Menu

Monthly Archives: September 2026

SUSE Linux Enterprise 15 SP7 Kernel Important Security Update 2026-4120-1
Debian Stable ruby-rack Important Access Restriction Issues DSA-6492-1
Watch out: Apple timepiece can grab snippets of conversation without both speakers’ consent
With the release of Apple Watch Series 12, Apple has decided that it’s ok to capture people’s conversations without their consent. The latest [...]
Why Linux Must Close File Descriptors Before a Filesystem Can Stall
A file descriptor is the numbered handle a running program uses to access an open file or similar resource. Linux can mark it to close automatically when [...]
Ubuntu Python Critical Denial of Service and Code Execution Vuln USN-8744-1
Linux Sandbox Bug Could Read a Freed Parent Directory
A Linux sandbox restricts which files a program can access. Landlock, a kernel facility that lets programs apply those restrictions to themselves, had a [...]
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
An unknown attacker used hundreds of AI agents to exploit two PaperCut MF/NG bugs and break into at least 395 organizations. The victims were concentrated [...]
Safe word: What is it and why do you need one?
AI scams are now hyper-realistic. But there’s one simple way to see through them.
Ubuntu 26.04 KissFFT Notable Denial of Service Vulnerability USN-8745-1
Ubuntu 26.04 Beets Media Injection Vulnerability USN-8747-1 CVE-2026-42052
Ubuntu libEBML Critical Buffer Overflow Denial of Service USN-8746-1
openSUSE waylyrics Important CVE-2026-25541 Security Update 2026-21815-1
openSUSE Helm Important Buffers And Authorization Exploits 2026-21809-1
openSUSE Leap 16.0 Critical Security Update libzypp zypper 2026-21808-1
Ubuntu Linux Kernel NVIDIA Important System Compromise Vuln USN-8748-1
openSUSE Tumbleweed ggml-devel Moderate Update for CVE-2026-52132
openSUSE libmariadb-devel Important CVE-2026-44172 Update 2026-11721-1
openSUSE Chromedriver Medium Update 38 Risks Resolved Advisory 2026-11714-1
openSUSE Corosync Moderate Security Issues Fixed in 2026-11715-1
Oracle Linux 10 qt6-qt5compat Important Out-of-Bounds Read CVE-2026-9499
Oracle Linux 9 qt5-qtbase Vital Out-of-Bounds Read Patch ELSA-2026-65993-0
Oracle Linux Important qt5-qtbase Fix for CVE-2026-9499 ELSA-2026-65897-0
Oracle ThunderBird Important Update ELSA-2026-65160-0 CVE-2026-74934
Oracle Linux 8 ELSA-2026-62667-0 perl-DBI Important Buffer Overflows
Oracle Linux 7 Python-urllib3 Critical Buffer Overflow Alert ELSA-2026-9031
Oracle gstreamer1-plugins-bad-free Important Update ELSA-2026-54752
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
Ubuntu PHP Critical SQL Injection and DoS Vulnerabilities USN-8743-1
Ubuntu 24.04 LTS GNU C Library Security Advisory USN-8737-2 Details
ShinyHunters expose 6.4M in attack on medical supplier McKesson
McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service [...]
SUSE openSUSE Moderate Patch for python-Authlib CVE-2026-41479
SUSE Libzypp Zypper Critical Update Security Fixes SUSE-SU-2026-4112-1
Moderate Severity Alert for SUSE Python-aiohttp Due to HTTP Smuggling Risk
SUSE tomcat11 Important Security Update for 11 Bugs SUSE-SU-2026-4114-1
SUSE Linux Important strongswan Security Update 2026-4115-1
SUSE bzip2 Critical Off-By-One Vulnerability Advisory 2026-23494-1
The Lightwell reality check
We’ve been talking with business leaders about Lightwell for the past few months, and the conversation always starts with enthusiasm. AI-driven exploits [...]
Accelerating post-quantum security migration with Red Hat Certificate System
The realities of quantum computing and its inevitable impact on enterprise cryptography are already taking shape:Red Hat Enterprise Linux has been [...]
Beyond container boundaries: Kernel-level agent security in Red Hat OpenShift AI 3.5
77% of organizations now have AI agents running in production.1 The adoption curve is steep. The governance curve is not. Agents operate over-permissioned [...]
Linux Security Visibility: What Your Logs Need to Tell You
Suppose an application setting has changed on a Linux server, but nobody remembers changing it. The application still works, and the usual health checks [...]
Unveiling Operation DreamJob: A New Threat for Linux Users
Security researchers have recently discovered that Linux users targeted with malware in the new “Operation DreamJob” Lazarus campaign for the first time.
SpaceX: 32,000 Linux Systems Deployed in Starlink Constellation
Assuming the second-generation satellites carry the same number of Linux computers, it would mean SpaceX plans to send at least two million Linux computers [...]
Effective Infrastructure Monitoring for Downtime Prevention
Infrastructure monitoring is an integral part of infrastructure management. It is an IT manager’s first line of defense against surprise downtime.
Linux cgroup Memory Limits Can Miss Kernel Network Use
A Linux cgroup, or control group, limits how much memory a group of processes can use. Yet its counters can look normal while those processes cause the [...]
Linux NFS Control File Can Reach Freed Kernel Memory
A program can keep a Linux file open even after the separate networking environment behind it has started shutting down. That environment is called a [...]
Linux IPv6 Segment Routing Bug Can Write to Freed Packet Memory
Linux can move a network packet’s data in memory while some networking code still holds its old address. That saved address is called a pointer. A [...]
Why enterprises should start with on-site AI agents
When I talk to people about agents interacting with websites, the conversation almost always starts with perception: how does an agent “see” a page? Is it [...]
Build your AI stack like you will need to replace it
Every AI feature you’re building is based on a price that isn’t real. Current AI services are heavily subsidized as model providers seek to expand their [...]
Your frontend observability has an accessibility blind spot
Frontend teams have become pretty good at monitoring what happens after an application reaches production. We track JavaScript errors, API failures, [...]
Dental contractor set up secret account with access to 4,000 patient records then left the company
PWNED Welcome back to PWNED, the weekly column where we highlight examples of how not to handle your security. This week’s tale of woe comes from a very [...]
Anthropic reveals fourth likely crime committed by its AI
Amid industry soul-searching¹ about the possibility of AI improving itself to the point that it kills everyone, Anthropic has revealed yet another incident [...]
Smashing Security podcast #484: How websites are tracking you with silence
Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one [...]
DSA-6490-1 fort-validator – security update
Mageia Thunderbird Privilege Escalation and Isolation Flaws MGASA-2026-0388
Mageia Firefox Important Use-After-Free Escapes 2026-0387 CVE-2026-75874
Mageia wget Important Denial of Service Fix for CVE-2026-16599
SUSE 2026-23454-1 Systemd Moderate Local Privilege Escalation Fix
SUSE Linux Micro 6.0 Security Update for Helm Moderate CVE-2026-33630
SUSE Linux Micro 6.2 Intel Microcode Important Security Update 2026-23459-1
SUSE Libvirt Important Threats and Security Update Advisory 2026-23460-1
SUSE Linux Micro OpenSSL-3 Important Memory Overflow Patch 2026-23463-1
SUSE cpio Moderate Denial of Service and Injection Fix 2026-23464-1
SUSE Linux Micro Security Advisory 2026-23465-1 for sssd Moderate Issues
SUSE Linux Micro Critical dracut Command Injection Flaw 2026-23466-1
SUSE Fuse-OverlayFS Moderate Privilege Escalation Fix 2026-23469-1
SUSE Systemd Moderate Local Privilege Escalation Resolution 2026-23470-1
SUSE Linux Micro Moderate wget Server-Controlled Loop CVE-2026-16599
SUSE openssl-3 Important Security Update Patch 2026-23473-1
SUSE NetworkManager Important Local Privilege Escalation Vuln 2026-23475-1
SUSE Multipath-Tools Moderate Heap Denial Of Service Fix 2026-23476-1
SUSE Kernel Important Security Update Addressing 588 Vulnerabilities
Serial Microsoft 0-day hunter drops yet another Defender exploit
Zero-day researcher Nightmare Eclipse, aka MSNightmare, published yet another Microsoft Defender proof-of-concept exploit for a zero-day dubbed [...]
SUSE Linux Micro Moderate opensc Buffer Overflow Vuln 2026-23478-1
SUSE Linux Micro Critical Kernel Livepatch Upgrade 2026-23479-1
SUSE Micro 6.0 Important Kernel Livepatch Update 29 Advisory 2026-23480-1
SUSE Linux Micro 6.0 Kernel Important Update Vulnerability Fixes 2026-23481
SUSE Linux Micro 6.0 Key Kernel RT Live Patch 14 Advisory 2026-23482-1
SUSE Linux Micro Important Kernel Update CVE-2026-23240 to CVE-2026-64600
SUSE Linux Micro 6.0 Kernel Important Patch 2026-23484-1
SUSE Linux Micro 6.0 Kernel Important Security Update 2026-23485-1
SUSE Linux Micro 6.0 Important Kernel Live Patch 24 Advisory 2026-23486-1
SUSE Linux Micro 6.0 Kernel Important Security Update 2026-23487-1
SUSE Linux Micro 6.0 Important Kernel Live Patch 26 Advisory 2026-23488-1
SUSE Linux Micro 6.0 Important Kernel Security Patch 2026-23489-1
Rocky Linux 10 python3.14-cryptography Security Update RLSA-2026-64795
Rocky Linux 10 389-ds-base Critical Error Fixes RLSA-2026-64785
Rocky Linux Skopeo Key Denial of Service Vulnerability RLSA-2026-64818
Rocky Linux 10 git-lfs Important Denial of Service Update RLSA-2026-64788
Rocky Linux 10 RLSA-2026-64796 Valkey Important Remote Code Execution Fixes
Rocky Linux Thunderbird Significant Security Patch RLSA-2026-65159
Rocky Linux glib2 Moderate Buffer Overflow Resolution RLSA-2026-64799
Rocky Linux 10 Expat Moderate Arbitrary Code Execution RLSA-2026-64810
Rocky Linux 10 xz Moderate Buffer Overflow Fix RLSA-2026-64787
Rocky Linux OpenTelemetry Collector Denial of Service Fix RLSA-2026-65116
Rocky Linux 10 RLSA-2026-65162 gpsd Important Command Execution
Rocky Linux 10 buildah Important Denial of Service and XSS RLSA-2026-64777
Rocky Linux 10 Kernel Important Bug Fix Update RLSA-2026-64775
Rocky Linux glib2 Moderate Heap Overflow Vuln RLSA-2026-64800
Rocky Linux 9 Kernel Important Security Update 2026-64808