnerable to an attack Anthropic has already fixed
CERT-EU blames Trivy supply chain attack for Europa.eu data breach
Hybrid work, expanded risk: what needs to change
The npm Supply Chain Problem: Why Installing Packages Executes Untrusted Code

It was discovered that pyasn1, a generic ASN.1 library for Python, is prone to a denial of service vulnerability when decoding ASN.1 data with deeply nested structures. For the oldstable distribution (bookworm), this problem has been fixed in version 0.4.8-3+deb12u2.

Several vulnerabilities were discovered in the inetutils implementation of telnetd and telnet, which may result in privilege escalation or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 2:2.4-2+deb12u3.

Google gives enterprises new controls to manage AI inference costs and reliability
Nigerian romance scammer jailed after being caught out by fellow fraudster
Understanding the risks of OpenClaw
Local-first browser data gets real

Update to upstream 2.5.2, including fixes for CVE-2026-33757 and CVE-2026-33758

Update to 9.21.20 (rhbz#2440560) Security Fixes: Fix unbounded NSEC3 iterations when validating referrals to unsigned delegations. (CVE-2026-1519) Fix memory leaks in code preparing DNSSEC proofs of non-existence.

Claude Code leak puts enterprise trust at risk as security, governance concerns mount