Menu

Category Archives: All

Everything

hex_core ver. 0.12.2

Rename from golang-honnef-tools and update to 2026.1

MCP C# SDK 1.0 arrives with improved authorization server discovery
Firefox taps Anthropic AI bug hunter, but rancid RAM still flipping bits
Spyware disguised as emergency-alert app sent to Israeli smartphones
How hackers bypassed MFA with a $120 phishing kit – until a global takedown shut it down
Cisco warns of two more SD-WAN bugs under active attack
Microsoft spots ClickFix campaign getting users to self-pwn on Windows Terminal
Son of government contractor arrested after alleged $46M crypto heist from US Marshals
Microsoft finally gets around to fixing Windows 10 Recovery Environment after breaking it in October
Microsoft finally gets around to fixing Windows 10 Recovery Environment after breaking it in October
Transport for London says 2024 breach affected 7M customers, not 5,000
Transport for London says 2024 breach affected 7M customers, not 5,000
Why local-first matters for JavaScript
Why enterprises are still bad at multicloud

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 145.0.7632.159-1~deb12u1.

Important: postgresql16 security update

Important: postgresql16 security update

Rust 1.94 arrives with array windows to iterate slices
Google says spyware makers and China-linked groups dominated zero-day attacks last year
Google says spyware makers and China-linked groups dominated zero-day attacks last year
Visual Studio Code previews agent plugins
Iran intelligence backdoored US bank, airport, software outfit networks
Iran intelligence backdoored US bank, airport, software outfit networks
UK watchdog eyes Meta’s smart glasses after workers say they ‘see everything’
UK watchdog eyes Meta’s smart glasses after workers say they ‘see everything’
How SMBs use threat research and MDR to build a defensive edge

We speak to Director of ESET Threat Research Jean-Ian Boutin about where solutions that blend advanced technology with human expertise provide the most practical value for businesses

The revenge of SQL: How a 50-year-old language reinvents itself
What I learned as an undercover agent on Moltbook
OpenAI developing GitHub rival as AI coding platform race intensifies
Smashing Security podcast #457: How a cybersecurity boss framed his own employee
WebAssembly proposal touted to improve Wasm web integration
MCP security: Implementing robust authentication and authorization

https://security-tracker.debian.org/tracker/DSA-6157-1

‘Hundreds’ of Iranian hacking attempts have hit surveillance cameras since the missile strikes
‘Hundreds’ of Iranian hacking attempts have hit surveillance cameras since the missile strikes
Malware-laced OpenClaw installers get Bing AI search boost
LexisNexis confirms data breach at Legal & Professional arm, some customer records affected
Kaspersky dismisses claims Coruna iPhone exploit kit is connected to NSA-linked operation
Linux Security Strategies for Cloud and IoT Environments
Protecting education: How MDR can tip the balance in favor of schools

The education sector is notoriously short on cash, but rich in assets for threat actors to target. How can managed detection and response (MDR) help learning institutions regain the initiative?

An ode to craftsmanship in software development
The right way to architect modern web applications
What I learned using Claude Sonnet to migrate Python to Rust
Google feels the need for security speed, so will ship Chrome updates every two weeks
Angular releases patches for SSR security issues
Dev stunned by $82K Gemini bill after unknown API key thief goes to town
Postman API platform adds AI-native, Git-based workflows
Chat at your own risk! Data brokers are selling deeply personal bot transcripts
Cyberwarriors elevated to big leagues in US war with Iran
They seized $4.8m in crypto… then gave the master key to the internet
Turns out most cybercriminals are old enough to know better
Until last month, attackers could’ve stolen info from Perplexity Comet users just by sending a calendar invite
Chrome Gemini panel became privilege escalator for rogue extensions
Cybercriminals swipe 15.8M medical records from French doctors ministry
Cloud architects earn the highest salaries
Under the hood with .NET 11 Preview 1
Why AI requires rethinking the storage-compute divide
Gamers furious as indie studio Cloud Imperium quietly admits to data breach
Phish of the day: Microsoft OAuth scams abuse redirects for malware delivery

https://security-tracker.debian.org/tracker/DSA-6155-1

https://security-tracker.debian.org/tracker/DSA-6156-1

Rust developers have three big worries – survey
Iran’s cyberwar has begun
UK businesses told to brace cyber defenses amid Iran conflict risk
Buyer’s guide: Comparing the leading cloud data platforms
Memory scalpers hunt scarce DRAM with bot blitz
Scammers try to SIM-swap Dubai citizens hours after Iranian missile strikes
FinOps for agents: Loop limits, tool-call caps and the new unit economics of agentic SaaS
AI makes networking matter again
UK government’s Vulnerability Monitoring System is working – fixes flow far faster
South Korea’s tax office apologizes for leaking seed phrase to seized crypto
AI trust through open collaboration: A new chapter for responsible innovation

https://security-tracker.debian.org/tracker/DSA-6154-1

https://security-tracker.debian.org/tracker/DSA-6153-1

Denizens of DEF CON are ‘fed up with government’
This month in security with Tony Anscombe – February 2026 edition

In this roundup, Tony looks at how opportunistic threat actors are taking advantage of weak authentication, unmanaged exposure, and popular AI tools

What Is ClamAV? A Linux Admins Guide to Risk, Monitoring, and Real-World Use

https://security-tracker.debian.org/tracker/DSA-6152-1

Double whammy: Steaelite RAT bundles data theft, ransomware in one evil tool
Suspected Nork digital intruders caught breaking into US healthcare, education orgs
Ransomware payments cratered in 2025, but attacks surged to record highs
French DIY etailer ManoMano admits customer data stolen
Cops back Dutch telco Odido after second wave of ShinyHunters leaks
Mobile app permissions (still) matter more than you may think

Start using a new app and you’ll often be asked to grant it permissions. But blindly accepting them could expose you to serious privacy and security risks.

Your staff are your biggest security risk: AI is making it worse
Rapid AI-driven development makes security unattainable, warns Veracode
Notorious ransomware gang allegedly blackmailed by fake FSB officer
Scattered Lapsus$ Hunters auditioning female voices to sharpen social engineering
Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover
Understanding the Snort NIDS: What It Changes in Your Monitoring and Risk Model
Claude collaboration tools left the door wide open to remote code execution
Smashing Security podcast #456: How to lose friends and DDoS people

https://security-tracker.debian.org/tracker/DSA-6149-1

https://security-tracker.debian.org/tracker/DSA-6150-1

The nervous system gets a soul: why sovereign cloud is telco’s real second act

https://security-tracker.debian.org/tracker/DSA-6151-1