Menu

Latest articles

Effective Nessus Vulnerability Scans for Data Center Linux Servers
Are you certain your data center Linux servers are free from vulnerabilities? If not, you need to scan them immediately! Learn how this can be done with Nessus.
FBI Arrests Ransomware Negotiation Firm Co-Founder in ShinyHunters Probe
AlmaLinux 9 Podman Moderate Security Fix CVE-2025-58183
AlmaLinux 9 oci-seccomp-bpf-hook Key Denial of Service Update 2026-33811
AlmaLinux 9 Delve Golang Moderate Update CVE-2025-58183
AlmaLinux 9 ALSA-2025-23336 gcc-toolset-13-binutils Moderate Heap Overflow
AlmaLinux 9 python3.9 Moderate Buffer Overflow Advisories 2024-5642
AlmaLinux 9 net-snmp Important Buffer Overflow CVE-2025-68615
Two characters open up a world of typosquatting opportunities in Chromium browsers
Researchers say two characters available to typosquatters and phisherfolk can trick Chromium browsers into displaying lookalike URLs as genuine web [...]
AlmaLinux 9 mod_md Important Security Fix for CVE-2025-55753
AlmaLinux 9 OpenSSH Moderate Code Execution Vuln 2025-61984
AlmaLinux 9 git-lfs Important Symlink Arbitrary File Write CVE-2025-26625
AlmaLinux 9 libssh Moderate Security Issue CVE-2025-5987
AlmaLinux 9 Buildah Important Container Escape Vulnerability 2025-52881
AlmaLinux 9 java-17-openjdk Important Security Update 2026-22013
AlmaLinux 9 keylime Important Identity Takeover Issue CVE-2025-13609
AlmaLinux 9 Kernel Important Security Update ALSA-2026-0793 CVEs 2025-38703
AlmaLinux 9 Kernel Security Update Moderate IPv6 MAC Issue ALSA-2025-19409
AlmaLinux 9 go-rpm-macros Important Security Fix for CVE-2025-47906
AlmaLinux 9 tigervnc Important Use After Free CVE-2025-62229
AlmaLinux 9 Wireshark Important Access Issue Fix CVE-2025-13499
AlmaLinux 9 GIMP Important Remote Code Execution Fix for CVE-2025-10922
AlmaLinux 9 Kernel Update for Medium Security Issues ALSA-2025-22865
AlmaLinux 9 redis-7 Significant Security Update for RCE and DoS Issues
AlmaLinux 9 Galera MariaDB Moderate DoS Security Update ALSA-2025-19584
AlmaLinux 9 Haproxy Important DoS Vulnerability Fix ALSA-2025-21693
AlmaLinux 9 Tomcat Important Security Fixes for CVE-2025-31651
AlmaLinux 9 git-lfs Important Denial of Service Issues Fix 2025-61729
AlmaLinux 9 podman Important Security Issue CVE-2025-52881
AlmaLinux 9 libsoup Important Host Header Parsing Issue Fix 2025-14523
AlmaLinux 9 redis-7 Important RCE and DoS Flaws ALSA-2025-20955
AlmaLinux 9 Osbuild Composer Significant Denial of Service Vulnerabilities
AlmaLinux 9 ruby-4.0 Important DoS and Code Exec Threats ALSA-2026-20596
AlmaLinux 9 Firefox Important Security Update (ALSA-2025-23034)
AlmaLinux 9 MySQL Moderate DML and InnoDB Vulnerabilities ALSA-2025-23109
AlmaLinux 9 python-kdcproxy Major SSRF DoS Vulnerabilities ALSA-2025-21139
AlmaLinux 9 MySQL 8.4 Moderate DML InnoDB Threats ALSA-2025-23111
AlmaLinux 9 ALSA-2025-21462 Lasso Critical Type Confusion CVE-2025-47151
AlmaLinux 9 BIND Important Cache Poisoning Issues CVE-2025-40778
AlmaLinux 9 grafana Moderate Unbounded Allocation Issue ALSA-2025-23087
AlmaLinux 9 kernel Security Update CVE-2025-39806 Moderate Fixes
AlmaLinux 9 ALSA-2025-20963 qt5-qt3d Moderate Heap Overflow CVE-2025-11277
AlmaLinux 9 xorg-x11-server Moderate Use-After-Free CVE-2025-62229
AlmaLinux 9 Squid Important Info Disclosure 2025-20935 CVE-2025-62168
AlmaLinux 9 Introduces Moderate Update for open-vm-tools ALBA-2025-20841
AlmaLinux 9 Python3.12 Critical ALSA-2025-15007 CVE-2025-8194 Loop Fix
AlmaLinux 9 python3.11 Security Update of Moderate Severity CVE-2025-8194
AlmaLinux 9 Expat Important Memory Allocation Fix CVE-2025-59375
AlmaLinux 9 Unveils Key Sudo Update for Local Privilege Escalation Fix
AlmaLinux 9 Kernel Advisory CVE-2025-37823 Important Security Update
AlmaLinux 9 Kernel Important Security Update CVE-2025-22097
AlmaLinux 9 Kernel Important Security Update CVE-2025-37803
AlmaLinux 9 Security Update Released for GIMP – ALSA-2025-9162
Three days to TechCrunch Disrupt: What’s next for AI and software development
First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code [...]
DSA-6550-1 ghostscript – security update
AWS AgentCore security undone by prompt requesting credentials
Bob, possibly the same Bob whose conversations with Alice draw so much interest from eavesdropping Eve, was browsing a site we’ll call TechHub. The [...]
MonsterCloud CEO Zohar Pinhasi Accused of Paying Hackers, Defrauding Victims
MATCHBOIL: New tricks, same old evil intentions
ESET Research catalogs the changes of UAC-0099’s MATCHBOIL downloader from 2024 to 2026
Lightwell project filters out 400 Java library vulnerabilities
Lightwell, the open-source security initiative set up by IBM and Red Hat, has identified more than 400 previously undiscovered vulnerabilities in widely [...]
OpenAI reports three new incidents of misalignment
OpenAI continues to report incidences of “misaligned” behavior by its AI models, with three new reports dropping on Oct. 2. However, they describe [...]
$10 million bounty offered for Chinese Hafnium hacker accused of Microsoft Exchange Server mega-attack
Practical AI Integration for Modern Business Teams
As AI agents grow, vendors carve out decision-making as a separate model layer
As enterprises struggle to balance AI budgets with the demands of scaling agentic applications, they have been increasingly looking for ways to make those [...]
Citrix gives NetScaler admins another critical reason to patch
Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 [...]
Open Source Security: What 400+ Vulnerability Fixes Could Mean for Linux Users
IBM and Red Hat say their Lightwell initiative has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries.
Defense in Depth Cybersecurity: How to Build Effective Layers
Why is the orders application talking to the backup server?
vLLM Vulnerability Update Fixes RCE and Server-Crashing Flaws
The vLLM project published security advisories on October 6, 2026, identifying version 0.31.0 as the fix for remote code execution (RCE), service crashes, [...]
Linux Filesystem Bug Lets Crafted JFS Names Overwrite Memory
Deepanshu Kartikey has submitted a patch for a Linux filesystem bug that lets a crafted JFS disk image overwrite kernel memory during a directory listing.
Linux NTFS Bug Copies Crafted Index Data Before Checking Its Size
Andrey Misiurov has proposed a patch for a Linux NTFS bug that lets a crafted disk image make the kernel read beyond a memory buffer.
NFC Security Bug Lets Linux Reuse Freed UART Memory During Shutdown
Shubham Antil has submitted a revised two-patch series addressing an NFC security bug in Linux’s device-shutdown code.
Nftables Interval Bug Can Leave Linux Using a Freed Chain Reference
Jérémy Jean has confirmed that a maintainer’s proposed patch stops the reproduced failure behind an nftables interval bug.
FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices
Four days to TechCrunch Disrupt: What’s next for AI and software development
First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code [...]
Neoclouds and the enterprises that need them
I’ve been tracking the rise of neoclouds in the past couple of years, and I’ll start by admitting that the numbers are genuinely staggering. Synergy [...]
FBI Seizes Flax Typhoon Hacking Tools Linked to Chinese Contractor
US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide
The FBI announced that it has seized seven web domains linked to hacking tools allegedly operated by a Chinese security firm called Integrity Technology [...]
DSA-6549-1 xz-utils – security update
OpenStack Fixes Zaqar Flaw Exposing Other Tenants’ Queues
OpenStack disclosed a Zaqar security flaw on Oct 7, 2026 that lets an authenticated user access another project’s messaging queues.
Linux Security Update Fixes 12 X.Org and Xwayland Flaws
X.Org has issued fixes for 12 vulnerabilities in its display software.
Linux TCP Fast Open Use After Free Leaves a Packet Pointer Behind
A bug in Linux’s TCP Fast Open code can leave it reading memory that has already been released.
Apache Jackrabbit Fixes Critical WebDAV Session Hijacking Flaw
Apache disclosed a critical Apache Jackrabbit session hijacking flaw on Oct 7, 2026.
High-severity Nvidia bug could crash GPU monitoring on exposed servers
Researchers found thousands of GPU servers exposing Nvidia’s DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity [...]
Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise
The credential-hijacking Shai-Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK. Multiple security researchers [...]
Inside a brand deal scam targeting YouTube creators
A plausible-sounding sponsorship offer could mask an attempt to compromise your Google account
Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones
Fighting GenAI with GenAI: The New Email Security Landscape
The use of phishing emails as a means of stealing information or implanting damaging malware dates back to the mid-1990s. Although almost as old as the [...]
Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code
UK and Germany team up against Russian cyberattacks as Brexit rethink looms
Britain and Germany have announced a partnership to counter cyberattacks and sabotage, particularly from Russia, as Prime Minister Andy Burnham heads to [...]
FBI, French Police Seize CSAM Site Domains, Suspected Admin Arrested
AWS takes aim at runaway AI agent behavior with Strands Box
Amazon Web Services (AWS) has introduced an open-source sandbox for AI agents that allows developers to restrict their actions based on previous behavior, [...]
AI-powered data pipeline observability: Stop monitoring and start preventing
Devops tools are making it increasingly easy to monitor data pipeline failures. But in many cases, those alerts are already too late. Take marketing [...]
Cheapskates wouldn’t pay for security help, got hit by ransomware, and went bust months later
Welcome back to PWNED, the weekly column where we highlight some of the lowlights in corporate security. This week, we’ll talk about two scenarios, one [...]
Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead
The United States Department of Justice has charged a man with fraud after he allegedly told clients he could decrypt files locked up by ransomware but [...]
Smashing Security podcast #487: Clippy’s crypto comeback
DSA-6548-1 node-shell-quote – security update
DSA-6547-1 ruby-jwt – security update
DSA-6546-1 rails – security update
Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
Imagine going to a Google website at its correct URL, only to be redirected to a crim’s illegitimate copy. Attackers hijacked top-level domains, [...]
Dread Dark Web Forum Hijacked, Operators Claim Control of Domain Keys (Updated)
AWS launches open-source AI agent sandbox to prevent YOLO mode disasters
AWS has offered multiple open-source strategies for holding AI agents accountable, and now it’s adding a full-on sandbox to this stack. Dubbed Strands Box, [...]