Menu

Monthly Archives: August 2026

SUSE Podman Significant Security Patch SUSE-SU-2026-3854-1
Debian LTS xrdp Critical Buffer Overflow Vulnerability Alerts DLA-4759-1
openSUSE rsyslog Important Heap Overflow Fix Advisory 2026-3859-1
openSUSE Rsyslog Important Heap Buffer Overflow Issue 2026-3860-1
Critical Advisory for openSUSE Apptainer Filesystem Issue CVE-2026-17106
openSUSE python310 Important Path Traversal Vulnerability Fix CVE-2026-7774
openSUSE 2026-3852-1 Rekor Major Security Update Released Today
Significant security patch update 2026-3853-1 launched for openSUSE Podman
openSUSE Podman Significant Security Patch SUSE-2026-3854-1
Rocky Linux libxml2 Moderate Update Buffer Overflow Vuln RLSA-2026-60394
Fedora 44 python-pynitrokey Critical Update CVE-2026-69247
Fedora 44 python-cryptography Critical Fix CVE-2026-69247 Advisory
Fedora 44 BlueZ Local DoS Buffer Overflow Vulnerability 2026-1fba3f22c9
Turns out Brits would quite like their private messages to stay private
Brits have delivered a fairly unambiguous verdict on giving the government access to their encrypted messages: no, thanks. New polling commissioned by the [...]
DSA-6479-1 roundcube – security update
DSA-6478-1 starlette – security update
openSUSE Broot Moderate Bug Fix Advisory CVE-2026-72847
openSUSE CoreDNS Moderate Denial of Service Fix 2026-21674-1
openSUSE Vim High Priority Fix for Service Disruption and Code Execution
Mageia Python-NLTK Important Multiple Issues Fixes 2026-0340
openSUSE Tumbleweed Pyenv Moderate Security Fix CVE-2026-68939 2026-11613-1
openSUSE Authlib Moderate Security Issue Fix 2026-11614-1 CVE-2024-37568
openSUSE Tumbleweed cadvisor Moderate CVE-2026-41178 Advisory 2026-11606-1
openSUSE Distribution-Registry Important CVE-2026-41178 2026-11609-1
Gentoo Freenet Important XSS Deanonymization Vulnerability GLSA 202608-33
Gentoo Tor Significant Various Risks Remote Code Execution GLSA 202608-32
Rust language adds algebraic floating-point methods
The Rust team has released Rust 1.98.0, an update to the language that introduces algebraic methods for floating-point operations. Developers who have a [...]
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
Anthropic’s Claude Code running Opus 5 in Auto Mode can be tricked into executing attacker-controlled code simply by asking the coding agent to summarize a [...]
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.
US government snitch-finder pleads guilty to leaking state secrets to foreign spies
The former Defense Intelligence Agency (DIA) IT specialist previously accused of trying to pass secret and top-secret information to foreign spies has [...]
Oracle Linux 9 Advisory ELSA-2026-59723 Important Kernel Bug Fixes
Oracle mingw-openssl Low Buffer Overread Fix ELSA-2026-60329-0
Oracle Linux 8 ELSA-2026-59821 Kernel Bug Fix Important
CISA: Most exploited vulnerabilities should have been eradicated decades ago
CISA is still crying out for software vendors to adopt Secure by Design (SBD) development practices, and says in its latest review that longstanding [...]
Streamlining container security: Red Hat Hardened Images now supported in AWS InspectorScan API and ECR Basic scanning
Software security teams can face an overwhelming influx of vulnerability alerts, often stemming from non-essential packages bundled inside traditional [...]
Preparing OpenStack for the post-quantum era: A systematic approach to crypto-agility
OpenStack powers clouds used by some of the most security-sensitive organizations on the planet: government agencies, telecommunications providers, [...]
Industry that built the problem offers to sell you the solution
OpenAI has gathered more than 100 of the world’s biggest tech and infosec companies to warn that cyber defense is in trouble – a reassuring [...]
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Why enterprise AI projects keep failing
Over the past three years, as an independent cloud and AI consultant, advisor, and industry influencer, I have worked with numerous companies seeking my [...]
Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood
Nothing smarts like a paper cut, but being attacked after leaving an application’s web interface exposed to the internet might be just as painful. Such [...]
Australian cops cuff alleged TeamPCP masterminds
The Australian city of Perth is by some measures the world’s most isolated major metropolis, but is still sufficiently connected to US law enforcement [...]
Fedora 43 rust-h2 Security Update Resolving RUSTSEC-2026-0258 Issue
SUSE Important Wicked Out-of-Bounds Issues CVE-2026-71401 CVE-2026-71402
openSUSE Wicked Important DHCP Out-of-Bounds Reads Vuln 2026-3839-1
SUSE important wicked Security Update CVE-2026-71401 CVE-2026-71402
openSUSE Wicked Important Indirect Shell Command Injection Fix 2026-3840-1
SUSE Wicked Important Indirect Remote Shell Injection Vuln 2026-3840-1
SUSE Wicked Important Security Update CVE-2026-71401 CVE-2026-71402
openSUSE Wicked Important Buffer Overflow Patch 2026-3842-1
SUSE 15.4 Important Wicked Security Issue CVE-2026-71401 CVE-2026-71402
openSUSE suseconnect-ng Moderate Security Fix Advisory 2026-3843-1
SUSE suseconnect-ng Moderate Security Update SUSE-SU-2026-3843-1
SUSE python36-pip Moderate URL Handling Arbitrary File Issue 2026-3846-1
openSUSE texlive Moderate Use-After-Free Vulnerability CVE-2026-63729
openSUSE Texlive Moderate Use-After-Free Vuln 2026-3847-1
Visual Studio Code 1.135 introduces Rubber Duck agent
Microsoft’s latest update to Visual Studio Code, released August 26, features a Rubber Duck agent for a second model opinion as well as UX improvements to [...]
Ubuntu 20.04 LTS Kernel Update Moderate WiFi Issue 2026-8666-3
Ubuntu 22.04 LTS Kernel Critical Network Flaw Update USN-8661-3
Ubuntu 20.04 Linux Kernel Azure CVM Security Update USN-8658-4
Ubuntu Linux Kernel Azure Critical Flaws Fixed USN-8644-3
Ubuntu 24.04 LTS 8643-5 Important Security Update for Linux Kernel
CRPx0 hacking service for dummies claims victim count more than quintupled
CRPx0, a cybercrime crew that has rapidly evolved from a scam service to a ClickFix-delivered ransomware and crypto-theft business over the summer, claims [...]
Ubuntu 24.04 LTS PAM Bypass Vulnerability Announcement USN-8688-1
Debian LTS Chromium Important Code Exec DoS Info Disclosure DLA-4758-1
Linux Patching Best Practices: Designing a Patch Validation Workflow
Patch work often gets declared finished at the package manager. The update installs, version inventory changes, the service restarts, and the ticket begins [...]
openSUSE librest Moderate PKCE OAuth Vulnerability 2026-3834-1
SUSE librest0_7 Moderate PKCE Crypto Issue Vuln 2026-3834-1
SUSE OpenSSL Important Security Fixes Advisory 2026-3835-1
Go 1.27 brings support for generic methods
Google’s Go programming language has been updated with changes across the language, toolchain, runtime, and standard library. Released August 19, Go 1.27 [...]
Mageia 10 python-django Important DoS Cross-Site Scripting Vuln 2026-0339
Mageia Avahi Important Security Flaws CVE-2025-59529 CVE-2026-24401
Mageia yt-dlp Bugfix Security Upgrade Released in January 2026
Mageia 10 fs-uae Security Patch Problem Report 2026-0113 Update
Mageia 10 Guayadeque Security Update 2026-0112 with Bug Fixes
Mageia 10 Mnemosyne Patch Update Released for January 11 2026
Mageia opencpn Bugfix Security Advisory 2026-0110 Core Dump Issue
Mageia 10 Viking Security Advisory 2026-0109 Segmentation Fault Fix
Mageia 10 Advisory 2026-0108 serd Security Update on Rebuilt Packages
Mageia 10 opencpn-o-charts-plugin Bugfix Advisory 2026-0107
Mageia 10 Advisory php8.5-gmagick Module Conflict Fix 2026-0106
AI girlfriend review site’s secrets were exposed to the world for three weeks
PWNED Welcome back to PWNED, the weekly column where we explore the frightening and amusing world of foolish infosec errors. This week, it’s all [...]
Debian Chromium Important Code Exec Denial of Service Vuln DSA-6476-1
Omarchy distro gains serious backing
The controversial Omarchy distro is attracting both criticism and fans – and financial support, too. Omarchy is an opinionated respin of Arch Linux and a [...]
Rocky Linux 10 golang Important Denial of Service Fix RLSA-2026-60306
Rocky Linux AssertJ-Core Moderate Info Disclosure DoS Issue RLSA-2026-60215
Rocky Linux 9 Golang Important DoS XSS Issues RLSA-2026-60304
Rocky Linux 9 Kernel Important Security Bug Fix Update RLSA-2026-59723
Rocky Linux 9 Moderate Symlink Traversal Escalation Fix RLSA-2026-60226
Rocky Linux 8 kernel-rt Important Security Fixes RLSA-2026-59737
openSUSE Leap 16.0 gh Important Issues Patch 2026-21663-1
openSUSE Leap 16.0 rsync Important Security Issues Resolved 2026-21650-1
Ubuntu 24.04 openCryptoki Important Access Issues USN-8686-1
openSUSE rmt-server Important Denial of Service Issues 2026-21640-1
openSUSE Leap 16.0 Advisory 2026-21639-1 dracut Important Root Code Exec
ATF responds to ‘major’ cybersecurity incident after ransomware gang’s claims
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) said it’s responding to a “major” cybersecurity incident shortly after the Qilin ransomware [...]
Schrödinger’s backup: not actually recovered until you try to restore IT
Schrödinger’s Cat, the famous 1935 thought experiment, imagines a cat that, for reasons rooted in quantum physics we need not dwell on here, is [...]
Linux Kernel Vulnerability News: Linux Security Roundup
Linux kernel vulnerability news dominated the security updates published from August 20 through August 27. Ubuntu, Debian, Fedora, Mageia, Oracle Linux, [...]
Ubuntu Kernel Security Vulnerabilities Resolved in Releases 16.04 to 24.04
Cybercrooks jet off with Manchester Airports Group customer data
The company behind three of the UK’s busiest airports says “a quantity” of data was stolen by an extortion group during a recent “cybersecurity [...]
AppArmor Credential Fix Prevents In-Hook Use-After-Free Risk
A Linux security hook should be able to check a task without invalidating the identity data that surrounding kernel code is still using. AppArmor broke [...]