Menu

Category Archives: Security

Articles about security

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 201 vulnerabilities, contains six features and has 41 security fixes can now be installed.

Infected Red Hat npm packages expose developer credentials

XZ Utils could be made to crash or run programs as your login if it received specially crafted input.

Linux Persistence Hunting: The 5 Techniques Security Teams Miss Most
Red Hat npm Package Compromise Highlights a Growing Supply Chain Problem
Claude celebrates Anthropic’s stock market float with blockbuster … outage

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Northern Ireland cops issue PSA after official phone number spoofed by scammers
Attack targeting OpenAI Codex users exposes AI software supply chain risks
Will the hyperscalers own AI workloads forever?
What will AI-first UX look like?

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Security update

Security update

Security update

Security update

Security update

A vulnerability was discovered in yelp, the GNOME help browser, that allows a crafted help document to read files accessible to the user and exfiltrate them to a remote server through resources loaded by the embedded web view. When yelp is launched from a sandboxed application (for example via the Flatpak OpenURI portal), this also […]

updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the

keep GTK4 in rawhide for now switch to GTK4 for GVim Fix CVE-2026-46483

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl’s built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.

Update to 1.25.1 (rhbz#2480119) Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto Networks, for the report.

CVE-2026-27851: lib-var-expand: Safe filter marks all following pipelines safe. CVE-2026-33603: auth: CRAM-SHA-*-PLUS channel binding could be faked. MITM attacker with a certificate trusted by the client could have bypassed the requirement for channel binding. CVE-2026-40020: IMAP folders can be shared-spammed to everyone.

This is an update fixing CVE-2026-43964.

Update to Samba 4.24.3 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238

Update to Samba 4.24.3 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238

Update to 3.26.4, fixes CVE-2026-8631, CVE-2026-8632

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl’s built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.

CVE-2026-27851: lib-var-expand: Safe filter marks all following pipelines safe. CVE-2026-33603: auth: CRAM-SHA-*-PLUS channel binding could be faked. MITM attacker with a certificate trusted by the client could have bypassed the requirement for channel binding. CVE-2026-40020: IMAP folders can be shared-spammed to everyone.

This is an update fixing CVE-2026-43964.

https://security-tracker.debian.org/tracker/DSA-6319-1

https://security-tracker.debian.org/tracker/DSA-6320-1

Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week

https://security-tracker.debian.org/tracker/DSA-6316-1

Election interlopers register 5K+ domains, hope to catch some voting phish
Why Linux Rootkits Still Matter in Cloud and VMware Environments 

An update that solves 60 vulnerabilities and has three security fixes can now be installed.

An update that solves 60 vulnerabilities and has three security fixes can now be installed.

An update that solves 29 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

Qt Declarative could be made to use excessive resources if it received specially crafted input.

Evolution Data Server could be made to remove files.

GTA cheat service Atlas Menu hacked as attacker alleges screenshot spying
Linux IDS vs IPS: Operational Differences and Deployment Tradeoffs

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 68 vulnerabilities, contains one feature and has 10 security fixes can now be installed.

An update that solves 68 vulnerabilities, contains one feature and has 10 security fixes can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Palo Alto VPN bug graduates from advisory to active exploitation
Flowise’s MCP implementation can run ghost commands
Password manager Dashlane suspends customer accounts amid brute-force attacks

Several security issues were fixed in rsync.

Putin sends submarines to survey Britain’s subsea cables. UK deploys Royal Navy, mobilizes parliamentary draftsmen

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the kernel.

AI’s brave new world of technical debt
How to run enterprise GenAI like a production service
How to succeed with AI-powered devops tools

An update that solves six vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

SUSE Linux 15 SP7 Kernel RT Important Live Patch 13 Local Root Exploit
An update that solves three vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

Several vulnerabilities have been found in aiohttp, an asynchronous HTTP client/server framework for asyncio and Python. CVE-2025-53643 Request smuggling vulnerability due to not parsing trailer sections of an HTTP request.

Update to 1.5.4. Fixes a buffer overflow caused by integer promotion rules in OFBMPImageFormatHandler and OFQOIImageFormatHandler. Update to 1.5.3

Update to 1.5.4. Fixes a buffer overflow caused by integer promotion rules in OFBMPImageFormatHandler and OFQOIImageFormatHandler. Update to 1.5.3