Menu

Latest articles

Mobile App Security in HealthTech: Safeguarding Patient Data Against Cybersecurity Threats
MCP Toolbox Flaw Could Expose Google Service Tokens
A September 23 advisory describes a flaw in the Python SDK used with MCP Toolbox: a shared cache could send a Google ID token to a service it was not meant for.
Emacs Security Flaw Could Run Code From an Untrusted File
A September 22 advisory on an Emacs vulnerability says opening a crafted file could run code on the reader’s computer, even with the editor’s [...]
Linux HID Flaw Could Leak Kernel Memory Through Input Events
A newly merged Linux HID fix addresses a Wacom input-device path that could read beyond a short report and pass a value to local software.
Linux DAMON Page-Table Bug Could Corrupt Arm64 System Memory
Linux DAMON, the kernel’s Data Access Monitor, samples memory use to show which pages a workload touches.
Ubuntu 26.04 LTS NetworkManager Important Info Exposure CVE-2026-19685
Ubuntu 26.04 SQL Parsing Denial of Service Vulnerabilities USN-8808-1
Ubuntu Open-iSNS Critical Denial of Service Vulnerability USN-8807-1
GitHub Enterprise Server Flaw Could Let Attackers Run Code
A GitHub Enterprise Server security fix addresses a way to turn the appliance’s notebook viewer into a route to its own internal services.
Someone’s attacking a critical 0-day RCE in F5 BIG-IP APM
F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code. [...]
Oracle Linux 10 Podman Important Updates CVE-2026-17106 ELSA-2026-70201
Oracle Linux 10 PostgreSQL 16 Significant Security Advisory ELSA-2026-70186
Oracle Linux 10 libarchive Low Security Advisory ELSA-2026-69553
Oracle rsyslog Important Buffer Overflow Fix ELSA-2026-69541
Oracle Linux 10 Firefox Important Vulnerability Update ELSA-2026-69461
Oracle Linux 10 Curl Important Security Flaws ELSA-2026-69125
Oracle Linux PostgreSQL 18 PostGIS Security Fix ELSA-2026-67166-0
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
JetBrains unveils JetBrains Air for agentic software development
JetBrains on September 22 announced JetBrains Air, an open system of products for managing AI-powered software development workflows across developers, [...]
Looking for free Robux? Here’s what’s real, and what’s a scam
Fake giveaways, free Robux generators and lookalike login pages all target the same thing – your Roblox account
Email Makes Up Nearly 1 in 3 MSSP Analyses: How Tier 1 Can Triage Phishing Faster
OpenAI, Anthropic cut AI model costs as price-performance race intensifies
Enterprises can now buy frontier AI for far less per token after OpenAI and Anthropic cut prices on their newest models on Tuesday. OpenAI released GPT-6 [...]
GitHub App keys can still enable takeovers long after they are forgotten
GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories [...]
Academic publisher Elsevier hit by LAPSUS$ redirect attack
Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew’s [...]
Closing the observability gap for the AI-ready enterprise
The modern enterprise is a digital enterprise. From the back office to the factory floor, connected systems and digital services form the operational [...]
Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes
British regulator takes a hard look at Pornhub’s Apple-powered age checks
Ofcom has opened an investigation into whether Pornhub’s Apple-based age checks are effective enough to keep children away from its adult content. [...]
Software dependencies are running away from us
You may very well have a big problem and you don’t even know it.  Do you have complete control over the dependencies of your application? I’m guessing that [...]
Get started with htmx 4
htmx is a simple way to add rich interactivity to web pages without writing JavaScript. On an htmx-powered page, you can imbue buttons, form elements, [...]
Why security belongs in the network
Every attack leaves a trail across the network, from initial reconnaissance to lateral movement and data exfiltration. That makes the network one of an [...]
Oracle Linux 7 389-ds-base Important Security Updates ELSA-2026-55758
Oracle Linux Firefox Important Remote Access Vulnern ELSA-2026-54248
Debian LTS DLA-4791-1 memcached Buffer Overflow and Timing Attacks
Visual Studio Code 1.138 brings agent sessions to Dev Containers
Visual Studio Code 1.380, the latest update to Microsoft’s open-source code editor, introduces three new features for AI-powered coding: agent sessions in [...]
Mageia perl-Dancer2 Vulnerable Session IDs Detected CVE-2026-13577
Mageia 10 9 Security Update PKCE Weak Random Number Issue CVE-2026-16615
Mageia 10 9 Important GNU cpio Path Traversal Memory Issues 2026-0435
Mageia diffutils Critical Heap Overflow Vulnern 2026-0434
Mageia Twinkle Bugfix Advisory for the Year 2026 and Update 0130
Why Seccomp Must Be Rechecked After Container Restore
Seccomp limits which Linux system calls a process can make.
How Container Restore Can Reopen Privilege Escalation Paths
Privilege escalation in a container does not always begin with a new exploit.
What CRIU Restores Beyond Application Memory in Linux Containers
Linux containers can be paused, checkpointed, and rebuilt later with CRIU.
Fedora 44 Chromium Buffer Overflow Race Condition Fix 2026-f910229c11
Fedora 44 Kernel Significant Patches Upgrade 2026-ca91e91bf0
Fedora 44 dotnet8.0 Severe Batch of CVEs Update 2026-0fa8c76e88
Fedora 44 dotnet10.0 Critical Multiple Threat Fixes 2026-a5c27e8727
Fedora 44 dotnet9.0 Critical SDK Updates CVE-2026-58649, CVE-2026-69304
Fedora 44 FreeIPMI Important Updates for CVE-2026-33554 2026-febfd10293
Fedora 44 postgresql16-anonymizer Major Arbitrary Execution CVE-2026-19633
Fedora 44 perl-Net-DNS 1.57 Denial of Service Fix Advisory 2026-57f107ed83
Fedora cyrus-imapd Security Advisory CVE-2026-47087 CVE-2026-47088
Why Container Security Needs a Separate Restore Boundary
A container normally starts under the security rules of the system receiving it.
Fedora 43 dotnet 8.0.131 Critical Update CVE-2026-58649 and More
Fedora 43 Dotnet 9.0 Update Addresses CVE-2026-58649 and More Issues
Fedora 43 dotnet10.0 Important SDK Runtime Update for CVEs 2026-04a0116777
Fedora 43 perl-Net-DNS CVE-2026-81928 Denial of Service Advisory
Fedora 43 Cyrus IMAP Update Security Advisory 2026-97a7ec5786
CRI-O Restore Flaw Can Bypass Kubernetes Security Policies
Kubernetes groups one or more containers into a pod, the basic unit it deploys.
SUSE Kernel Update 2026-4284-1 Important Security Issues Addressed
SUSE Bind Important Remote Denial of Service Fix SUSE-SU-2026-4285-1
SUSE Amazon SSM Agent Important Fix Denial of Service Vuln 2026-4286-1
SUSE openssl-certs Moderate Update Advisory 2026-4287-1
openSUSE php-composer2 Moderate Path Traversal Flaw Fix 2026-4288-1
SUSE php-composer2 Moderate Path Traversal Issues Fix 2026-4288-1
PH4NTXM Linux Builds a Disposable Identity at Every Boot
A live Linux distribution runs from removable media, usually a USB drive, without requiring a permanent installation.
Fedora 45 Kernel 7.2.7 Important System Update Advisory 2026-4c098c462e
Fedora 45 libxmp Medium Buffer Overflow Fix 2026-743387fdbe
Fedora 45 dotnet10.0 Critical SDK Runtime Update Advisory 2026-fa6de37202
Fedora 45 PostgreSQL 16 Anonymizer SQL Injection Vulnerabilities Found
Fedora 45 Cyrus IMAP Important Security Advisory 2026-3bf3e31ef4
DSA-6510-1 xdg-dbus-proxy – security update
Rocky Linux 9 webkit2gtk3 Important Security Update RLSA-2026-69098
Rocky Linux 9 curl Important Unauthorized Access Issue RLSA-2026-69126
Rocky Linux gstreamer1-plugins-base Security Issues Report RLSA-2026-69100
Rocky Linux RLSA-2026-69914 PostgreSQL Important SQL Injection Issues
Rocky Linux Sudo Important Policy Bypass Security Update RLSA-2026-69123
Rocky Linux osbuild-composer Security Advisory on XSS DoS Vulnerabilities
Rocky Linux OpenSSH Key Vulnerability Leads to SSH Protocol Security Bypass
Rocky Linux PostgreSQL Important Arbitrary Execution Issues RLSA-2026-69923
Rocky Linux PostgreSQL Important Execution Issues Advisory RLSA-2026-69876
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
A new Windows malware called CLOSEDQUORUM can query up to four LLM providers – Google Gemini, DeepSeek, Qwen, and Mistral – to autonomously [...]
ShinyHunters Hacks FBI Jobs Portal, Claims It Stole Agents’ Data
SUSE Freeipmi Key Buffer Overflow Denial of Service Vulnern 2026-4277-1
SUSE libtpms Moderate Heap Overflow Parameter Issues Advisory 2026-4278-1
SUSE Linux Enterprise Micro Important Kernel Update Vuln 2026-4279-1
SUSE perl-Authen-SASL Important Replay Attack Issue Advisory 2026-4280-1
SUSE 15 SP7 CUPS Moderate Heap Overflow CVE-2026-87875 Advisory 2026-4281-1
SUSE php-composer2 Critical Credential Leak and Code Exec Patch 2026-4283-1
AWS launches CloudWatch Omni to unify observability for AI agents and applications
As enterprises continue to move AI agents and agentic applications into production, AWS says traditional observability and monitoring tools — including its [...]
Ubuntu 26.04 Sudo Important Command Bypass Risk CVE-2026-82474 USN-8803-1
ShinyHunters claims FBI hack: ‘This is NOT financially motivated’
ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data – and this time it’s personal. The gang wants the Feds to correct the [...]
RatHat Android Malware Uses AI to Target Banking Credentials in Real Time
Ubuntu 20.04 OpenSSH Critical Arbitrary Code Execution DoS Flaw 2026-8804-1
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
As AI opens new paths to company data while making familiar attacks faster and cheaper, SMBs need protection designed around the time and expertise [...]
NightmareEclipse’s latest zero-day leaves Microsoft Defender stuck in the past
Serial Microsoft zero-day leaker NightmareEclipse has found another way to mess with Windows Defender, this time by stopping the antivirus from updating [...]
Z.ai says sorry for slurping up your code, open sources ZCode
Chinese AI giant Z.ai has apologized after developers caught it pulling a Grok, packaging up and uploading user workspaces to cloud storage. In a case [...]
MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide
UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
A coalition of law enforcement and private-sector tech companies led by Microsoft have disrupted the EvilTokens phishing service, arresting suspected [...]
Who signed off on that AI agent? Nobody? Thought so.
If you were in any doubt that AI agents are capable of complex autonomous work, that skepticism should have faded this summer. In July, news emerged that [...]
Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk
Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught [...]