Menu

Latest articles

Security update

Security update

Ubuntu Kylin Software Center could be made to run programs as an administrator if it received specially crafted input via its D-Bus service.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that fixes 5 vulnerabilities is now available.

VRChat says somebody faked a breach notice with the Maine AG’s office

An update that solves 5 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Mistral could be made to expose sensitive information or run code.

Langflow 1.9.0 Advisory CVE-2026-5027 High File Write Threat
After Years of Supply Chain Attacks, npm Is Finally Closing the Door on Auto-Scripts
How to Find and Secure Exposed Services on Linux
Actively Exploited Chromium V8 Zero-Day: What Linux Admins Need to Know
Microsoft open sources AI evaluation framework for enterprise agents
Databricks’ OpenSharing targets the ‘integration tax’ of enterprise AI

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

It’s crunch time for Java modernization
Build an agent? Sell an agent

Crypt-SaltedHash incorrectly generated random numbers.

Every employee’s password was stored in a single Excel file

It was discovered that a udev helper provided by libinput, a input device management and event handling library, performed insufficient sanitising of device properties, which can result in local privilege escalation in some setups. For the oldstable distribution (bookworm), this problem has been fixed

Two vulnerabilities were discovered in libdbi-perl, a Perl framework that provides a common interface to access various backend databases in a uniform manner, which may result in denial of service, or potentially the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed

Security update

Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4.

Update to Rust 1.96.0: New Range* types Assert matching patterns Changes to WebAssembly targets Stabilized APIs

new version 2.4.68 fixes various security issues

Fixes XML external entity vulnerability. For more information, refer to https://src.fedoraproject.org/rpms/xmlstarlet/pull-request/4.

GitHub finally pulls the plug on automatic install script execution for npm

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

Chinese agents caught rebuilding botnets and stirring the pot on AI datacenter debate

https://security-tracker.debian.org/tracker/DSA-6341-1

https://security-tracker.debian.org/tracker/DSA-6340-1

https://security-tracker.debian.org/tracker/DSA-6339-1

https://security-tracker.debian.org/tracker/DSA-6338-1

Smashing Security podcast #471: This AI worm just rewrote its own rules

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 149.0.7827.102-1~deb12u1.

A flaw was discovered in jackson-core, a fast and powerful JSON library for Java, which may allow an attacker to cause a denial of service by using deeply nested JSON data. Please note that related and complementary jackson-* packages like jackson- databind or jackson-dataformat-smile had to be upgraded as well in

https://security-tracker.debian.org/tracker/DSA-6335-1

https://security-tracker.debian.org/tracker/DSA-6334-1

https://security-tracker.debian.org/tracker/DSA-6333-1

https://security-tracker.debian.org/tracker/DSA-6332-1

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

How to use virtual environments in Python
Angry bug hunter with Microsoft beef drops new Windows 0-day
Cybercriminals: the ‘auditors’ you never hired

Every organisation gets audited. The question is who does the auditing.

Security update

Security update

HTTP-Daemon could be made to run programs if it received specially crafted network traffic.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves 12 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 4 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

USN-6455-1 introduced a regression in Exim

Why schools remain one of cybercriminals’ favourite targets
GitHub pulls pin on npm’s auto-run scripts

An update that solves one vulnerability can now be installed.

An update that solves six vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 10 vulnerabilities can now be installed.