Menu

Monthly Archives: July 2026

Mageia 389-ds-base Critical CPU Amplification Dos Vulnerability 2026-0310
Mageia 10 9 nghttp2 Important HTTP Smuggling Fix CVE-2026-58055
Mageia perl-DBI Moderate Multiple Security Issues Advisory 2026-0308
SUSE ImageMagick Moderate Code Injection Buffer Overflow Vuln 2026-3412-1
SUSE ImageMagick Moderate Heap Buffer Code Injection Vulnern 2026-3413-1
SUSE Important Update for Prometheus-Ha Cluster Exporter CVE-2026-39821
openSUSE 16.0 s2n Moderate Memory Leak Man-in-the-Middle Fix 2026-21474-1
openSUSE Leap 16.0 Apptainer Important Update CVE-2026-39821 CVE-2026-56852
openSUSE Keybase Client Low ASCII Punycode Issue Advisory 2026-21471-1
openSUSE GraphicsMagick Low Heap Buffer Overwrite Issue 2026-21468-1
openSUSE Java-25-OpenJDK Important Denial of Service Fix 2026-21467-1
openSUSE Python313 Important Update for Multiple Issues 2026-21459-1
openSUSE logcli Moderate CVE-2026-39822 Package Update 2026-11393-1
openSUSE kubevirt1.8-container-disk Moderate Security Update 2026-11392-1
openSUSE Tumbleweed Kubernetes Moderate APIServer Update CVE-2020-8561
openSUSE Tumbleweed Kubernetes Medium CVE-2020-8561 Advisory 2026-11389-1
openSUSE Tumbleweed Kubernetes Medium CVE-2020-8561 Advisory 2026-11390-1
openSUSE Tumbleweed ffmpeg Moderate CVE-2026-8461 Security Update
openSUSE Helm Moderate Security Update CVE-2026-63308 2026-11386-1
openSUSE freerdp Moderate Patch for 3 Vulnerabilities 2026-11385-1
Jailed Flock vandal wipes out three cameras, racks up thousands in damages
Note to privacy-conscious vandals: If you’re going to destroy Flock license plate readers, make sure you also take out the other CCTV cameras in the [...]
Ubuntu 22.04 LTS Sinatra Denial of Service Vulnern 2026-8624-1
Ubuntu 22.04 20.04 libinput Important Code Execution Issue USN-8602-1
Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
A critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by [...]
New Databricks tool uses AI agents to rewrite legacy SQL at scale
Databricks is adding an agentic code conversion capability to its Lakebridge toolkit, using Genie Code to provide its new customers another way to move [...]
Debian expat Critical Memory Corruption Denial of Service Vuln DSA-6404-1
Rocky Linux openssh Medium Risk Resolution RLSA-2019-3702
Rocky Linux perl Important Denial of Service Vuln RLSA-2026-48225
Rocky Linux GStreamer Important Buffer Overflow Fix RLSA-2026-47731
SUSE GIMP Important Buffer Overflow Threat Advisory 2026-3399-1
SUSE PackageKit Moderate Improper Authorization Issue Advisory 2026-3405-1
SUSE Python-Dulwich Important SSH Host Key Update CVE-2026-38974
SUSE PackageKit Moderate Authorization Manipulation Vuln 2026-3404-1
SUSE Rsyslog Important Denial of Service Fix Advisory 2026-3398-1
SUSE WebKit2GTK3 Important Memory Corruption Process Crash Fix 2026-3396-1
SUSE Python-urllib3 Moderate Denial of Service Vuln 2026-3397-1
SUSE 15.6 OpenVPN Significant DoS Security Patch 2026-3407-1
SUSE Java 17 Important Security Update CVE-2026-41254 2026-3406-1
SUSE Kernel 2026-3392-1 Important Live Patching CVE-2026-53366
SUSE GraphicsMagick Low Heap Buffer Issue Vuln 2026-3395-1
SUSE OpenSUSE Leap 15.6 Important python-ujson Memory Leak Vuln 2026-3402-1
Russian spies take their half-click email attack from Zimbra to Outlook
The Russian espionage crew that turned simply reading an email into a security risk has expanded beyond Zimbra, with Proofpoint saying it’s now [...]
North Korea’s elite hackers turned on their own government – and got caught
How AI can improve site reliability engineering
One percent of AI-active developers now generate 46 times more AI-written lines of code per day than the median active user, according to the Cursor [...]
Shipping an MCP test agent: The boring parts nobody demos
The demo videos always end at the same moment. A figma frame turns into a passing test in twelve minutes. Someone in the room says the word “productivity.” [...]
AI agents need security regression testing, not another checklist
AI agents are being connected to real systems faster than most organizations are learning how to secure them. That should concern us. The first wave of AI [...]
Headteacher had the most guessable username-password combo you could imagine
PWNED Welcome, once again, to PWNED, the weekly column where we show you how not to use your computer or your network. In this week’s fable of [...]
Excuses like ‘AI did it’ don’t exist in the eyes of the law
The OpenAI rogue agent behind the Hugging Face hack accessed four accounts on four services, according to updated company disclosures about the intrusion. [...]
Fedora 44 libssh 0.12.2 Update Notification FEDORA-2026-c60881e04b
Fedora 44 unbound Critical DoS Issues Fixed in Update 2026-e495bd59ef
Fedora 44 ProFTPD Update Addresses ACL Bypass CVE-2026-35025
Fedora 44 Squid 7.6 Memory Fix Advisory 2026-e6bbab8aa8
Fedora 44 Node.js Updated to 24.18.0 with Denial of Service April 2026
Fedora 44 Fixes Critical SQL Injection and Remote Code Execution Issue
Fedora 43 ProFTPD ACL Bypass Fix CVE-2026-35025 Advisory 2026-d314ce6051
Fedora 43 WordPress Critical SQL Injection RCE Vuln 2026-46346e9637
Fedora 43 Nginx-mod-vts Security Advisory 2026-3b93aae2d6
Fedora 43 nginx-mod-modsecurity Critical CVE Fix 2026-42533
Fedora 43 nginx-mod-naxsi 1.6-21 Security Update CVE-2026-42533
Fedora 43 nginx-mod-fancyindex Security Advisory 2026-3b93aae2d6
Fedora 43 nginx-mod-brotli Security Advisory 2026-3b93aae2d6
Fedora 43 nginx-mod-headers-more Security Advisory 2026-3b93aae2d6
Fedora 43 Nginx Critical Update for Multiple Issues 2026-3b93aae2d6
Fedora 43 perl-HTTP-Date Important DoS Fix FEDORA-2026-b1bdb7c518
Visual Studio Code 1.131 zeroes in on subagents
Microsoft has shipped Visual Code 1.131, an update to its code editor with improvements for monitoring subagents, dictation, and Markdown editing. Released [...]
DSA-6404-1 expat – security update
Smashing Security podcast #478: This job interview could destroy your company
Rocky Linux 10 gstreamer1-plugins-bad-free Heap Overflow Issues RLSA-2026
Rocky Linux PipeWire Important Sandbox Escape CVE-2026-5674 RLSA-2026-47083
Rocky Linux 10 RLSA-2026-47085 Rest Important Weak Random Number Generation
Rocky Linux libXfont2 Heap Buffer Overflow Fix for RLSA-2026-47079
Rocky Linux 10 Kernel Important Bug Fixes Advisory RLSA-2026-47017
Rocky Linux ruby Important Command Injection Vulnerability RLSA-2026-33512
Rocky Linux Nginx Important Heap Overflow Bug Fix RLSA-2026-36331
Rocky Linux plexus-utils Important Directory Traversal Fix RLSA-2026-38796
Rocky Linux 9 PHP Remote Code Execution Denial of Service RLSA-2026-33449
Rocky Linux 9 PostgreSQL Important Security Update RLSA-2026-27741
Rocky Linux Firefox Significant Security Patch RLSA-2026-47105
Rocky Linux python-urllib3 Moderate Info Disclosure RLSA-2026-36732
Rocky Linux perl-IO-Compress Important Code Exec RLSA-2026-30858
Rocky Linux 8 perl-Archive-Tar Path Traversal Vulnerability CVE-2026-42496
Microsoft updates MCP C# SDK for stateless MCP
Microsoft has released MCP C# SDK v2.0, a major update of the company’s official C# SDK for Model Context Protocol (MCP) servers and clients. Unveiled July [...]
openSUSE Leap 15.6 python-ujson Important Memory Leak Fix CVE-2026-44660
openSUSE PackageKit Moderate Improper Authorization Fix 2026-3404-1
openSUSE java-17-openjdk Important Denial of Service Issues Fix 2026-3406-1
openSUSE openvpn Important Denial of Service Issues Fix SUSE-SU-2026-3407-1
openSUSE Xen Important System Exploit Fix Advisory 2026-3409-1
Debian DSA-6403-1 nss Important Arbitrary Code Execution Fix
Closed models refuse to help researcher swat Linux bug
The guardrails that prevent closed-source, frontier models from aiding threat actors have turned into handcuffs that prevent those bots from helping to [...]
Oracle simplifies migrating legacy databases off IBM mainframes with support for EBCDIC
Oracle on Tuesday described new EBCDIC character set compatibility features in Oracle AI Database for customers transitioning from legacy databases on IBM [...]
JDK 27: The new features of Java 27
Java Development Kit 27, an Oracle-driven, planned update to standard Java, is set to reach its initial release candidate (RC) stage on August 6. This [...]
Word worm crawls into Copilot, spreads chaos
UPDATED Watch out for untrusted documents. According to research, an attacker can hide malicious instructions in a Word document that, when included in [...]
openSUSE rsyslog Important Denial of Service Fix SUSE-SU-2026-3398-1
openSUSE GIMP Important Buffer Overflow Patch 2026-3399-1
Detecting Web Shell Activity on Linux Using Behavioral Clues
Although its main website is loading, a production Linux server can host an active command-and-control gateway without any errors that can be seen. If you [...]
Why Automation Breaks When Visual Data Is Treated as an Afterthought
Most automation projects don’t fail with dramatic outages; they fail through a slow erosion of trust.
Ubuntu 24.04 LTS Linux-NVIDIA Kernel Moderate Security Issue USN-8623-1
Ubuntu 26.04 LTS Linux-Nvidia Security Flaws Update USN-8622-1
Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems
Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the cyberattack that disrupted more than 30 [...]
Substituting IP address evaluation with hardware-rooted sovereign zero trust
The need for trustworthy networking, reliable cloud access, and compliance with digital sovereignty requirements has increased substantially in recent [...]