Menu

Category Archives: Security

Articles about security

Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix, which might result in bypass of access checks, overwrite of files in unintended situations using the WORM vfs module, installing CA certificates over http without verification when auto-enrollment GPO is enabled, denial of service or remote code

CrowdStrike, Google shatter Glassworm botnet
BTMOB: A stealthy RAT burrowing deep into Android devices

The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise

Bosses blinded by confidence about shadow AI use by workers
FBI: Get to know your IT guy – extortion crews are visiting law firms pretending to be tech support
FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework
India’s cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat
Context-aware advisor recommendations in Red Hat Lightspeed
Building the levee: Why Red Hat’s post-quantum strategy is already in production
LinuxSecurity.com Major Update for Improved Threat Discovery and Research
How to guarantee a speaker gig: Hack the system. Literally
Docker Sandboxes and microVMs, explained
What do software developers do now?

Dnsmasq could be made to crash or run programs if it received specially crafted network traffic.

libssh2 could be made to crash if it received specially crafted network traffic.

Multiple vulnerabilities were discovered in SPIP, a website engine for publishing, which may result in remote code execution or an open redirect. For the stable distribution (trixie), these problems have been fixed in version 4.4.15+dfsg-0+deb13u1.

GitHub Actions Compromise CI/CD Supply Chain Risks Explored
VPN Strategies for Linux Developers Managing Mobile Security Risks

Several security issues were fixed in the Linux kernel.

SimpleEval could be made to run programs if it received specially crafted input.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in Rclone.

ngtcp2 could be made to run programs as your login if it received specially crafted network traffic when qlog was enabled.

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 23 vulnerabilities can now be installed.

An update that solves 6 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 13 vulnerabilities and has 13 bug fixes can now be installed.

An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.

An update that solves one vulnerability and has 4 bug fixes can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.

An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed.

An update that solves 20 vulnerabilities and has one bug fix can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.

MyPillow must decide whether to be firm or soft as ransomware crims demand pay
FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required
Misuse of Cron Jobs for Long-Term Access in Linux Environments
Inside the New LinuxSecurity.com: Smarter Linux Security Research and Threat Discovery
Experts pour cold borscht on Farage’s Russian hack claim
The Big Three cloud providers are more alike than not
Taming the generative AI back end
Why most AI agents disappoint in production (and what to fix first)

MGASA-2026-0156 – Updated nginx packages fix security vulnerabilities

MGASA-2026-0155 – Updated x11-server, x11-server-xwayland & tigervnc packages fix security vulnerabilities

MGASA-2026-0154 – Updated perl-Imager packages fix security vulnerabilities

MGASA-2026-0153 – Updated ffmpeg packages fix security vulnerabilities

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Update to 9.18.49 (rhbz#2480121) Security Fixes: Limit resolver server list size. (CVE-2026-3592) Fix GSS-API resource leak. (CVE-2026-3039) Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946)

Update to 9.18.49 (rhbz#2480121) Security Fixes: Limit resolver server list size. (CVE-2026-3592) Fix GSS-API resource leak. (CVE-2026-3039) Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946)

Update to 20260519: ASoC: tas2783: Add Firmware files for tas2783A projects add firmware for MT7927 WiFi device Add HP ISH firmware for Intel Panther Lake systems ti: Add PCM6240 firmware with multiple audio profiles support

Update to latest upstream release https://forum.torproject.org/t/security- release-0-4-8-25-and-0-4-9-8/21559

Update to 1.25.1 (rhbz#2480119) Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto Networks, for the report.

Update to latest upstream release https://forum.torproject.org/t/security- release-0-4-8-25-and-0-4-9-8/21559

https://security-tracker.debian.org/tracker/DSA-6297-1

Ubuntu 26.04 LTS Dotnet Critical Denial Service Issue USN-8298-1
.NET could be made to consume excessive resources if it received specially crafted network traffic.

Several security issues were fixed in NLTK.

Several security issues were fixed in Vim.

An update that solves 13 vulnerabilities can now be installed.

An update that solves two vulnerabilities and contains one feature can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves four vulnerabilities can now be installed.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Google adds open source Agent Executor to support AI agents in production

New kernel packages are available for Slackware 15.0 and -current to fix a security issue.

An update that solves 5 vulnerabilities can now be installed.

An update that solves 6 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 4 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

DeepSeek’s steep V4-Pro price cut escalates AI pricing war
As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free
AI coders need good software engineers
The role of MCP in context engineering
Anthropic to release Mythos-class models to the public

https://security-tracker.debian.org/tracker/DSA-6296-1

https://security-tracker.debian.org/tracker/DSA-6295-1

The 6.19.14-108 stable kernel update contains a couple if important security fixes.

Update to .NET SDK 8.0.127 and Runtime 8.0.27 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.27/8.0.127.md

Update to .NET SDK 9.0.117 and Runtime 9.0.16 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.16/9.0.117.md

Update to .NET SDK 10.0.108 and Runtime 10.0.8 Fixes: CVE-2026-32175,CVE-2026-32177,CVE-2026-35433,CVE-2026-42899 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.8/10.0.108.md

Update to release v0.30.0 Resolves CVE-2026-39984: rhbz#2458929 Upstream new features and fixes

Update to release v0.34.0 Resolves: rhbz#2467576 Resolves CVE-2026-39984: rhbz#2458930 Upstream new features and fixes

A new prerelease of Python 3.15 with fixes to several CVEs.

Update NSS to 3.123.1 Update to Firefox 151.0

Update NSS to 3.123.1 Update to Firefox 151.0