Menu

Category Archives: Security

Articles about security

AI coding agents may be getting bad instructions from ‘smelly’ config files

Update NSS to 3.124.0 Update to Firefox 152.0

Update NSS to 3.124.0 Update to Firefox 152.0

Update to 149.0.7827.114 CVE-2026-12007: Use after free Core CVE-2026-12008: Use after free DigitalCredentials CVE-2026-12009: Insufficient validation of untrusted input Accessibility CVE-2026-12010: Heap buffer overflow GPU

Ongres Scram update and security fix.

This update fixes a command injection issue resulting from the use of the 2-argument form of open (CVE-2026-11526).

Upgrade to 4.4.2 upstream version.

Changes: 6.17 2026-05-19 23:11:06Z Fix CVE-2026-8450 (affects 6.15 and earlier): 2-arg open() in send_file() enabled RCE / arbitrary file write / response-body exfiltration when a string argument was derived from attacker-

https://security-tracker.debian.org/tracker/DSA-6353-1

https://security-tracker.debian.org/tracker/DSA-6354-1

Security update

Security update

Security update

Security update

Several security issues were fixed in LXD.

An update that solves 11 vulnerabilities can now be installed.

An update that solves 11 vulnerabilities can now be installed.

An update that solves 11 vulnerabilities can now be installed.

An update that solves 11 vulnerabilities can now be installed.

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in version 1:140.12.0esr-1~deb13u1. We recommend that you upgrade your thunderbird packages.

Several security issues were fixed in libheif.

Several security issues were fixed in Net::CIDR::Lite.

Several security issues were fixed in Vim.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, bypass of the same-origin policy, privilege escalation, information disclosure, spoofing or sandbox escape. For the stable distribution (trixie), these problems have been fixed in

Dolibarr could be made to run programs if it received specially crafted network traffic.

Several security issues were fixed in kitty.

It was discovered that atril, the MATE document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened. For the stable distribution (trixie), this problem has been fixed in version 1.26.2-4+deb13u1.

Several security issues were fixed in Go Cryptography.

Security update

Several security issues were fixed in Tomcat.

Protecting legacy OT systems against modern cyberthreats

Many manufacturing plants depend on OT systems that stay in service for many years. That long run can hide significant cybersecurity risks.

Navigating the future: Schiphol Airport’s journey to shift-left platform engineering

An update that solves three vulnerabilities can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 4 vulnerabilities can now be installed.

An update that solves 3 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 3 vulnerabilities can now be installed.

Google told researcher ‘Nice catch!’ Then denied bug bounty for flaw it still hasn’t fixed

ldns could be made to accept spoofed DNS responses.

Databricks targets AI operations bottlenecks with ZeroOps

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

France’s OVHcloud bets on frontier AI as Europe seeks alternatives to US models

An update that fixes one vulnerability is now available.

Angular Signals in practice: Building a signal-first form in Angular
Why AI coding debt is different

Security update

Security update

Security update

Major US carrier stored credit card info in the clear, employee learned on first day

A vulnerability was discoverd in Nginx, a high-performance web and reverse proxy server, which could result in remote code execution and denial of service. For Debian 11 bullseye, this problem has been fixed in version 1.18.0-6.1+deb11u7.

Cyber offenses now account for around a third of all crime across Asia and South Pacific

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves six vulnerabilities and contains one feature can now be installed.

# Security update for helm Announcement ID: SUSE-SU-2026:2439-1 Release Date: 2026-06-17T14:48:27Z Rating: important References:

Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed

New openssl packages are available for Slackware 15.0 and -current to fix security issues.

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

New libidn packages are available for Slackware 15.0 and -current to fix security issues.

New bind packages are available for Slackware 15.0 and -current to fix a security issue.

# Security update for xwayland Announcement ID: SUSE-SU-2026:2426-1 Release Date: 2026-06-17T09:50:05Z Rating: important References:

An update that solves one vulnerability can now be installed.

njs could be made to crash or run programs if it received a specially crafted input.

Massive password-stealing attack hits 75k Fortinet firewalls
FishMonger’s arsenal upgraded: SprySOCKS for Windows

ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness

Critical Joomla JCE RCE Added to CISA KEV as Attacks Target Linux Web Servers
Malicious JetBrains Plugins: The IDE Is Now a Supply-Chain Attack

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

QR Code Phishing Linux Quishing Risks and Mitigation Strategies
FreeRDP 3.27 Raises the Baseline for Secure Remote Access
SimpleHelp Authentication Bypass Exposes Remote Access Security Risk

Several security issues were fixed in GStreamer Bad Plugins.

AWS targets software release bottlenecks with DevOps Agent update
Digital sovereignty needs an operating model
Cisco adds another SD-WAN box to max-severity bug advisory