Menu

Category Archives: Security

Articles about security

https://security-tracker.debian.org/tracker/DSA-6208-1

Recovery scammers hit you when you’re down: Here’s how to avoid a second strike

If you’ve been the victim of fraud, you’re likely already a lead on a ‘sucker list’ – and if you’re not careful, your ordeal may be about to get worse.

Navigating the Mythos-haunted world of platform security
MCP security: Logging and runtime security measures

Important: kea security update

Two different attackers poisoned popular open source tools – and showed us the future of supply chain compromise

Several vulnerabilities were discovered in the inetutils implementation of telnetd and telnet, which may result in privilege escalation or information disclosure. CVE-2026-28372 Ron Ben Yizhak from SafeBreach found that the fix for CVE-2026-24061 was

Hungarian government creds left in the safe hands of ‘FrankLampard’

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 140.9.1esr-1~deb11u1.

https://security-tracker.debian.org/tracker/DSA-6206-1

Swift for Visual Studio Code comes to Open VSX Registry

https://security-tracker.debian.org/tracker/DSA-6204-1

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

AI and cryptocurrency scams are costing Americans billions, FBI reports
CPUID site hijacked to serve malware instead of HWMonitor downloads
AWS targets AI agent sprawl with new Bedrock Agent Registry
Project Glasswing and open source software: The good, the bad, and the ugly
Britain seeks views before it drops the hammer on signal jammers
AI agents aren’t failing. The coordination layer is failing
Cloud degrees are moving online

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

Unpacking AI security in 2026 from experimentation to the agentic era

New upstream release (#2442363) fixing various security issues

Update to latest upstream

Microsoft’s reauthentication snafu cuts off developers globally

https://security-tracker.debian.org/tracker/DSA-6205-1

Anthropic rolls out Claude Managed Agents
Crypto? Huh. Good gawd y’all, what is it good for? $45M in this case
‘Several dozen’ high-value corporations hit by new extortion crew in helpdesk phishing spree
Meta’s Muse Spark: a smaller, faster AI model for broad app deployment
Chevin pulls the handbrake on FleetWave software after security scare
Months-old Adobe Reader zero-day uses PDFs to size up targets
Microsoft locks out VeraCrypt and WireGuard devs, blames verification process
Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

Important: fontforge security update

Moderate: ncurses security update

Zephyr Energy loses £700K in cyber hit that rerouted contractor payment
Bringing databases and Kubernetes together
How Agile practices ensure quality in GenAI-assisted development
Rethinking Angular forms: A state-first perspective
Sticky-note security turned gym into hall of ’80s horrors
Cryptographers place $5,000 bet whether quantum will matter
Minimus Welcomes Yael Nardi as CBO to Facilitate Strategic Growth
Visual Studio Code 1.115 introduces VS Code Agents app
Visual Studio Code 1.115 introduces VS Code Agents app
Smashing Security podcast #462: LinkedIn is spying on you, and you agreed to nothing

https://security-tracker.debian.org/tracker/DSA-6201-1

Criminal wannabes even more dangerous than the pros, says ex-FBI cyber chief
Microsoft announces end of support for ASP.NET Core 2.3
As breakout time accelerates, prevention-first cybersecurity takes center stage

Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.

AWS turns its S3 storage service into a file system for AI agents
Dutch healthcare software vendor goes dark after ransomware attack
Z.ai unveils GLM-5.1, enabling AI coding agents to run autonomously for hours
NHS Scotland-linked domains caught serving pr0n and dodgy sports streams
Microsoft’s new Agent Governance Toolkit targets top OWASP risks for AI agents
The winners and losers of AI coding
Get started with Python’s new frozendict type
Microsoft hints at bit bunkers for war zones

Important: fontforge security update

Important: fontforge security update

Moderate: crun security update

Moderate: kernel security update

Moderate: crun security update

Moderate: kernel security update

https://security-tracker.debian.org/tracker/DSA-6202-1

Anthropic: All your zero-days are belong to Mythos
Iran cyber actors disrupting US water, energy facilities, FBI warns
GitHub Copilot CLI adds Rubber Duck review agent

https://security-tracker.debian.org/tracker/DSA-6197-2

Hundreds of orgs compromised daily in Microsoft device code phishing attacks
US cybercrime losses pass $20B for first time as AI boosts online fraud
Russia’s Fancy Bear still attacking routers to boost fake sites, NCSC warns
The Terraform scaling problem: When infrastructure-as-code becomes infrastructure-as-complexity
Nvidia’s SchedMD acquisition puts open-source AI scheduling under scrutiny
Enterprise developers question Claude Code’s reliability for complex engineering
How to destroy a company quickly
What enterprise devops teams should learn from SaaS
Life imprisonment for Cambodian scam compound operators – but will it make a difference?
Rust team warns of WebAssembly change
Yahoo! Japan’s owner consolidating 164 OpenStack clusters into one

33.0.1 release

Update to 9.6.0. Fixes rhbz#2452087

Moderate: kernel-rt security update

Moderate: kernel-rt security update

Moderate: 389-ds:1.4 security update

Important: python3.12 security update

AI agents found vulns in this popular Linux and Unix print server
Visual Studio Code 1.114 streamlines AI chat
Attackers exploited this critical FortiClient EMS bug as a 0-day
How to choose the best LLM using R and vitals
Databricks launches AiChemy multi-agent AI for drug discovery