Menu

Category Archives: All

Everything

Several security issues were fixed in strongSwan.

Ubuntu PackageKit Critical Local Privilege Escalation CVE-2026-41651
Trump’s Golden Dome gets $3.2BN of contractors and an AI sprinkle
Confidential clusters for Red Hat OpenShift: Developer Preview now available on Microsoft Azure with AMD SEV-SNP
Cybersec is a thankless job: expanding workload and shrinking pay packet
Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attempt
Microsoft updates the Windows Update Experience: You can hit pause now
ICO chief John Edwards steps back as workplace probe quietly unfolds
Google begins putting the guardrails on agentic AI
The best JavaScript certifications for getting hired
Anthropic’s magic code-sniffer: More Swiss cheese than cheddar, for now
Google Cloud Next proves what we suspected: Everything is AI now

An update that solves 25 vulnerabilities can now be installed.

Important: kernel-rt security update

Important: kernel-rt security update

Important: kernel-rt security update

How Linux Pentesting Improves Network Security
AI-Driven Cybersecurity Upgrades: 3 Strategic Uses
Tails 7.7 Surfaces Secure Boot Risk as 2026 Certificate Expiry Approaches
Boost Linux Security Through Clear and Readable Coding Practices

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.10.0esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.

Hot take: AI’s not going to kill open source code security

https://security-tracker.debian.org/tracker/DSA-6230-1

The calm before the ransom: What you see is not all there is

A breach claims the systems as well as the confidence that was, in retrospect, a major vulnerability

Understanding Log Management and Analysis Tools for Linux Systems
Crime crew impersonates help desk, abuses Microsoft Teams to steal your data

Backport security patches from OpenSSL 3.5.6

CVE-2026-35385: Fix privilege escalation via scp legacy protocol when not in preserving file mode CVE-2026-35388: Add connection multiplexing confirmation for proxy-mode multiplexing sessions CVE-2026-35387: Fix incomplete application of PubkeyAcceptedAlgorithms and

Fix CVE-2026-35535

Fix CVE-2026-40192.

Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-5713, CVE-2026-6100

Update to 147.0.7727.101 Critical CVE-2026-6296: Heap buffer overflow in ANGLE Critical CVE-2026-6297: Use after free in Proxy Critical CVE-2026-6298: Heap buffer overflow in Skia Critical CVE-2026-6299: Use after free in Prerender

Meta’s compute grab continues with agreement to deploy tens of millions of AWS Graviton cores
Germany’s sovereign AI hope changes hands
Former OpenAI research scientist launches new AI model for Tencent
GopherWhisper: A burrow full of malware

ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions

US clarifies mobile hotspots part of foreign router ban despite rarity of American made consumer kit
ShinyHunters claim they have cruise giant Carnival’s booty as 7.5M emails surface
Governments on high alert after CISA snuffs out Firestarter backdoor on fed network
More ancient Linux device support faces the chop
Intel bets the farm on AI inference to drag CPU back to the top table
Microsoft beefs up Remote Desktop security with … hard-to-read messages
It’s a myth that you need Mythos to find bugs: Open source models can do it just as well
Integrating Red Hat Lightspeed with CrowdStrike for enhanced malware detection coverage

Several security issues were fixed in GStreamer Bad Plugins.

Greece relaxes Euro biometric border entry rules amid airport chaos
Where to begin a cloud career
Why world models are AI’s next frontier

An update that solves 10 vulnerabilities, contains one feature and has one security fix can now be installed.

An update that solves nine vulnerabilities, contains one feature and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

UK gov pays public £550 to discuss Digital ID – then bans journalists from the room
Researchers find cyber-sabotage malware that may predate Stuxnet by five years
Weak security means attackers could disable all of a city’s public EV chargers
The agentic AI frenzy increases as more vendors stake their claims

https://security-tracker.debian.org/tracker/DSA-6229-1

Dev targeted by sophisticated job scam: ‘I let my guard down, and ran the freaking code’
Chinese attackers are pwning your infrastructure to use in attacks, 10 countries warn
Google pitches Agentic Data Cloud to help enterprises turn data into context for AI agents
Age checks could turn internet into an ID checkpoint, complains Proton CEO
Why Linux Logging Fails: Detection Gaps in Real-World Systems

Several security issues were fixed in league/commonmark.

American farms have a new steward for their safety net, disaster programs… Palantir
Offer customers passkeys by default, UK’s NCSC tells enterprises
Medical data of 500k Biobank volunteers listed for sale on Alibaba, UK minister reveals

Slurm could be made to send data to an arbitrary unix socket on the host.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves six vulnerabilities and has one security fix can now be installed.

An update that solves six vulnerabilities and has one security fix can now be installed.

Hybrid clouds have two attack surfaces and you’re not paying enough attention to either
Beyond the Sandbox: Container Escape Techniques Observed in Recent Research
If malware via monitor cables is a matter of national security, this might be the gadget for you
Microsoft taps Anthropic’s Mythos to strengthen secure software development
Sharing isn’t caring if it’s an admin password
How open source ideals must expand for AI
How I doubled my GPU efficiency without buying a single new card
Is your Node.js project really secure?
Pass the key, passwords have passed their sell-by date
Claude Mythos signals a new era in AI-driven security, finding 271 flaws in Firefox
Malicious pgserve, automagik developer tools found in npm registry
Another npm supply chain worm is tearing through dev environments
Smashing Security podcast #464: Rockstar got hacked. The data was junk. The secrets it revealed were not
Anthropic’s super-scary bug hunting model Mythos is shaping up to be a nothingburger
Microsoft issues out-of-band patch for critical security flaw in update to ASP.NET Core
New NGate variant hides in a trojanized NFC payment app

ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI

PackageKit could be made to install packages as the administrator.

Several security issues were fixed in strongSwan.

Multiple security issues were discovered in cpp-httplib, a C++ cross platform HTTP/HTTPS library, which could result in denial of service. For the stable distribution (trixie), these problems have been fixed in version 0.18.7-1+deb13u1. We recommend that you upgrade your cpp-httplib packages.

Maik Schaefer discovered that a TOCTOU race condition in PackageKit (a package management service over a DBus interface) could result in local privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.2.2-2+deb11u1.

Multiple vulnerabilities were fixed in strongSwan, an IKE/IPsec suite. CVE-2026-35328 A vulnerability in libtls related to the processing of the supported_versions extension in TLS that can result in an infinite loop.

An update that solves one vulnerability can now be installed.

SpaceX secures option to acquire AI coding startup Cursor for $60B
Google unleashes even more AI security agents to fight the baddies
Lateral Movement Detection Strategies for Linux Systems
France’s ‘Secure’ ID agency probes breach as crooks claim 19M records
Scotland Yard can keep using live facial recognition on people in London, say judges