Menu

Category Archives: All

Everything

Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
Vietnam to develop domestic cloud so it can ditch risky overseas operators for government workloads
AI is ready to take over Python programming, but not much else
Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs
Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files
Eyes wide open: How to mitigate the security and privacy risks of smart glasses

Smart glasses allow anyone to track and record the world around them. That could put your data and the privacy of those nearby at risk.

Mistral AI SDK, TanStack Router hit in npm software supply chain attack
GitLab CEO sees developer tool bill increasing 100-fold
US bank reports itself after slinging customer data at ‘unauthorized AI app’
Why Runtime Monitoring Is Replacing Traditional Linux Logging
Debian 14 Makes Reproducible Builds Mandatory for Linux Packages
Linux AI Tools Require Enhanced Observability for Security
Red Hat adds support for agentic AI development
Cache-poisoning caper turns TanStack npm packages toxic
Apple, Google drag cross-platform texting into the encrypted age

Several security issues were fixed in ImageMagick.

Tokenmaxxing is super dumb
A networking revolution at AWS
Kill the loading spinner with local-first data and reactive SQL
What’s new and exciting in JDK 26
Japan’s PM orders cybersecurity review to stop Mythos going full CyberZilla

Update to 148.0.7778.96 CVE-2026-7896: Integer overflow in Blink CVE-2026-7897: Use after free in Mobile CVE-2026-7898: Use after free in Chromoting CVE-2026-7899: Out of bounds read and write in V8

Update NSS to 3.122.2 Updated to Firefox 150.0.1

Update NSS to 3.122.2 Updated to Firefox 150.0.1

Update NSS to 3.122.2 Update to Firefox 150.0.1

Update NSS to 3.122.2 Update to Firefox 150.0.1

https://security-tracker.debian.org/tracker/DSA-6265-1

Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline
Cookie thieves caught stealing dev secrets via fake Claude Code installers
Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator
BWH Hotels guests warned after reservation data checks out with cybercrooks
Why Linux Servers Get Hacked More Often Than People Think
Linux Could Soon Disable Vulnerabilities Without a Reboot: Kernel Killswitch
Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads
Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged

Moderate: libpng security update

Moderate: libpng security update

Moderate: freeipmi security update

Your AI doesn’t need another database
How to add AI to an existing product (without annoying users)

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

Taiwan’s train cyber-trauma reveals a global system that’s coming off the tracks

https://security-tracker.debian.org/tracker/DSA-6264-1

https://security-tracker.debian.org/tracker/DSA-6263-1

https://security-tracker.debian.org/tracker/DSA-6262-1

https://security-tracker.debian.org/tracker/DSA-6261-1

https://security-tracker.debian.org/tracker/DSA-6260-1

Two security vulnerabilities were discovered in the Corosync cluster engine, which could result in denial of service or memory disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 3.1.7-1+deb12u2. For the stable distribution (trixie), these problems have been fixed in

Multiple security vulnerabilities were discovered in Tor, a connection- based low-latency anonymous communication system, which could result in denial of service. For the oldstable distribution (bookworm), these problems have been fixed in version 0.4.9.8-0+deb12u1.

MGASA-2026-0126 – Updated openvpn packages fix security vulnerabilities

33.0.3 Release

This is new version of exim fixing some security bugs.

Update to .NET SDK 10.0.107 and Runtime 10.0.7 Fixes: CVE-2026-40372 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.7/10.0.107.md

Linux Firewall Rules Management Challenges Kubernetes Security

It was discovered that PyJWT, a Python implementation of JSON web tokens insufficiently validated the “crit” header parameter, which could result in incomplete enforcement of authentication settings. For the oldstable distribution (bookworm), this problem has been fixed in version 2.6.0-1+deb12u1.

A security vulnerability has been discovered in libpng, a library implementing an interface for reading and writing PNG (Portable Network Graphics) files, which could leading to corrupted chunk data and potential heap information disclosure. For Debian 11 bullseye, this problem has been fixed in version

Two vulnerabilities have been discovered in the Linux kernel that may lead to local privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 6.1.170-3. We recommend that you upgrade your linux packages.

https://security-tracker.debian.org/tracker/DSA-6258-1

https://security-tracker.debian.org/tracker/DSA-6259-1

What happens when engineering teams reorganize around AI agents

Two vulnerabilities have been discovered in the Linux kernel that may lead to local privilege escalation. For Debian 11 bullseye, these problems have been fixed in version 5.10.251-4. We recommend that you upgrade your linux packages.

An update that solves two vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Fake call logs, real payments: How CallPhantom tricks Android users

ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down

Fixing the password problem is as easy as 123456

How come it’s still possible to ‘secure’ an online account with a six-digit string?

Worm rubs out competitor’s malware, then takes control
One in eight UK workers has sold their company passwords, and bosses think it’s fine
Inside Department 4: Russia’s secret school for hackers
Linux Attackers Abuse Admin Tools For Stealthy Intrusions
‘Dirty Frag’ Linux flaw one-ups CopyFail with no patches and public root exploit
Ubuntu Dirty Frag Important Local Privilege Escalation Exploit
Meta U-turns on encryption push for Instagram as DMs go plaintext

Important: git-lfs security update

Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in remote code execution, privilege escalation, denial of service or information disclosure. For Debian 11 bullseye, these problems have been fixed in version 2.4.67-1~deb11u1.

Hackers ate my homework: Educational SaaS Canvas down after cyberattack

Lua could be made to crash or run programs as your login if it opened a specially crafted file.

Meta fights Ofcom over how many billions count as billions
Sri Lanka makes 37 arrests as it raids another scam centre
12 model-level deep cuts to slash AI training costs
When cloud giants meddle in markets
Python isn’t always easy

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes “Content-Length” over “Transfer-Encoding: chunked” when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse

Validate RSA_public_encrypt() result in RSASVE

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes “Content-Length” over “Transfer-Encoding: chunked” when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse

13 new critical holes in JavaScript sandbox allow execution of arbitrary code

https://security-tracker.debian.org/tracker/DSA-6256-1

https://security-tracker.debian.org/tracker/DSA-6257-1

https://security-tracker.debian.org/tracker/DSA-6253-1

https://security-tracker.debian.org/tracker/DSA-6254-1

https://security-tracker.debian.org/tracker/DSA-6255-1

Mozilla boasts Mythos boosted Firefox bug cull

https://security-tracker.debian.org/tracker/DSA-6249-1

The best new features in Python 3.15
Anthropic response to 1-click pwn: Shouldn’t have clicked ‘ok’
Container Security Misconfigurations That Still Go Unnoticed
60% of MD5 password hashes are crackable in under an hour
Teradata launches platform for enterprise AI agents moving beyond pilots
CrackArmor AppArmor Flaws Put Linux Containers and Snap Sandboxes at Risk