Menu

Monthly Archives: May 2026

Suspected Dream Market kingpin arrested after gold bars sent to his home address
Anthropic puts Claude agents on a meter across its subscriptions

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), this problem has been fixed in version 7:7.1.4-0+deb13u1.

nginx could be made to crash or run programs if it received specially crafted network traffic.

Important: jq security update

Important: kernel security update

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed in version 1:140.10.2esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in

Important: jq security update

Cops arrest man suspected of being Dream Market kingpin
Dirty Frag gets a sequel as Fragnesia hands Linux attackers root-level access
When ransomware gets physical: cybercriminals turn to threats of violence
Notion courts developers with a platform for AI agents and workflow automation
Using continuous purple teaming to protect fast-paced enterprise environments
A better way to work with SQL Server
Evidence-driven workflows: Rethinking enterprise process design
RubyGems Attack Highlights Open Source Supply Chain Risks for Linux Teams
Why CI/CD Pipelines Became Targets in Software Supply Chain Attacks
To gain root access at this company, all an intruder had to do was ask nicely
AI models are getting better at replacing cybersecurity pros on certain tasks
Cisco to fire 4,000 staff and generously give them free training – on Cisco

https://security-tracker.debian.org/tracker/DSA-6271-1

https://security-tracker.debian.org/tracker/DSA-6270-1

https://security-tracker.debian.org/tracker/DSA-6269-1

https://security-tracker.debian.org/tracker/DSA-6268-1

https://security-tracker.debian.org/tracker/DSA-6267-1

https://security-tracker.debian.org/tracker/DSA-6266-1

Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits
Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities
AWS to Quick admins: The access control didn’t work, but you weren’t using it anyway, so what’s the problem?
Bug hunter tracks down three massive MCP flaws and one vendor won’t fix theirs
Mystery Microsoft bug leaker keeps the zero-days coming
The path to zero trust: Bridging the gap between AI development and OpSec
AWS debuts Graviton-powered Redshift RG instances to cut analytics costs

Moderate: freerdp security update

Important: openexr security update

Moderate: glib2 security update

Moderate: libsoup3 security update

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

SAP’s AI promises last year? Most are still rolling out
Securing Remote Access to Linux Servers: Best Practices for 2026
First look: Lemonade serves up local AI with limitations
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
Vietnam to develop domestic cloud so it can ditch risky overseas operators for government workloads
AI is ready to take over Python programming, but not much else
Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs
Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files
Eyes wide open: How to mitigate the security and privacy risks of smart glasses

Smart glasses allow anyone to track and record the world around them. That could put your data and the privacy of those nearby at risk.

Mistral AI SDK, TanStack Router hit in npm software supply chain attack
GitLab CEO sees developer tool bill increasing 100-fold
US bank reports itself after slinging customer data at ‘unauthorized AI app’
Why Runtime Monitoring Is Replacing Traditional Linux Logging
Debian 14 Makes Reproducible Builds Mandatory for Linux Packages
Linux AI Tools Require Enhanced Observability for Security
Red Hat adds support for agentic AI development
Cache-poisoning caper turns TanStack npm packages toxic
Apple, Google drag cross-platform texting into the encrypted age

Several security issues were fixed in ImageMagick.

What’s new and exciting in JDK 26
Kill the loading spinner with local-first data and reactive SQL
A networking revolution at AWS
Tokenmaxxing is super dumb
Japan’s PM orders cybersecurity review to stop Mythos going full CyberZilla

Update NSS to 3.122.2 Updated to Firefox 150.0.1

Update to 148.0.7778.96 CVE-2026-7896: Integer overflow in Blink CVE-2026-7897: Use after free in Mobile CVE-2026-7898: Use after free in Chromoting CVE-2026-7899: Out of bounds read and write in V8

Update NSS to 3.122.2 Updated to Firefox 150.0.1

Update NSS to 3.122.2 Update to Firefox 150.0.1

Update NSS to 3.122.2 Update to Firefox 150.0.1

https://security-tracker.debian.org/tracker/DSA-6265-1

Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline
Cookie thieves caught stealing dev secrets via fake Claude Code installers
Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator
BWH Hotels guests warned after reservation data checks out with cybercrooks
Why Linux Servers Get Hacked More Often Than People Think
Linux Could Soon Disable Vulnerabilities Without a Reboot: Kernel Killswitch
Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads
Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged

Moderate: libpng security update

Moderate: freeipmi security update

Moderate: libpng security update

How to add AI to an existing product (without annoying users)
Your AI doesn’t need another database

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

Taiwan’s train cyber-trauma reveals a global system that’s coming off the tracks

https://security-tracker.debian.org/tracker/DSA-6264-1

https://security-tracker.debian.org/tracker/DSA-6263-1

https://security-tracker.debian.org/tracker/DSA-6262-1

https://security-tracker.debian.org/tracker/DSA-6261-1

https://security-tracker.debian.org/tracker/DSA-6260-1

Two security vulnerabilities were discovered in the Corosync cluster engine, which could result in denial of service or memory disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 3.1.7-1+deb12u2. For the stable distribution (trixie), these problems have been fixed in

Multiple security vulnerabilities were discovered in Tor, a connection- based low-latency anonymous communication system, which could result in denial of service. For the oldstable distribution (bookworm), these problems have been fixed in version 0.4.9.8-0+deb12u1.

MGASA-2026-0126 – Updated openvpn packages fix security vulnerabilities

33.0.3 Release

Update to .NET SDK 10.0.107 and Runtime 10.0.7 Fixes: CVE-2026-40372 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.7/10.0.107.md

This is new version of exim fixing some security bugs.

Linux Firewall Rules Management Challenges Kubernetes Security

It was discovered that PyJWT, a Python implementation of JSON web tokens insufficiently validated the “crit” header parameter, which could result in incomplete enforcement of authentication settings. For the oldstable distribution (bookworm), this problem has been fixed in version 2.6.0-1+deb12u1.

A security vulnerability has been discovered in libpng, a library implementing an interface for reading and writing PNG (Portable Network Graphics) files, which could leading to corrupted chunk data and potential heap information disclosure. For Debian 11 bullseye, this problem has been fixed in version