Menu

Category Archives: All

Everything

Oracle Linux 9 dbus-broker Moderate Session Bus DoS Fix ELSA-2026-61355-0
Oracle Linux 9 libxml2 Moderate Security Issue ELSA-2026-61247-0
Oracle 9 pam Moderate Vulnerability Fix ELSA-2026-60224-0
Oracle Linux 9 OpenSSL FIPS Provider Moderate Security Flaw ELSA-2026-27744
Oracle Linux 9 Image Builder Important CVEs ELSA-2026-23228
Oracle Linux 9 microcode_ctl Important Fix ELSA-2026-500239
Oracle Linux 8 ELSA-2026-62583-0 Node.js Important Security Update
Oracle FreeRDP Important Security Update ELSA-2026-62571-0
Oracle GIMP Important Security Update ELSA-2026-62507-0
Oracle Linux 8 ELSA-2026-62425-0 Critical Fix for CVE-2026-18300
Oracle 8 gegl04 Important Security Update ELSA-2026-62420-0 CVE-2026-18300
Oracle Linux 8 ELSA-2026-62407-0 Grafana Important Remote Access Issues
Oracle Linux 8 PHP Important Bug Fixes Advisory ELSA-2026-62334-0
Oracle Linux 8 NodeJS Important Security Fix ELSA-2026-62219-0
Oracle Linux 8 libssh Moderate Patch Vulnerability ELSA-2026-62218-0
Oracle Linux 8 ELSA-2026-62144-0 Wget Moderate Bug Fixes
Oracle Linux 8 iperf3 Important CVE-2026-71217 ELSA-2026-61257-0
Oracle Linux 8 ELSA-2026-61248-0 libxml2 Moderate CVE-2026-11979
Oracle 7 Kernel Important Security Update CVE-2026-31598 ELSA-2026-500238
Rust 1.98.1 fixes miscompilation bug
Hot on the heels of the Rust 1.98.0 release, the Rust team has published Rust 1.98.1, an update that fixes a miscompilation in vtable generation. Rust [...]
Why Tails OS Is Changing How a Linux Distro Ships Security Updates
Tails OS is changing the speed of its entire Linux distribution because one of its most security-sensitive applications is tied to the system image. Tails [...]
Linux Security Roundup: Remote Access, PostgreSQL, and Sandbox Fixes to Prioritize Now
The Linux security news from August 27 through September 3 brought serious fixes for remote access software, PostgreSQL, sandboxing tools, local system [...]
CISA Flags Exploited Kestra Flaw That Lets Attackers Run Commands in Linux Containers
A newly confirmed Kestra vulnerability is being exploited in the wild. CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on Sep 2, [...]
AI Is Learning to Turn Linux Kernel Vulnerabilities Into Exploit Chains
A kernel crash tells defenders that something went wrong. It does not show whether an attacker can turn that failure into a useful capability, combine [...]
What Nvidia’s $13B acquisition of Hugging Face means for AI model choice
When Nvidia said Thursday that it plans to pay $13 billion to acquire Hugging Face, the question arose of whether the open AI platform would remain open [...]
DSA-6481-1 firefox-esr – security update
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from [...]
I’ve been deepfaked: What do I do?
Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal
Drowning in CVEs and thirsty for answers? Try CTEM
A decade or two ago, board executives asked “why should I care about cybersecurity?” Five years ago, they were asking “Are you patching [...]
Internet Routing Attack Sent Malicious Updates to Linux Servers
Virtualizor has confirmed that a BGP hijack redirected traffic for part of its update infrastructure and allowed an attacker-controlled server to deliver a [...]
Why DNS Attacks Can Outrun Linux Security Monitoring
A Linux host intrusion prevention system can fail even when the protected server still has spare CPU. If its logging path cannot record and move events as [...]
Linux Patch Addresses Network Code Bug That Reads Past Memory
A Linux kernel patch series submitted on Sep 1, 2026, stops an out-of-service Logical Link Control socket from indexing below two connection-state tables. [...]
Cybercrooks trawl Fishbrain to net password hashes
Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking [...]
Continuous Linux Security: Why a Hardening Checklist Is Not Enough
A Linux server can be carefully hardened before it reaches production and still become less secure over time. Hardening means reducing unnecessary [...]
Meta upgrades Muse Spark for long-horizon coding without raising API prices
Meta is upgrading its Muse Spark family with a new model aimed at long-horizon coding tasks and agentic software development while keeping its standard API [...]
UK’s Online Safety Act has made ‘absolutely no difference,’ kids say
Children have told England’s Children’s Commissioner, Dame Rachel de Souza, that the UK’s Online Safety Act (OSA) “has made [...]
Running AI agents in sandboxes with Microsoft Execution Containers
One of the problems facing those who develop agents today, especially when building agents that run on edge systems with a mix of local and cloud AI, is [...]
How to keep your mission-critical cloud workloads running
Entrusting mission-critical workloads in the cloud puts a lot of pressure on IT operations to build resilience into data infrastructure they don’t even own [...]
TechCrunch Disrupt: What’s next for AI and software development
First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code [...]
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
PWNED Welcome back to PWNED, where we talk about organizations that are independently self-owned. This week’s tale of toxic tech involves a disgruntled [...]
To keep the AI hacking genie bottled up, try one-way networks
To prevent frontier AI models breaking out of test environments and collaborating to hack other companies, we may have to rethink the network architectures [...]
Oracle Linux 9 wget Moderate Buffer Overflow Fix ELSA-2026-62143-0
Oracle Linux 9 gimp Important Fixes for Vulnerabilities ELSA-2026-61587-0
Oracle Linux 9 iperf3 Important JSON Value Check Fix ELSA-2026-61389-0
Oracle Linux 9 nodejs Important Security Patch ELSA-2026-61386-0
Oracle Linux 9 Nodejs Security Advisory ELSA-2026-61383 Critical CVEs
Oracle Linux 9 freerdp Important CWCVEs Buffer Overflow ELSA-2026-61379-0
Oracle Linux 9 xmlrpc-c Important HTML Injection Fix ELSA-2026-61316-0
Oracle Linux 9 Pipewire Moderate Security Advisory ELSA-2026-61240-0
Oracle Linux 9 Golang Important Bug Fix Advisory ELSA-2026-60304-0
Oracle Nginx Important Denial of Service Fix ELSA-2026-59490
Important CVEs for Oracle Linux 9 xorg-x11-server-Xwayland ELSA-2026-38490
Oracle Linux 10 wget Moderate Bug Fixes Advisory ELSA-2026-62142-0
Fedora 45 Dracut Essential Root Privilege Correction 2026-5bf73fe397
rustup 1.29.1 brings concurrency improvements
The team behind the rustup installer for the Rust programming language has released an update to the command-line utility. Announced September 1, rustup [...]
Fedora 44 Syncthing CVE-2026-40898 Denial of Service Advisory
Fedora 44 Firefox Important Heap Buffer Overflow Vuln 2026-42a3a95e62
Fedora 44 NSS Heap Buffer Overflow Patch Update 2026-42a3a95e62
Fedora 44 mingw-gstreamer1-plugins-bad-free Critical Remote Code Execution
Fedora 44 mingw-gstreamer1 Critical Remote Code Exec Issues 2026-e6ca27403f
Fedora 44 mingw-gstreamer1-plugins-base Has Serious Remote Code Exec Risks
Fedora 44 mingw-gstreamer1-plugins-good Remote Code Execution Vulnerability
Fedora 44 mingw-expat Denial of Service Fix Update 2026-f5e2a6b9b5
Fedora 44 mingw-openexr Update Addresses Integer Overflow Vulnerability
Fedora 44 ProFTPD Security Bugfix Advisory 2026-f073efe2f3
Fedora 43 Exiv2 Bugfix Denial of Service Issues 2026-2854e48ee4
Fedora 43 gvfs Critical Heap Overflow Disclosures and Fixes 2026-571b7e1505
Fedora 43 Firefox Heap Overflow Security Advisory 2026-208add2041
Fedora 43 nss Important Heap Buffer Overflow Advisory 2026-208add2041
Fedora 43 FreeRDP Update to 3.31.0 Advisory FEDORA-2026-e0f5d28f57
Fedora 43 mingw-gstreamer1-plugins-base Critical RCE Vulnerability Update
Fedora 43 mingw-gstreamer1 Plugins Vulnerability High Risk RCE Alert
Fedora 43 mingw-openexr Denial of Service and Overflow Vulnerabilities
Fedora 43 mingw-expat Update Denial of Service CVE-2026-72522 Advisory
Fedora 43 ProFTPD Update Important FTP Bugfixes FEDORA-2026-0abbe10cdc
SUSE Texlive Moderate Heap Use-After-Free CVE-2026-63729 2026-3924-1
SUSE Bzip2 Low Off-By-One Error Issue Vulnerability 2026-3925-1
DSA-6482-1 chromium – security update
Why Patched Linux Servers Still Fail a Penetration Test
A patched Linux server can still fail a penetration test because patch status cannot show whether an attack path remains open.
How to Prevent DNS Leaks and Secure Proxy Credentials on Linux Systems
Using a proxy on Linux changes how web traffic reaches its destination, but it does not automatically protect every part of the connection. DNS requests [...]
Smashing Security podcast #483: This AI helps thieves steal your iPhone
Rocky Linux 10 Kernel Advisory RLSA-2026-61887 Important Security Fixes
Rocky Linux Nodejs Key Filesystem Access Memory Issues RLSA-2026-62583
Rocky Linux GIMP Important Remote Code Exec Advisory RLSA-2026-62507
Ubuntu 18.04 LTS Linux Kernel Important WiFi Injection Threat USN-8715-1
Ubuntu 20.04 18.04 Kernel Important Threat Correction USN-8714-1
Ubuntu 20.04 Linux Kernel Important WiFi Issue USN-8661-4
Claude Mythos only model to complete full cyber kill chain, experts say
Despite what we saw with OpenAI’s models going rogue, creating message boards, and breaking into Hugging Face, only one advanced AI model – [...]
Debian Firefox-ESR Critical Issues Execution CVE-2026-16365 DSA-6481-1
DSA-6480-1 keystone – security update
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
A human ransomware crook used frontier AI models to breach an enterprise network in less than 10 hours, an intrusion Unit 42 says would normally take human [...]
SUSE dovecot22 Critical Denial of Service Issues Fix Advisory 2026-3919-1
SUSE libgcrypt Moderate DoS Issue Fix Advisory SUSE-SU-2026-3921-1
SUSE vim Key Security Update Mitigates Risks of Code Execution 2026-23391-1
SUSE Linux Micro 6.2 Gzip Moderate Buffer Overflow Vuln 2026-23392-1
SUSE vim Important Security Fixes Advisory 2026-23393-1 CVE-2026-73070
SUSE dhcpcd Moderate Memory Leak and DoS Vuln 2026-23400-1
SUSE Python Cryptography Moderate PKCS#7 Timing CVE-2026-69247
SUSE udisks2 Significant Local Privilege Escalation Patch 2026-23405-1
SonicWall’s SMA1000 boxes under active attack again
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and [...]