October 10, 2026
AlmaLinux 9 xorg-x11-server Moderate Use-After-Free CVE-2025-62229
October 10, 2026
AlmaLinux 9 Expat Important Memory Allocation Fix CVE-2025-59375
October 10, 2026
AlmaLinux 9 Kernel Advisory CVE-2025-37823 Important Security Update
October 10, 2026
AlmaLinux 9 Kernel Important Security Update CVE-2025-22097
October 10, 2026
AlmaLinux 9 Kernel Important Security Update CVE-2025-37803
October 10, 2026
AlmaLinux 9 Security Update Released for GIMP – ALSA-2025-9162
October 10, 2026
Three days to TechCrunch Disrupt: What’s next for AI and software development
First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code [...]
October 10, 2026
DSA-6550-1 ghostscript – security update
October 10, 2026
AWS AgentCore security undone by prompt requesting credentials
Bob, possibly the same Bob whose conversations with Alice draw so much interest from eavesdropping Eve, was browsing a site we’ll call TechHub. The [...]
October 9, 2026
MATCHBOIL: New tricks, same old evil intentions
ESET Research catalogs the changes of UAC-0099’s MATCHBOIL downloader from 2024 to 2026
October 9, 2026
Lightwell project filters out 400 Java library vulnerabilities
Lightwell, the open-source security initiative set up by IBM and Red Hat, has identified more than 400 previously undiscovered vulnerabilities in widely [...]
October 9, 2026
OpenAI reports three new incidents of misalignment
OpenAI continues to report incidences of “misaligned” behavior by its AI models, with three new reports dropping on Oct. 2. However, they describe [...]
October 9, 2026
Practical AI Integration for Modern Business Teams
October 9, 2026
As AI agents grow, vendors carve out decision-making as a separate model layer
As enterprises struggle to balance AI budgets with the demands of scaling agentic applications, they have been increasingly looking for ways to make those [...]
October 9, 2026
Citrix gives NetScaler admins another critical reason to patch
Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 [...]
October 9, 2026
Open Source Security: What 400+ Vulnerability Fixes Could Mean for Linux Users
IBM and Red Hat say their Lightwell initiative has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries.
October 9, 2026
Defense in Depth Cybersecurity: How to Build Effective Layers
Why is the orders application talking to the backup server?
October 9, 2026
vLLM Vulnerability Update Fixes RCE and Server-Crashing Flaws
The vLLM project published security advisories on October 6, 2026, identifying version 0.31.0 as the fix for remote code execution (RCE), service crashes, [...]
October 9, 2026
Linux Filesystem Bug Lets Crafted JFS Names Overwrite Memory
Deepanshu Kartikey has submitted a patch for a Linux filesystem bug that lets a crafted JFS disk image overwrite kernel memory during a directory listing.
October 9, 2026
Linux NTFS Bug Copies Crafted Index Data Before Checking Its Size
Andrey Misiurov has proposed a patch for a Linux NTFS bug that lets a crafted disk image make the kernel read beyond a memory buffer.
October 9, 2026
NFC Security Bug Lets Linux Reuse Freed UART Memory During Shutdown
Shubham Antil has submitted a revised two-patch series addressing an NFC security bug in Linux’s device-shutdown code.
October 9, 2026
Nftables Interval Bug Can Leave Linux Using a Freed Chain Reference
Jérémy Jean has confirmed that a maintainer’s proposed patch stops the reproduced failure behind an nftables interval bug.
October 9, 2026
Four days to TechCrunch Disrupt: What’s next for AI and software development
First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code [...]
October 9, 2026
Neoclouds and the enterprises that need them
I’ve been tracking the rise of neoclouds in the past couple of years, and I’ll start by admitting that the numbers are genuinely staggering. Synergy [...]
October 9, 2026
US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide
The FBI announced that it has seized seven web domains linked to hacking tools allegedly operated by a Chinese security firm called Integrity Technology [...]
October 8, 2026
DSA-6549-1 xz-utils – security update
October 8, 2026
OpenStack Fixes Zaqar Flaw Exposing Other Tenants’ Queues
OpenStack disclosed a Zaqar security flaw on Oct 7, 2026 that lets an authenticated user access another project’s messaging queues.
October 8, 2026
Linux Security Update Fixes 12 X.Org and Xwayland Flaws
X.Org has issued fixes for 12 vulnerabilities in its display software.
October 8, 2026
Linux TCP Fast Open Use After Free Leaves a Packet Pointer Behind
A bug in Linux’s TCP Fast Open code can leave it reading memory that has already been released.
October 8, 2026
Apache Jackrabbit Fixes Critical WebDAV Session Hijacking Flaw
Apache disclosed a critical Apache Jackrabbit session hijacking flaw on Oct 7, 2026.
October 8, 2026
High-severity Nvidia bug could crash GPU monitoring on exposed servers
Researchers found thousands of GPU servers exposing Nvidia’s DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity [...]
October 8, 2026
Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise
The credential-hijacking Shai-Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK. Multiple security researchers [...]
October 8, 2026
Inside a brand deal scam targeting YouTube creators
A plausible-sounding sponsorship offer could mask an attempt to compromise your Google account
October 8, 2026
Fighting GenAI with GenAI: The New Email Security Landscape
The use of phishing emails as a means of stealing information or implanting damaging malware dates back to the mid-1990s. Although almost as old as the [...]
October 8, 2026
UK and Germany team up against Russian cyberattacks as Brexit rethink looms
Britain and Germany have announced a partnership to counter cyberattacks and sabotage, particularly from Russia, as Prime Minister Andy Burnham heads to [...]
October 8, 2026
AWS takes aim at runaway AI agent behavior with Strands Box
Amazon Web Services (AWS) has introduced an open-source sandbox for AI agents that allows developers to restrict their actions based on previous behavior, [...]
October 8, 2026
AI-powered data pipeline observability: Stop monitoring and start preventing
Devops tools are making it increasingly easy to monitor data pipeline failures. But in many cases, those alerts are already too late. Take marketing [...]
October 8, 2026
Cheapskates wouldn’t pay for security help, got hit by ransomware, and went bust months later
Welcome back to PWNED, the weekly column where we highlight some of the lowlights in corporate security. This week, we’ll talk about two scenarios, one [...]
October 8, 2026
Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead
The United States Department of Justice has charged a man with fraud after he allegedly told clients he could decrypt files locked up by ransomware but [...]
October 8, 2026
Smashing Security podcast #487: Clippy’s crypto comeback
October 7, 2026
DSA-6548-1 node-shell-quote – security update
October 7, 2026
DSA-6547-1 ruby-jwt – security update
October 7, 2026
DSA-6546-1 rails – security update
October 7, 2026
Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
Imagine going to a Google website at its correct URL, only to be redirected to a crim’s illegitimate copy. Attackers hijacked top-level domains, [...]
October 7, 2026
AWS launches open-source AI agent sandbox to prevent YOLO mode disasters
AWS has offered multiple open-source strategies for holding AI agents accountable, and now it’s adding a full-on sandbox to this stack. Dubbed Strands Box, [...]
October 7, 2026
US states sue popular kitmaker TP-Link over China risks
The attorneys general of Florida, Iowa, Montana, and Nebraska have sued ubiquitous networking and smart home tech maker TP-Link, alleging its security [...]
October 7, 2026
How DNS, Firewalls and Endpoint Tools Block Websites
October 7, 2026
The quest for simplicity: Why SMBs want advanced protection without the complexity
The cybersecurity market is often making it tougher for SMBs to keep threats at bay
October 7, 2026
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI [...]
October 7, 2026
FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet [...]
October 7, 2026
South Korean president calls for creation of tools that stop all cyber-attacks
South Korean president Lee Jae Myung has told the nation’s cabinet that it’s time to develop AI-powered defensive tools to combat AI-wielding attackers. [...]
October 7, 2026
Anthropic reconfigures its cool kids security program
Only a week after warning about the perils of competitor Z.ai’s GLM-5.3 model and its advanced cybersecurity capabilities, Anthropic has expanded its [...]
October 6, 2026
Karina Portugal Makes the Case for Know Your Agent
October 6, 2026
Trump Mobile customers’ data dumped – and some never even received their gold device
If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the [...]
October 6, 2026
One week to TechCrunch Disrupt: What’s next for AI and software development
First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code [...]
October 6, 2026
Microsoft extends the Outlook naughty step with two more file types
Microsoft is adding two extra file types to its Outlook block list to strengthen security. The file types are .msix and .msixbundle, used for Windows [...]
October 6, 2026
5 Astrix and Aembit Alternatives for AI Agent Identity Security
October 6, 2026
Aembit Extends Access Controls to Personal AI Agents
October 6, 2026
Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets
GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent [...]
October 6, 2026
ServiceNow takes aim at enterprise AI’s workflow bottleneck with AI Workflow Factory
ServiceNow has launched two AI solutions that can help enterprises identify business processes ripe for automation, build the workflows to address them, [...]
October 6, 2026
Asos app delivers a data leak threat instead of fast fashion
Asos customers have reported receiving a rogue app notification claiming the online clothing retailer’s Snowflake instance has been compromised and [...]
October 6, 2026
Denmark’s ID register spills more people’s details than the country has residents
An unauthorized party abused a private Danish company’s legitimate access to the country’s Central Population Register (CPR), exposing names, [...]
October 6, 2026
Search Exposure Linux Security Threats Impacting Personal Data
Search-indexed personal data increases security risk in Linux environments. When email addresses, usernames, phone numbers, and role information are easy [...]
October 6, 2026
Understanding Internal vs External Pen Testing for Your Business
Penetration tests are like fire drills for your network. They expose weak spots, test defenses, and help prevent real damage when threats come knocking. [...]
October 6, 2026
Using Technology to Fight Distraction and Improve Focus
October 6, 2026
FBI Confirms Multiple Arrests in ShinyHunters Investigation
October 6, 2026
Money can’t buy enterprise trust
I thought the AI boom was producing a new level of bad behavior, what with MongoDB CEO CJ Desai peacing out, not to mention Google’s earlier controversial [...]
October 6, 2026
Don’t buy a consultant’s AI framework
Every major consulting firm offers its own prebuilt architectural framework, model, or reference architecture for generative AI and agentic AI. The pitch [...]
October 6, 2026
Linux Kernel Vulnerability Fixed in Binder Device Creation
Linux developers have merged a fix for a Linux kernel vulnerability that can leave Binder device creation writing to memory the kernel has already released.
October 6, 2026
Citrix NetScaler Vulnerability Is Being Exploited: Check SAML Systems
Citrix has confirmed targeted attacks involving a Citrix NetScaler vulnerability and urged affected customers to update.
October 6, 2026
OpenOffice Vulnerability Can Run Code From Malicious Documents
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
October 6, 2026
Apache Thrift 0.25.0 Adds Memory Limits for Network Messages
Apache released Thrift 0.25.0 on Sep 30, 2026 with memory checks for several C++, Java, and Python components.
October 6, 2026
Apache Directory LDAP API 2.1.9 Security Update for CVE-2026-103877
Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.
October 6, 2026
OpenSSL Vulnerability Can Leak Server Memory Through DTLS
OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.
October 6, 2026
Fedora 45 Kernel 7.2.9 Important Fixes Advisory 2026-8dc7d1def3
October 6, 2026
