Menu

Category Archives: All

Everything

This month in security with Tony Anscombe – April 2026 edition

Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 – here’s some of what made the headlines this month

Enterprise Spotlight: Transforming software development with AI
Seccomp, AppArmor, SELinux: Where Linux Security Controls Fall Short
Ubuntu Copy Fail High Local Privilege Escalation Threat Advisory 2026-31431
First reports come in of victims of critical cPanel vuln as ‘millions’ of sites potentially exposed
Why Memory Safety Is Becoming a Core Requirement in Modern Software

Three security vulnerabilities were discovered in libexif, a library to reads and writes EXIF metainformation from and to images files, that can causes crashes or information leaks. CVE-2026-32775 If the exif_mnote_data_get_value function in MakerNotes gets passed

Important: libtiff security update

Important: xorg-x11-server-Xwayland security update

Important: yggdrasil-worker-package-manager security update

Important: yggdrasil security update

Important: vim security update

OpenAI locks GPT-5.5-Cyber behind velvet rope despite slamming Anthropic for doing exactly that
Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down
Passport to £££: Home Office adds £216M to travel doc contract before a single bid’s been placed
Running AI in the cloud is easy – and expensive
Are we ready to give AI agents the keys to the cloud? Cloudflare thinks so

https://security-tracker.debian.org/tracker/DSA-6239-1

https://security-tracker.debian.org/tracker/DSA-6197-3

https://security-tracker.debian.org/tracker/DSA-6240-1

https://security-tracker.debian.org/tracker/DSA-6242-1

https://security-tracker.debian.org/tracker/DSA-6243-1

The never-ending supply chain attacks worm into SAP npm packages, other dev tools
Bot her emails: most modern phishing campaigns are AI-enabled
FBI cyber boss: China’s hacker-for-hire ecosystem ‘out of control’
Google’s fix for critical Gemini CLI bug might break your CI/CD pipelines
French prosecutors link 15-year-old to mega-breach at state’s secure document agency
Redefining security data: Red Hat’s new VEX experience heading to Red Hat Summit 2026

Important: vim security update

Important: PackageKit security update

Important: xorg-x11-server security update

Nearly half of UK businesses pwned last year as phishing keeps doing the job like it’s 2005
What type of ‘C2 on a sleep cycle’ do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia
Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or sandbox escape. For Debian 11 bullseye, these problems have been fixed in version 140.10.1esr-1~deb11u1.

SAP npm package attack highlights risks in developer tools and CI/CD pipelines
Harness teams of agentic coders with Squad
Making AI work for databases
Britain’s £6B armoured sickener Ajax cleared for duty despite injuring troops

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats
Finance company stores DB credentials in helpfully labeled spreadsheet
Linux cryptographic code flaw offers fast route to root
Smashing Security podcast #465: This developer wanted to cheat at Roblox. It cost millions
Researchers move in the right direction, develop powerful GPS interference alarm
Microsoft’s patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack
Legacy TLS tour continues with Exchange Online blocking old versions from July 2026
The End of Patch and Pray: How Rust Is Reshaping Memory Safety in Linux
CISA flags data-theft bug in NSA-built OT networking tool
GitHub: Woah, a genuinely helpful AI-assisted bug report that isn’t total slop. Here, Wiz, take this wad of cash

Several security issues were fixed in OpenSSH.

An update that solves two vulnerabilities and has one security fix can now be installed.

Alleged Silk Typhoon hacker extradited to the United States to face charges

Multiple vulnerabilities where identified in polkit, a toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes. CVE-2021-4115 Kevin Backhouse of GitHub Security Lab (GHSL) found that there is a

EU waves through open source age-check tool to keep kids safe online
Critical GitHub RCE bug exposed millions of repositories

PackageKit could be made to install packages as the administrator.

Oracle NetSuite announces AI coding skills for SuiteCloud developers
GoDaddy customer claims registrar transferred 27-year-old domain without any security checks
Why it’s so hard to create stand-alone Python apps
A new challenge for software product managers

An update that solves 14 vulnerabilities and has five security fixes can now be installed.

An update that solves 14 vulnerabilities and has five security fixes can now be installed.

30 ClawHub skills secretly turn AI agents into a crypto swarm
More fake extensions linked to GlassWorm found in Open VSX code marketplace

https://security-tracker.debian.org/tracker/DSA-6237-1

https://security-tracker.debian.org/tracker/DSA-6236-1

https://security-tracker.debian.org/tracker/DSA-6231-1

Don’t pay Vect a ransom – your data’s likely already wiped out
Kernel Hardening Trends: Whats Changing in Upstream Security Controls
Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leak

Important: gdk-pixbuf2 security update

Important: firefox security update

Important: kernel security update

Important: sudo security update

Important: grafana security update

Important: firefox security update

GitHub shifts Copilot to usage-based billing, signaling a new cost model for enterprise AI tools
Xiaomi releases MIT‑licensed MiMo models for long‑running AI agents
OpenAI’s Symphony spec pushes coding agents from prompts to orchestration
SUSE’s sovereignty pitch meets an inconvenient $6 billion question
Enterprise AI is missing the business core
The front-end architecture trilemma: Reactivity vs. hypermedia vs. local-first apps
French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches

https://security-tracker.debian.org/tracker/DSA-6232-1

https://security-tracker.debian.org/tracker/DSA-6233-1

https://security-tracker.debian.org/tracker/DSA-6234-1

https://security-tracker.debian.org/tracker/DSA-6235-1

Ongoing supply-chain attack ‘explicitly targeting’ security, dev tools
Medical and utility tech companies hacked by digital intruders

Several security issues were fixed in nginx.

Pillow could be made to crash if it opened a specially crafted file.

HAProxy could be made to expose sensitive information over the network.

Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile.

ClamAV could be made to crash if it opened a specially crafted HTML file.

Several security issues were fixed in strongSwan.

Ubuntu PackageKit Critical Local Privilege Escalation CVE-2026-41651
Trump’s Golden Dome gets $3.2BN of contractors and an AI sprinkle
Confidential clusters for Red Hat OpenShift: Developer Preview now available on Microsoft Azure with AMD SEV-SNP