Menu

Monthly Archives: June 2026

Important: flac security update

Moderate: qt5 security and bug fix update

Moderate: protobuf-c security update

Moderate: coreutils security update

Moderate: libxslt security update

Moderate: keylime security update

Important: skopeo security update

https://security-tracker.debian.org/tracker/DSA-6369-1

https://security-tracker.debian.org/tracker/DSA-6368-1

https://security-tracker.debian.org/tracker/DSA-6367-1

Moderate: python-wheel security update

Moderate: freeradius:3.0 security update

Moderate: python27:2.7 security update

Even the Secret Service won’t use company-issued phones
How Memory Leaks Affect System Stability and Security

Multiple vulnerabilities were discovered in gdcm, a C++ library for working with DICOM medical files: CVE-2024-22373 An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality. A specially crafted

An update that solves six vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves 19 vulnerabilities can now be installed.

An update that solves 19 vulnerabilities can now be installed.

An update that solves 13 vulnerabilities can now be installed.

Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data

An update that solves 21 vulnerabilities and has two security fixes can now be installed.

An update that solves 21 vulnerabilities and has two security fixes can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves 10 vulnerabilities, contains one feature and has five security fixes can now be installed.

An update that solves one vulnerability can now be installed.

US tells OpenAI to restrict access to its most powerful AI model

Important: nginx security update

Important: buildah security update

Moderate: golang security, bug fix, and enhancement update

Important: nginx security update

Moderate: golang security, bug fix, and enhancement update

Important: buildah security update

Important: nginx security update

Moderate: golang security, bug fix, and enhancement update

Rocky Linux 9 RLSA-2026-29703 Important Containernetworking-Plugins Update
Important: containernetworking-plugins security update

Important: runc security update

Important: buildah security update

Important: thunderbird security update

Important: tigervnc security update

Important: buildah security update

Moderate: golang security, bug fix, and enhancement update

Important: runc security update

Important: thunderbird security update

Important: tigervnc security update

Important: containernetworking-plugins security update

Important: buildah security update

Moderate: golang security, bug fix, and enhancement update

Important: runc security update

Important: thunderbird security update

Important: tigervnc security update

Important: containernetworking-plugins security update

An update that solves one vulnerability can now be installed.

An update that solves 4 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 5 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds

Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in a bypass of security restrictions or the execution of arbitrary commands. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u8.

pgEdge joins rush to merge OLTP and OLAP storage to support AI
Dark Moon: Can AI Actually Automate Penetration Testing on Linux?
How to Detect Unauthorized SSH Key Usage on Linux Systems
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Why private AI is the smarter bet
Security boss thought MFA would be too much security

Moderate: libpng security update

Moderate: libpng security update

Moderate: libpng security update

Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder
Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs

https://security-tracker.debian.org/tracker/DSA-6366-1

https://security-tracker.debian.org/tracker/DSA-6365-1

https://security-tracker.debian.org/tracker/DSA-6364-1

Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues

Multiple vulnerabiliites have been discovered in PDNS Recursor, a resolving name server which could result in denial of service, cache poisoning or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 5.2.11-0+deb13u1.

It was discovered that incorrect request handling in the internal web server of the PowerDNS DNS server could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 4.9.16-0+deb13u1. We recommend that you upgrade your pdns packages.

Multiple security vulnerabilities were discovered in the dnsdist DNS loadbalancer, which could result in denial of service, information disclosure or bypass of security rules. For the stable distribution (trixie), these problems have been fixed in version 1.9.15-0+deb13u1.

A use-after-free issue was found in libtext-csv-xs-perl, a Perl C/XS module to process Comma-Separated Value files, which may yield type confusion or memory corruption when registered callbacks extend the Perl argument stack. For Debian 11 bullseye, this problem has been fixed in version

Multiple security vulnerabilities were discovered in the SOGo groupware server, which could result in cross-site scripting or SQL injection. For the stable distribution (trixie), these problems have been fixed in version 5.12.1-3+deb13u2. We recommend that you upgrade your sogo packages.

Multiple security vulnerabilities were discovered in libssh2, a client-side C library implementing the SSH2 protocol which could result in memory disclosure, denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in

Several security issues were fixed in AMD Microcode.

ESET takes part in Operation Endgame to disrupt Amadey and Stealc

ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 149.0.7827.196-1~deb13u1.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

Agentic AI security steals the spotlight at Confidential Computing Summit

An update that solves 23 vulnerabilities can now be installed.

Fedora 43 Goose Critical DNS Rebinding Threat Fix 2026-08bb036c3e
Update goose to 1.36.0

Addresses CVE-2026-47895 which is a theoretical RCE Fixes CVE-2026-25075, CVE-2026-35328, CVE-2026-35329, CVE-2026-35330, CVE-2026-35331, CVE-2026-35332, CVE-2026-35333, CVE-2026-35334 Update to address CVE-2025-9615 and CVE-2025-62291

new version 2.4.68 fixes various security issues

Several security issues were fixed in xrdp.

Update goose to 1.36.0

Moderate: keylime security update

Moderate: libxslt security update

Important: skopeo security update