Menu

Monthly Archives: June 2026

YARD could be made to expose sensitive information over the network.

Dirk Mueller discovered that a flaw in the function performing a credential check on the command socket of haveged, a userspace entropy daemon, may result in local privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.9.14-1+deb11u1.

Beyond automation: Why the surge in AI-driven security vulnerabilities demands human technical advocacy
Fragnesia and friends: When page cache vulnerabilities keep coming back
The Role of Natural Language Processing in Detecting Phishing Emails
World Food Programme breach exposes data of 600k vulnerable Gazan families

Warisjeet Singh discovered that Exim, a mail transport agent, does not properly handle PROXY frames whose declared payload length is too short for the claimed address family, which may result in information disclosure in configurations with SUPPORT_PROXY and ‘host_proxy’ set. For Debian 11 bullseye, this problem has been fixed in version

Postfix could be made to crash if it received specially crafted network traffic.

Several security issues were fixed in Robocode.

Several security issues were fixed in Exim.

Several security issues were fixed in Tomcat.

Council in UK’s City of York outs hundreds of disabled residents with a single email blunder
Embedding pipelines are the new ETL
The real cost of agentic AI

4.1.2, fix for CVE-2026-38978

libre v4.8.1 (2026-05-28) fmt/pl: add pl_strip_html() sys/fs: add getpwuid fallback for fs_gethome tls: remove unused include rsa.h ice: check source address of incoming application packets

Backport fix for CVE-2026-48710

33.0.4 Release

This update addresses a number of bugs including these security issues: Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) Fix dupkeys_as_arrayref type confusion (CVE-2026-9334)

Backport 0.9.41 / 0.9.44 fixes for possible path traversal issues

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

4.1.2, fix for CVE-2026-38978

Update to Samba 4.23.8 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238

Update to Samba 4.23.8 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238

libre v4.8.1 (2026-05-28) fmt/pl: add pl_strip_html() sys/fs: add getpwuid fallback for fs_gethome tls: remove unused include rsa.h ice: check source address of incoming application packets

Backport fix for CVE-2026-48710

33.0.4 Release

This update addresses a number of bugs including these security issues: Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) Fix dupkeys_as_arrayref type confusion (CVE-2026-9334)

Backport 0.9.41 / 0.9.44 fixes for possible path traversal issues

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to 0.031 #2477035 #2481131 fixes CVE-2026-8463

Update to version 0.11.2. Resolves CVE-2025-12474 and CVE-2026-1837. Release notes: https://github.com/libjxl/libjxl/releases/tag/v0.11.2

Changes: 6.83 2026-05-12 11:41:48Z – LWP::UserAgent now strips Authorization and Proxy-Authorization headers on cross-origin redirects (a different scheme, host, or port) to prevent credential leakage to the redirect target. Same-origin redirects retain

0.094 – fix to prevent invalid characters in all headers, and prevent header smuggling (CVE-2026-7010)

Automatic update for cockpit-362-1.fc43. Changelog for cockpit * Wed May 20 2026 Packit – 362-1 – Bug fixes and translation updates – Fix arbitrary code execution via specially crafted logs page link

Several security issues were fixed in the Linux kernel.

The system could be compromised under certain conditions.

Several security issues were fixed in the Linux kernel.

Pink is the latest goon squad to use fake helpdesk calls to steal creds

https://security-tracker.debian.org/tracker/DSA-6322-1

https://security-tracker.debian.org/tracker/DSA-6321-1

An update that solves 203 vulnerabilities, contains six features and has 41 security fixes can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities and contains one feature can now be installed.

An update that solves five vulnerabilities can now be installed.

Microsoft makes Linux developers feel more at home in Windows with Coreutils release
Meta’s own AI chatbot to blame for Instagram accounts being stolen in seconds
OpenAI’s agent chained decade-old DoS attacks to crash web servers in seconds
Microsoft’s Web IQ aims to give enterprise AI agents real-time web intelligence
Lessons for life: Why children’s data is a long-term identity risk

Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.

How Open Source SIEM Architectures Scale Beyond Single-Server Deployments
HTTP/2 Bomb: Why Linux Infrastructure is Vulnerable to a New Low-Bandwidth DoS Attack

An update that solves 14 vulnerabilities and contains one feature can now be installed.

An update that solves five vulnerabilities and contains two features can now be installed.

An update that solves three vulnerabilities and has 12 fixes can now be installed.

Five Eyes: Watch out for odd LinkedIn connection requests, China’s back on the hunt for state secrets

Security update

Security update

Duo who sold car crash victims’ data must repay £118k
Google brings local AI agents to laptops with Gemma 4 12B
Rayfin signals Microsoft’s push to make Fabric an AI app runtime
The next AI breakthrough won’t come from bigger models, but from better data
Angular Signals explained: How pull-based reactivity changes how we model state
Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Update to xwayland 24.1.12, security fixes for ZDI-CAN-30136, ZDI-CAN-30159, ZDI-CAN-30160, ZDI-CAN-30161, ZDI-CAN-30163, ZDI-CAN-30164, ZDI-CAN-30165, ZDI-CAN-30168

Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx – Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 – Sudo-elevated root code execution via TOCTOU between self-

Version 1.4.5 This release contains vulnerability fixes for the following security advisories: GHSA-h842-vjwg-pxxx – Sudo-elevated arbitrary file deletion via extra.pie- installed-binary metadata in UninstallUsingUnlink GHSA-pm6p-666q-hvj5 – Sudo-elevated root code execution via TOCTOU between self-

Release 1.6.16 Fix potential too long value in IMAP ID command (#10136) Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog Security: Fix CSS injection bypass in HTML sanitizer via SVG

Patch for CVE-2026-5119

All the passwords were stored in Active Directory description fields
OpenAI fixed a visibility problem; the governance problem remains.
Hole in GitHub’s browser-based VSCode editor could lead to stolen token

Several security issues were fixed in Exim.

Multiple vulnerabilities were discovered in Ceph, a distributed storage and file system, which may result in privilege escalation, denial of service or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 16.2.15+ds-0+deb12u2.