Menu

Monthly Archives: May 2026

Two vulnerabilities have been discovered in the Linux kernel that may lead to local privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 6.1.170-3. We recommend that you upgrade your linux packages.

https://security-tracker.debian.org/tracker/DSA-6259-1

https://security-tracker.debian.org/tracker/DSA-6258-1

What happens when engineering teams reorganize around AI agents

Two vulnerabilities have been discovered in the Linux kernel that may lead to local privilege escalation. For Debian 11 bullseye, these problems have been fixed in version 5.10.251-4. We recommend that you upgrade your linux packages.

An update that solves two vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Fake call logs, real payments: How CallPhantom tricks Android users

ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down

Fixing the password problem is as easy as 123456

How come it’s still possible to ‘secure’ an online account with a six-digit string?

Worm rubs out competitor’s malware, then takes control
One in eight UK workers has sold their company passwords, and bosses think it’s fine
Inside Department 4: Russia’s secret school for hackers
Linux Attackers Abuse Admin Tools For Stealthy Intrusions
‘Dirty Frag’ Linux flaw one-ups CopyFail with no patches and public root exploit
Ubuntu Dirty Frag Important Local Privilege Escalation Exploit
Meta U-turns on encryption push for Instagram as DMs go plaintext

Important: git-lfs security update

Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in remote code execution, privilege escalation, denial of service or information disclosure. For Debian 11 bullseye, these problems have been fixed in version 2.4.67-1~deb11u1.

Hackers ate my homework: Educational SaaS Canvas down after cyberattack

Lua could be made to crash or run programs as your login if it opened a specially crafted file.

Meta fights Ofcom over how many billions count as billions
Sri Lanka makes 37 arrests as it raids another scam centre
Python isn’t always easy
When cloud giants meddle in markets
12 model-level deep cuts to slash AI training costs

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes “Content-Length” over “Transfer-Encoding: chunked” when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse

Validate RSA_public_encrypt() result in RSASVE

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes “Content-Length” over “Transfer-Encoding: chunked” when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse

13 new critical holes in JavaScript sandbox allow execution of arbitrary code

https://security-tracker.debian.org/tracker/DSA-6257-1

https://security-tracker.debian.org/tracker/DSA-6256-1

https://security-tracker.debian.org/tracker/DSA-6255-1

https://security-tracker.debian.org/tracker/DSA-6254-1

https://security-tracker.debian.org/tracker/DSA-6253-1

Mozilla boasts Mythos boosted Firefox bug cull

https://security-tracker.debian.org/tracker/DSA-6249-1

The best new features in Python 3.15
Anthropic response to 1-click pwn: Shouldn’t have clicked ‘ok’
Container Security Misconfigurations That Still Go Unnoticed
60% of MD5 password hashes are crackable in under an hour
Teradata launches platform for enterprise AI agents moving beyond pilots
CrackArmor AppArmor Flaws Put Linux Containers and Snap Sandboxes at Risk
Developing a Successful Open Source Security Information Management System

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The network password was a key plot point in one of the most famous movies of all time

Several security issues were fixed in the Linux kernel.

Three skills that matter when AI handles the coding
The hidden cost of front-end complexity
MongoDB targets AI’s retrieval problem

https://security-tracker.debian.org/tracker/DSA-6252-1

https://security-tracker.debian.org/tracker/DSA-6251-1

https://security-tracker.debian.org/tracker/DSA-6250-1

Smashing Security podcast #466: Meta sees everything, Copy Fail, and a deepfake gets hired
ServiceNow clears agents for landing with new AI control tower
Arctic Wolf kicks 250 employees out of the pack to save money for AI
1 in 8 employees totally cool with selling work credentials
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games

Why Linux Supply Chain Attacks Are Becoming a Nightmare for DevOps Teams
Iran cybersnoops still LARPing as ransomware crooks in espionage ops
Linux Systems Running Wireshark May Be Exposed to Remote Attacks
UK age-gating plans risk breaking the internet, privacy groups warn

Important: golang security update

Important: grafana-pcp security update

Moderate: freeipmi security update

Important: grafana security update

Important: dovecot security update

Important: kernel security update

Your Linux Logs Probably Arent Catching Attacks: 2026 Detection Gaps
Building AI apps and agents with Microsoft Foundry
Designing front-end systems for cloud failure
No, AI won’t destroy software development jobs
India orders infosec red alert in case Mythos sparks crime spree

https://security-tracker.debian.org/tracker/DSA-6248-1

Supply-chain attacks take aim at your AI coding agents
Oracle will patch more often to counter AI cybersecurity threat
Attackers are cashing in on fresh ‘CopyFail’ Linux flaw
CVE-2026-31431: How Red Hat Advanced Cluster Security and Red Hat Advanced Cluster Management can help
Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking

An update that solves six vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

ShinyHunters claims dump puts 119K Vimeo emails in the wild
AI finds 20-year-old bugs in PostgreSQL and MariaDB
Romance scammers turn sweet talk into £102M payday

Multiple vulnerabilities have been discovered in libarchive, a multi-format archive and compression C library, which also provides the following command-line tools: bsdcat, bsdcpio, bsdtar and bsdunzip. CVE-2026-4111 A flaw was identified in the RAR5 archive decompression logic of the

NHS to close-source hundreds of GitHub repos over AI, security concerns
Diskless databases: What happens when storage isn’t the bottleneck
Vibe coding or spec-driven development? How to choose
The agentic AI distraction
Microsoft’s bad obsession is showing up in shabby services and slipshod software. Here’s proof
SAP to acquire data lakehouse vendor Dremio
Singapore boffins get diverse SIEMs singing in harmony with agentic rule translation

https://security-tracker.debian.org/tracker/DSA-6247-1

Kids say they can beat age checks by drawing on a fake mustache