Menu

Category Archives: All

Everything

Important: kernel security update

Important: 389-ds:1.4 security update

Important: xorg-x11-server security, bug fix, and enhancement update

Important: xorg-x11-server-Xwayland security, bug fix, and enhancement update

Important: xorg-x11-server security, bug fix, and enhancement update

Important: xorg-x11-server-Xwayland security, bug fix, and enhancement update

Important: dracut security update

Important: postfix security update

Important: rsync security, bug fix, and enhancement update

Important: 389-ds-base security, bug fix, and enhancement update

Moderate: yggdrasil-worker-package-manager security update

Important: hplip security update

Important: dracut security update

Important: tomcat security update

Important: valkey security update

Important: fence-agents security update

Important: podman security update

Important: rsync security update

Important: 389-ds-base security, bug fix, and enhancement update

Important: dracut security update

An update that solves 5 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Why Amazon hates ‘human-in-the-loop’ AI governance

https://security-tracker.debian.org/tracker/DSA-6351-1

Researchers grow a hypothesis tree for AI coding agents

Important: tomcat security update

Important: valkey security update

Important: fence-agents security update

Important: podman security update

Important: rsync security update

Important: 389-ds-base security, bug fix, and enhancement update

Europe’s Open Source Strategy Takes Aim at Software Security’s Maintenance Problem
Killing me gently: Inside Gentlemen’s EDR killer framework

ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen

OpenStack Keystone Flaws Expose Multiple Paths to Cloud Privilege Escalation
Solving an ARD problem in AI: Agentic Resource Discovery

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

OpenAI gets the attention it needs from AI researcher Noam Shazeer
Researchers drop checkm8-style BootROM exploit for A12 and A13 iPhones
Apple’s Hide My Email tweak leaves privacy fans fuming

An update that solves 3 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 9 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 14 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 40 vulnerabilities can now be installed.

Google, Microsoft offer specs to help you prove your AI is behaving nicely
Imposter scams cost Americans $3.5 billion in 2025 – and it’s getting worse
Fortinet FortiSandbox Critical Command Execution Risk Exploit 2026-39813
Everything’s bigger and better in Texas – even data breaches

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

Britain’s privacy watchdog quits after ‘poor judgment’ admission
Rights groups brand Home Office’s AI age guesser for asylum-seekers as biased and inaccurate

Important: dracut security update

Important: hplip security update

Moderate: yggdrasil-worker-package-manager security update

Important: dracut security update

Important: hplip security update

Important: dracut security update

Moderate: yggdrasil-worker-package-manager security update

Important: hplip security update

Important: 389-ds-base security, bug fix, and enhancement update

Moderate: yggdrasil-worker-package-manager security update

Important: rsync security, bug fix, and enhancement update

Important: 389-ds-base security, bug fix, and enhancement update

Important: postfix security update

AWS aims to take the pain out of RAG with Bedrock Managed Knowledge Base
Write cleaner and faster Python code
Cloud at 20: How AWS shaped enterprise IT

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.12.0esr-1~deb11u1. For Debian 12 bookworm, these problems have been fixed in version

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, bypass of the same-origin policy, privilege escalation, information disclosure, spoofing or sandbox escape. For Debian 11 bullseye, these problems have been fixed in version

Important: xorg-x11-server security, bug fix, and enhancement update

Important: dracut security update

Important: xorg-x11-server-Xwayland security, bug fix, and enhancement update

Important: xorg-x11-server-Xwayland security, bug fix, and enhancement update

Important: xorg-x11-server security, bug fix, and enhancement update

Important: 389-ds:1.4 security update

Important: kernel security update

Important: dracut security update

AI coding agents may be getting bad instructions from ‘smelly’ config files

Update NSS to 3.124.0 Update to Firefox 152.0

Update NSS to 3.124.0 Update to Firefox 152.0

Update to 149.0.7827.114 CVE-2026-12007: Use after free Core CVE-2026-12008: Use after free DigitalCredentials CVE-2026-12009: Insufficient validation of untrusted input Accessibility CVE-2026-12010: Heap buffer overflow GPU

Ongres Scram update and security fix.

This update fixes a command injection issue resulting from the use of the 2-argument form of open (CVE-2026-11526).

Upgrade to 4.4.2 upstream version.

Changes: 6.17 2026-05-19 23:11:06Z Fix CVE-2026-8450 (affects 6.15 and earlier): 2-arg open() in send_file() enabled RCE / arbitrary file write / response-body exfiltration when a string argument was derived from attacker-

https://security-tracker.debian.org/tracker/DSA-6353-1

https://security-tracker.debian.org/tracker/DSA-6354-1

Security update

Security update

Security update

Security update

Several security issues were fixed in LXD.