Menu

Latest articles

Important: tigervnc security update

Important: buildah security update

Moderate: golang security, bug fix, and enhancement update

Important: runc security update

Important: thunderbird security update

Important: tigervnc security update

Important: containernetworking-plugins security update

Important: buildah security update

Moderate: golang security, bug fix, and enhancement update

Important: runc security update

Important: thunderbird security update

Important: tigervnc security update

Important: containernetworking-plugins security update

An update that solves one vulnerability can now be installed.

An update that solves 4 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 5 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds

Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in a bypass of security restrictions or the execution of arbitrary commands. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u8.

pgEdge joins rush to merge OLTP and OLAP storage to support AI
Dark Moon: Can AI Actually Automate Penetration Testing on Linux?
How to Detect Unauthorized SSH Key Usage on Linux Systems
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Why private AI is the smarter bet
Security boss thought MFA would be too much security

Moderate: libpng security update

Moderate: libpng security update

Moderate: libpng security update

Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder
Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs

https://security-tracker.debian.org/tracker/DSA-6366-1

https://security-tracker.debian.org/tracker/DSA-6365-1

https://security-tracker.debian.org/tracker/DSA-6364-1

Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues

Multiple vulnerabiliites have been discovered in PDNS Recursor, a resolving name server which could result in denial of service, cache poisoning or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 5.2.11-0+deb13u1.

It was discovered that incorrect request handling in the internal web server of the PowerDNS DNS server could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 4.9.16-0+deb13u1. We recommend that you upgrade your pdns packages.

Multiple security vulnerabilities were discovered in the dnsdist DNS loadbalancer, which could result in denial of service, information disclosure or bypass of security rules. For the stable distribution (trixie), these problems have been fixed in version 1.9.15-0+deb13u1.

A use-after-free issue was found in libtext-csv-xs-perl, a Perl C/XS module to process Comma-Separated Value files, which may yield type confusion or memory corruption when registered callbacks extend the Perl argument stack. For Debian 11 bullseye, this problem has been fixed in version

Multiple security vulnerabilities were discovered in the SOGo groupware server, which could result in cross-site scripting or SQL injection. For the stable distribution (trixie), these problems have been fixed in version 5.12.1-3+deb13u2. We recommend that you upgrade your sogo packages.

Multiple security vulnerabilities were discovered in libssh2, a client-side C library implementing the SSH2 protocol which could result in memory disclosure, denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in

Several security issues were fixed in AMD Microcode.

ESET takes part in Operation Endgame to disrupt Amadey and Stealc

ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 149.0.7827.196-1~deb13u1.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

Agentic AI security steals the spotlight at Confidential Computing Summit

An update that solves 23 vulnerabilities can now be installed.

Fedora 43 Goose Critical DNS Rebinding Threat Fix 2026-08bb036c3e
Update goose to 1.36.0

Addresses CVE-2026-47895 which is a theoretical RCE Fixes CVE-2026-25075, CVE-2026-35328, CVE-2026-35329, CVE-2026-35330, CVE-2026-35331, CVE-2026-35332, CVE-2026-35333, CVE-2026-35334 Update to address CVE-2025-9615 and CVE-2025-62291

new version 2.4.68 fixes various security issues

Several security issues were fixed in xrdp.

Update goose to 1.36.0

Moderate: keylime security update

Moderate: libxslt security update

Important: skopeo security update

Moderate: protobuf-c security update

Moderate: coreutils security update

Moderate: qt5 security and bug fix update

Important: flac security update

Low: gmp security and enhancement update

Important: nginx:1.26 security update

Moderate: libfastjson security update

Moderate: libreoffice security update

Important: kernel security, bug fix, and enhancement update

Moderate: libmicrohttpd security update

Moderate: librabbitmq security update

Moderate: samba security, bug fix, and enhancement update

Moderate: freerdp security update

Moderate: ctags security update

Moderate: wireshark security update

Moderate: emacs security update

An update that solves 5 vulnerabilities can now be installed.

An update that solves 3 vulnerabilities can now be installed.

An update that solves 5 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 5 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 11 vulnerabilities can now be installed.

An update that solves 3 vulnerabilities can now be installed.

cpp-httplib could mishandle HTTP requests if it received specially crafted network traffic.

NSD could be made to crash or run programs if it received specially crafted network traffic.

Several security issues were fixed in ImageMagick.

Apache MINA could be made to run programs if it received specially crafted network traffic.

pbkdf2 could be made to generate predictable cryptographic keys if it received specially crafted input.

Several security issues were fixed in containerd.

Several security issues were fixed in containerd.

Several security issues were fixed in containerd.

The New Rules for AI-Assisted Contributions: Ownership is Not Optional
Linux Roundup: The Biggest Linux Releases This Week
SELinux Troubleshooting: What to Check Before You Disable SELinux

An update that fixes two vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

New Linux Foundation project aims to bring DNS-style trust to AI agents
Anthropic accuses Alibaba of using 25,000 fake accounts to scrape Claude AI
Making Windows a developer platform, again