Menu

Monthly Archives: August 2026

SUSE Alsa Moderate Double-Free Memory Corruption Vuln 2026-3492-1
openSUSE perl-HTTP-Tiny Important Cross-Origin Redirect Fix 2026-0274-1
openSUSE Thrift Important Security Fix 2026-0275-1 CVE-2026-41602
openSUSE perl-YAML-Syck Important Mem Safety Crash Fixes 2026-0273-1
Mageia PHP Security Update CVE-2026-7260 CVE-2026-17543
Mageia acl attr Critical Buffer Overflow Vuln 2026-0321
Bypassing AI guardrails is so easy a script kiddie can do it
If you want to bypass AI guardrails designed to stop models from assisting with cyberattacks, you often just have to ask the right way, according to [...]
AWS’s Kiro Crew aims to turn AI coding agents into autonomous engineering teams
AWS on Tuesday released Kiro Crew, an open-source orchestration platform designed to help enterprises move beyond interactive AI coding assistants toward [...]
Oracle Linux 10 Thunderbird Major Update ELSA-2026-49621
Oracle Linux 10 nodejs22 Important Multiple Issues ELSA-2026-48033
Oracle Linux 10 ELSA-2026-48032 Nodejs Nodemon Important Security Update
Oracle Firefox Important Vulnerabilities Advisory ELSA-2026-47101
Oracle Linux 10 Node.js Important Bug Fix Advisory ELSA-2026-35842
Oracle Linux 10 Kernel Significant Security Patch ELSA-2026-23329
Oracle Linux 8 perl-Archive-Tar Important DoS Fix ELSA-2026-49524
Oracle Linux 8 FRR Important Packet Parsing Fix ELSA-2026-49511
Oracle 8 PHP Low Memory Corruption Vuln ELSA-2026-47750
Oracle Linux 8 PHP 8.2 Low Bug Fix Advisory ELSA-2026-47749
Oracle Linux 8 ELSA-2026-46396 Libreswan Important Fixes
Oracle Linux 8 Kernel Important Threat Fixes ELSA-2026-500121
Oracle Linux 7 Rsync Important CVE-2026-41035 Advisory ELSA-2026-25172
This one time, at Hacker Summer Camp …
As the entire security industry descends on Las Vegas this week for Hacker Summer Camp – not one, but three conferences – attendees can count on two hot [...]
Feds get 3 days to patch N-able God mode flaw under active exploit
The US Cybersecurity and Infrastructure Security Agency (CISA) has added an exploited N-able vulnerability to its Known Exploited Vulnerabilities (KEV) [...]
AI helps Microsoft bug hunters chase a record $20M payday
Microsoft announced this week that between July 1, 2025, and June 30, 2026, the company had paid more than $20 million in bug bounties to 562 researchers. [...]
AI Is Already Performing Linux Security Work. What Happens When It Escapes Containment?
Nearly everyone following technology has heard about the recent security incidents involving OpenAI and Anthropic. The headlines focused on the containment [...]
OpenStack IPA Flaws Highlight a Hidden Bare-Metal Security Risk
OpenStack disclosed a flaw in its bare-metal management tool, the Ironic Python Agent (IPA), showing that it could accidentally fall back to local network [...]
Tennessee congressional hopeful accused of shooting license plate cameras
An independent congressional candidate in Tennessee faces four felony vandalism charges after allegedly shooting four automated license plate reader (ALPR) [...]
Google ADK flaws reveal what happens when AI agents trust the wrong message
Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger [...]
CAF Bank reopens online service but warns of further outages
CAF Bank has told customers its online banking service is back after being shuttered for more than ten days following what it described as “attempted [...]
Fake IRS letters target cryptocurrency holders
When you should use AI, and when you shouldn’t
Most folks seem happy to let AI write their LinkedIn posts for them. Others, myself included, have AI draft their work memos or slide decks. And some, [...]
When the cloud control plane fails
Not long ago, I worked with an enterprise that believed it had done everything right. The company had spread workloads across multiple regions, replicated [...]
Debian LTS ruby2.7 Important DNS Buffer Overflow Threat DLA-4716-1
Cloudflare has mostly ditched third party security tools, suggests not trying that at home
Cloudflare has used AI to automate processing of incoming reports to its bug bounty program for $58 a month using Anthropic’s Claude Sonnet model and chose [...]
Fedora 43 BorgBackup CVE-2026-62268 Bugfix Update 2026-5a13ef79cc
GitHub pushes stacked pull requests into public preview
Advancing on software development, GitHub has announced the public preview of stacked pull requests. The public preview was announced July 30. Stacked pull [...]
Fedora 44 python-nh3 Update Advisory RUSTSEC-2026-0193 RUSTSEC-2026-0213
Fedora 44 rust-ammonia Update RUSTSEC-2026-0193 RUSTSEC-2026-0213
Fedora 44 Nebula 1.11.0 Patch Fixing Security Issues December 2026
SUSE perl-DBI Important SQL Handling Issues Vuln 2026-3461-1
openSUSE Leap 15.4 Xen Important Buffer Overflow Vuln 2026-3462-1
SUSE 2026-3462-1 Critical Xen Buffer Overflow Security Update
openSUSE libssh Moderate Denial of Service and Integrity Issues 2026-3463-1
SUSE libssh Moderate Denial of Service and Info Disclosure Vuln 2026-3463-1
Oracle Linux 10 p11-kit Moderate Security Issue ELSA-2026-49668
Oracle Linux 10 ELSA-2026-49523 perl-Archive-Tar Important Memory DoS Fix
Oracle 10 perl-DBI Important Threat Fix Advisory ELSA-2026-49514
Oracle Linux 10 gstreamer1-plugins-good Critical Integer Overflow Issue
Oracle Linux 10 php Low Advisory ELSA-2026-48170 CVE-2026-14355
Oracle9 perl-DBI Important Security Advisory ELSA-2026-49612
Oracle Linux 9 ELSA-2026-49527 frr Important Input Validation Fix
Oracle Linux 9 perl-Archive-Tar Vital Memory Management DoS ELSA-2026-49525
Oracle Linux 9 Libreswan Important Vulnerability Advisory ELSA-2026-46397
Oracle Linux 8 Nodejs Important Security Advisory ELSA-2026-47060
Oracle Linux Node.js Important Security Update ELSA-2026-47059
Oracle Linux 8 pki-deps Important Security Update ELSA-2026-43218
Oracle Linux 8 javapackages-tools Important Update Advisory ELSA-2026-41948
Oracle Linux 7 compat-libtiff3 Key Buffer Underflow Fix ELSA-2026-24992
Moderate CVEs for Oracle Linux 7 Python Tornado ELSA-2026-24342
SUSE Nginx Important Heap Overflow Denial of Service Vuln 2026-3448-1
SUSE RRDTool Important Buffer Overflow Risk Advisory 2026-3449-1
SUSE Containerd Moderate Denial of Service Fix Advisory 2026-3450-1
SUSE Linux 12 SP5 Important Xen Security Update 2026-3451-1
SUSE 2026-3452-1 Bind Important Denial of Service Vulnerabilities
SUSE Java 11 Important Security Update Denial of Service CVE-2026-47057
SUSE perl-HTTP-Date Moderate CPU Exhaustion Fix Advisory 2026-3454-1
SUSE gawk Moderate Buffer Overflow Integer Overflow Vuln 2026-3455-1
SUSE perl-Net-DNS Important DoS Issue Advisory 2026-3456-1
SUSE OpenSSL Addresses Significant DoS Risk with Patch 2026-3457-1
SUSE vim Important Code Execution Flaws Vuln 2026-3458-1
SUSE Python3-Dulwich Important SSH Key Issue 2026-3459-1
SUSE Important python-urwid Security Update 2026-3460-1
SUSE Python3 Important Security Update Vulnern 2026-22959-1
SUSE Kernel RT Vital Security Patch for CVE-2026-53359 and CVE-2026-53366
SUSE Kernel RT Important KVM and IPv4 Vulnerabilities 2026-22962-1
SUSE Kernel RT Important KVM and IPv4 Security Patch 2026-22963-1
Google dev kit spurs first-ever agent-on-agent violence
In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the [...]
Gleam update shines on language server
Gleam, a type-safe and scalable language for the Erlang virtual machine and JavaScript runtimes, has reached version 1.18.0. The update brings full support [...]
Mageia Perl Unicode Line Break Security Fix CVE-2026-8594 2026-0320
Mageia Squid Important Heap Overflow FTP Gateway Vuln 2026-0319
Mageia perl-GD Medium OS Command Injection Vuln 2026-0318
Mageia 10 Perl Important Security Fixes CVE-2026-13221 57432 57433
Mageia Unbound Security Patch 1.25.2 Released for 2026-0316 CVE-2026-14586
Mageia libvncserver Important Heap Out-of-Bounds Vulnerabilities 2026-0315
Mageia 2026-0314 Librabbitmq Critical Local Attacks Issue CVE-2023-35789
Mageia corosync Critical DoS Information Exposure Vulnerabilities 2026-0313
AI slop pollutes the CVE pipeline with fake vulns
Now AI is making fake vulnerabilities and polluting the ecosystem. A batch of critical- and high-rated SQLite CVEs that appeared in the NVD with [...]
Russian spies turn public Wi-Fi into malware delivery systems
Conference-goers may want to think twice about connecting to public Wi-Fi after Microsoft disclosed that Russian foreign intelligence operatives (SVR) are [...]
Responding to a Web Server Compromise
Your website isn’t acting normally. Users report errors. Monitoring detects unexpected outbound connections. You discover a recently modified PHP file in [...]
What Is Fuzzing? Inside the Search for Hidden Linux Kernel Bugs
If you spend time reading Linux kernel bug reports or security patches, that line is everywhere. It sits quietly at the bottom of code fixes across the [...]
Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
Georgia and Michigan are the latest US states to report cyberattacks on water systems, as the FBI investigates incidents across at least seven states. [...]
Hashimoto’s Superlogical bets that agentic software development needs more than a better terminal
The rise of AI coding agents is beginning to expose a longstanding weakness in software development: work remains fragmented across developer terminals, CI [...]
Alibaba takes aim at OpenAI and Anthropic with Qwen3.8-Max launch
Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight [...]
Same goals, different clocks: What Red Hat’s 2025 Risk Report reveals about global compliance gaps
In April 2026, Red Hat’s Product Security team published its annual Risk Report . I encourage everyone involved in building, shipping, securing, or [...]
UK government investment arm cops to 40-hour leak of officials’ contact details
The UK government’s corporate finance adviser has admitted that an employee left an internal file containing the names and work email addresses of [...]
What Business Owners Need to Know About Linux Security
Business owners can effectively manage Linux security by shifting their focus from technical commands to strategic risk management and operational oversight.
Debian libssh Important Denial of Service Arbit Code Exec DSA-6410-1
Oracle Linux 10 Kernel Important Bug Fix Advisory ELSA-2026-47017
Oracle Linux 8 Kernel Important Update for CVE-2026-53006 ELSA-2026-47011
Oracle Linux 9 Advisory ELSA-2026-47040 Kernel Important Bug Fix