Menu

Category Archives: Security

Articles about security

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves 19 vulnerabilities can now be installed.

An update that solves 19 vulnerabilities can now be installed.

An update that solves 13 vulnerabilities can now be installed.

Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data

An update that solves 21 vulnerabilities and has two security fixes can now be installed.

An update that solves 21 vulnerabilities and has two security fixes can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves 10 vulnerabilities, contains one feature and has five security fixes can now be installed.

An update that solves one vulnerability can now be installed.

US tells OpenAI to restrict access to its most powerful AI model

Moderate: golang security, bug fix, and enhancement update

Important: buildah security update

Important: buildah security update

Important: nginx security update

Moderate: golang security, bug fix, and enhancement update

Important: nginx security update

Important: nginx security update

Important: tigervnc security update

Important: thunderbird security update

Important: containernetworking-plugins security update

Important: containernetworking-plugins security update

Important: buildah security update

Important: tigervnc security update

Important: tigervnc security update

Important: runc security update

Important: thunderbird security update

Important: thunderbird security update

Rocky Linux 9 RLSA-2026-29703 Important Containernetworking-Plugins Update
Important: containernetworking-plugins security update

Important: runc security update

Important: runc security update

Moderate: golang security, bug fix, and enhancement update

Moderate: golang security, bug fix, and enhancement update

Moderate: golang security, bug fix, and enhancement update

Important: buildah security update

Important: buildah security update

An update that solves 4 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 5 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds

Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in a bypass of security restrictions or the execution of arbitrary commands. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u8.

pgEdge joins rush to merge OLTP and OLAP storage to support AI
Dark Moon: Can AI Actually Automate Penetration Testing on Linux?
How to Detect Unauthorized SSH Key Usage on Linux Systems
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Why private AI is the smarter bet
Security boss thought MFA would be too much security

Moderate: libpng security update

Moderate: libpng security update

Moderate: libpng security update

Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder
Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs

https://security-tracker.debian.org/tracker/DSA-6366-1

https://security-tracker.debian.org/tracker/DSA-6365-1

https://security-tracker.debian.org/tracker/DSA-6364-1

Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues

Multiple vulnerabiliites have been discovered in PDNS Recursor, a resolving name server which could result in denial of service, cache poisoning or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 5.2.11-0+deb13u1.

It was discovered that incorrect request handling in the internal web server of the PowerDNS DNS server could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 4.9.16-0+deb13u1. We recommend that you upgrade your pdns packages.

Multiple security vulnerabilities were discovered in the dnsdist DNS loadbalancer, which could result in denial of service, information disclosure or bypass of security rules. For the stable distribution (trixie), these problems have been fixed in version 1.9.15-0+deb13u1.

A use-after-free issue was found in libtext-csv-xs-perl, a Perl C/XS module to process Comma-Separated Value files, which may yield type confusion or memory corruption when registered callbacks extend the Perl argument stack. For Debian 11 bullseye, this problem has been fixed in version

Multiple security vulnerabilities were discovered in the SOGo groupware server, which could result in cross-site scripting or SQL injection. For the stable distribution (trixie), these problems have been fixed in version 5.12.1-3+deb13u2. We recommend that you upgrade your sogo packages.

Multiple security vulnerabilities were discovered in libssh2, a client-side C library implementing the SSH2 protocol which could result in memory disclosure, denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in

Several security issues were fixed in AMD Microcode.

ESET takes part in Operation Endgame to disrupt Amadey and Stealc

ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 149.0.7827.196-1~deb13u1.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

Agentic AI security steals the spotlight at Confidential Computing Summit

An update that solves 23 vulnerabilities can now be installed.

Fedora 43 Goose Critical DNS Rebinding Threat Fix 2026-08bb036c3e
Update goose to 1.36.0

Addresses CVE-2026-47895 which is a theoretical RCE Fixes CVE-2026-25075, CVE-2026-35328, CVE-2026-35329, CVE-2026-35330, CVE-2026-35331, CVE-2026-35332, CVE-2026-35333, CVE-2026-35334 Update to address CVE-2025-9615 and CVE-2025-62291

new version 2.4.68 fixes various security issues

Several security issues were fixed in xrdp.

Update goose to 1.36.0

Important: skopeo security update

Moderate: libxslt security update

Moderate: keylime security update

Moderate: coreutils security update

Moderate: protobuf-c security update

Moderate: libfastjson security update

Important: nginx:1.26 security update

Low: gmp security and enhancement update

Important: flac security update

Moderate: qt5 security and bug fix update

Moderate: librabbitmq security update

Moderate: libmicrohttpd security update

Important: kernel security, bug fix, and enhancement update

Moderate: libreoffice security update

Moderate: wireshark security update

Moderate: ctags security update

Moderate: freerdp security update

Moderate: samba security, bug fix, and enhancement update

Moderate: emacs security update

An update that solves 3 vulnerabilities can now be installed.

An update that solves 5 vulnerabilities can now be installed.