Menu

Category Archives: Security

Articles about security

Rocky Linux 10 dogtag-pki Important Code Execution Fix RLSA-2026-73765
Rocky Linux Node.js 24 Important Security Fix RLSA-2026-73428
Rocky Linux gvfs Important Buffer Overflow Risks RLSA-2026-73998
Rocky Linux 10 openssh Moderate Auth Delay Risk RLSA-2026-73954
Rocky Linux 9 RLSA-2026-73955 OpenSSH Moderate Authentication Issue
Rocky Linux 9 pki-core Important Code Execution Risk RLSA-2026-73766
New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords
Microsoft catches hackers exploiting Zimbra bug before disclosure
Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, [...]
Why Mobile Device Management Needs Its Own Threat Model
MI5 warns UK academics their research may have helped Chinese spies
MI5 has warned that more than 100 UK-linked academics contributed to research projects allegedly funded to improve China’s spying capabilities. The [...]
Google makes Gemini 4 AI model available to a trusted few
Google has unveiled a new frontier AI model after months of delay. Gemini 4 Argon is designed to handle complex, long-horizon workloads spanning software [...]
CISO thought he had a ‘r3@lg00dp@$$w0rd’ but forgot to patch
Welcome back to PWNED, the weekly column where we warn you about weak security practices. This week’s terrifying tale involves a lack of important patching [...]
England’s schools are getting better at mopping up cyber incidents
England’s secondary schools are reporting slightly fewer cybersecurity incidents and faster recovery when disaster strikes, according to a survey by [...]
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader
ShinyHunters suspect arrested, and is now investigated over alleged murder plots
UK privacy watchdog starts over with new board and Manchester HQ
Britain’s data protection watchdog has acquired a new legal identity and governance structure, although the familiar ICO initials are staying put. On [...]
Ubuntu 22.04 LTS Advisory USN-8818-4 Important Privilege Escalation Patch
Ubuntu 20.04 LTS Kernel Security Issues with CVE-2025-38724
Ubuntu 22.04 LTS Linux Kernel FIPS Update USN-8730-7 CVE-2026-53131
Japanese Car-Sharing Site Times Car Data Breach Affects 6.6M Accounts
Ubuntu Linux Kernel 5.15 Critical Privilege Escalation Risk USN-8849-1
Ubuntu 24.04 Linux Kernel Important Local Privilege Escalation 8817-2
Ubuntu 8819-4 Linux Kernel FIPS Important Network & System Threat Fixes
Ubuntu 20.04 LTS Linux Kernel Security Advisory USN-8850-1
Fewer women than ever in UK’s ‘old boys’ club’ cyber industry
The proportion of workers in the UK cybersecurity industry identifying as women has dropped to 16 percent, the lowest level since 2021. Gender diversity [...]
The dream of enterprise semantics: Why this time is different
In most companies, the struggle to answer a new question fast has nothing to do with a lack of data. The problem is a lack of semantics. Or to put it [...]
Microsoft doubles down on Rust
After many years of watching how Microsoft develops platforms and rolls out technologies to external users, one thing is clear: anything that is important [...]
OpenAI bets enterprises are ready to delegate real work to autonomous agents
OpenAI says true agentic AI has finally arrived, pushing beyond the trivial capabilities of early-stage virtual assistants. This week at OpenAI Dev Day, [...]
Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative
Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else
OpenAI, which hoovered up vast amounts of internet content amid copyright fights, has accused individuals associated with China’s Moonshot AI of being [...]
Stack Overflow expands Stack Internal to give AI agents ‘trusted’ enterprise knowledge
As enterprises increasingly turn to coding agents for building applications, Stack Overflow has added new capabilities to Stack Internal, its [...]
SUSE ntfs-3g Moderate DoS Heap Buffer Overflow Vuln 2026-4399-1
DSA-6530-1 pcre2 – security update
DSA-6529-1 libwebsockets – security update
openSUSE gdb Important Out-Of-Bounds Write Vuln 2026-4400-1
SUSE gdb Important Out-of-bounds Write Vulnern CVE-2026-13732
SUSE python313 Medium DoS and Buffer Overflow Vulnerability 2026-4401-1
SUSE Python-PyYAML Important Code Execution Risk Advisory 2026-4402-1
openSUSE Python-Tornado6 Important HTTP Request Smuggling Fix 2026-4403-1
SUSE Python-Tornado6 Important Denial of Service Vulnern 2026-4403-1
SUSE python-tornado Important Multiple Vulnerabilities 2026-4404-1
MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
A 16-year-old security researcher named Faav found an authentication flaw in Microsoft’s Titan analytics service that allowed him to gain administrator [...]
Debian Firefox-esr Critical Privilege Escalation Vulnerabilities DSA-6533-1
Debian LTS pgextwlist Security Update DLA-4806-1 CVE-2023-39417
Ubuntu 26.04 Authen-SASL Major Network Vulnerability Report USN-8858-1
Debian 12 mkvtoolnix Critical Heap Buffer Overflow Vuln DLA-4805-1
Debian DSA-6532-1 Resolves Tor Denial of Service Vulnerabilities
Timeshare exit scams: From fake buyers to recovery fraud
Con artists are targeting timeshare owners who want out – and some victims are hit twice
Ubuntu 26.04 Kdenlive Important Command Execution Risk USN-8856-1
Rocky Linux 10 GDB Severe Out-of-Bounds Write Vulnerability RLSA-2026-73427
Rocky Linux 10 gawk Important Code Execution DoS RLSA-2026-73429
Rocky Linux Thunderbird Critical Security Patch RLSA-2026-73130
Rocky Linux Kernel Important Bug Fixes and Enhancements RLSA-2026-72624
Rocky Linux 9 Kernel Important Fixes and Enhancements RLSA-2026-72623
Rocky Linux gdb Important Buffer Overflow Risk RLSA-2026-73426
Rocky Linux Node.js Important Security Bug Fix RLSA-2026-73838
Rocky Linux 9 gawk Moderate Buffer Overflow Fix RLSA-2026-73512
Rocky Linux 9 Expat Serious Denial of Service XML Injection RLSA-2026-72663
Debian LTS DLA-4802-1 Python-Django Critical Cache Exposure
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
openSUSE gpsd Moderate Update CVE-2026-60122 Advisory 2026-11891-1
openSUSE Chromedriver Moderate Security Issue SU-2026-11888-1
openSUSE gimp Critical Remote Access Vulnerabilities Fix 2026-11890-1
openSUSE Emacs Moderate Update CVE-2026-96442 Severity 2026-11889-1
openSUSE Tumbleweed pi-coding-agent Moderate Security Issues 2026-11884-1
openSUSE Tumbleweed libpoppler-cpp3 Important Security Fix 2026-11885-1
openSUSE python311 Moderate Code Issues Vuln 2026-11886-1
openSUSE Tumbleweed libtesseract5 Moderate Vulnerability CVE-2026-11887
openSUSE Tumbleweed pcapplusplus-devel Moderate Update 2026-11883-1
openSUSE netty Important Security Fix for 30 Issues 2026-11882-1
Key Considerations for Ubuntu OpenStack Keystone Auth Issues USN-8854-1
Mageia Borgbackup Security Update Notification 2026-0143
Mageia 10 Engrampa Bugfix ZST File Issue Vulnern 2026-0142
Mageia 10 task-lxde Security Update for Bugfix 2026-0141
Legit Security launches agentic remediation for open-source dependency vulnerabilities
Debian LTS libsmpp34 Serious Memory Corruption Vulnerability DLA-4804-1
Ubuntu 22.04 LTS Linux Kernel Critical Memory Escape Privilege 8818-5
Ubuntu 24.04 22.04 Linux Kernel Critical Memory Bypass Flaw USN-8817-3
Ubuntu 26.04 OpenVPN Critical Denial of Service Threat USN-8852-1
Unsloth’s model picker had a code-execution problem
True to its name, AI-model-training tool Unsloth would do more work than it was asked to when developers checked out a model: It would also allow arbitrary [...]
Ubuntu 22.04 LTS OpenSBI Denial of Service Vulnern USN-8853-1
Securing AI agents requires securing the systems around them
Enterprise AI is changing from software that primarily generates information to software that can take action. AI agents can call APIs, invoke tools, [...]
GitLab Patches Critical CI/CD Flaws That Can Run Code on Servers
Two critical GitLab flaws can turn authenticated continuous integration and delivery (CI/CD) configuration into code execution on self-managed servers.
Amazon Prime Phishing Scam Uses Fake Billing Alert to Steal Logins and Card Details
Pentagon personnel database breach exposes personal data of millions
More than half of UK businesses lack confidence in basic cyber skills
More than half of UK businesses lack confidence in their ability to perform at least one basic cybersecurity task, according to the government’s [...]
Observability for AI-native systems: New SLIs beyond latency and error rate
When HTTP 200 means nothing An AI assistant can return a response in under a second, maintain 99.9% availability and still give customers a fabricated [...]
Validating AI models and agents with property-based testing
Testing deterministic systems is relatively straightforward. Create an assertion that the system should pass, and automate validating it against a series [...]
AI cuts software developers some slack
My mom used to say that Hodges’s law was “Junk expands to fill the space allotted for it.” We lived in three houses over the years, each one bigger than [...]
8 Top Red Teaming Service Providers for Enterprise Adversary Emulation
UK rail cops’ £320K face-scanning spree nets zero matches
British Transport Police (BTP) spent more than £320,000 putting half a million commuters through live facial recognition cameras, only for the system to [...]
Spectre bug is back, this time to haunt JIT engines
The Spectre microarchitecture vulnerability has returned yet again, this time to vex just-in-time (JIT) engines that generate machine code for browsers, [...]
Ubuntu 26.04 LTS libdbi-perl Critical DoS and Code Exec Vuln 8841-1
Mageia 10 Whatsie Bugfix Update Dark Theme Issue 2026-0140
Mageia 10 9 urpm-ng Bugfix Migration Advisory 2026-0139
Fedora 43 libxmp Medium Playback Bugfix Advisory 2026-47ffcebe44
Fedora 43 Thunderbird Software Upgrade with version 2026-a387125860
Fedora 43 RootlessKit Update DoS Fix CVE-2026-56855 & CVE-2026-78662
Fedora 43 perl-Imager Key Concerns with TGA Color Map and Palette