August 6, 2026
Mageia 10-9 Font-Tools Bugfix Security Advisory 2026-0078
August 6, 2026
AI struggles to patch vulns without adult supervision
AI models may not be that good at fixing security flaws. Researchers at 1Password’s Off-by-1 Labs analyzed security patches generated by two frontier [...]
August 6, 2026
Oracle Linux 10 ELSA-2026-27288 Important Kernel Bug Fix
August 6, 2026
Humans in the loop miss a third of dangerous AI coding agent requests
A browser-based game designed to test humans’ ability to safely approve AI coding agent requests suggests humans in the loop aren’t as good at [...]
August 6, 2026
Mak’s Weekly Security Roundup: Critical Linux Security Updates Admins Should Know
This week’s most important Linux security updates arrived through vendor advisories rather than major headline-making disclosures.
August 6, 2026
Kubernetes Maintainers Expand CSI Path Traversal Fixes Beyond Original Vulnerabilities
Kubernetes maintainers patched two path-traversal vulnerabilities in the NFS and SMB CSI drivers earlier this year. But repository histories show that the [...]
August 6, 2026
IT department put sticky notes on the laptops to help employees log in
PWNED Welcome back to PWNED, the weekly column where we lovingly poke fun at other organizations’ security screw-ups, in hopes the rest of us can [...]
August 6, 2026
Meta launches Muse Code for complex software work with persistent AI agents
Meta has released a beta coding agent designed to handle complex software assignments across large codebases. Available for macOS and Linux, Muse Code uses [...]
August 6, 2026
Agents are coming for data (just slowly)
Agents have turned up just about everywhere in software this past year, with one conspicuous exception: data. That’s a little odd, because querying data is [...]
August 6, 2026
Microsoft Web IQ: Ground your AI agents with up-to-date web data
Microsoft has unveiled a suite of IQ products over the last few months. Work IQ, Fabric IQ, and Foundry IQ build on what Microsoft used to call its [...]
August 6, 2026
Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway
Chinese Wi-Fi router vendor Zbtlink has denied its products contain backdoors but paused firmware downloads while it fixes unspecified security [...]
August 6, 2026
Rocky Linux Kernel Moderate DoS Bug Fixes RLSA-2026-49871
August 6, 2026
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
The chain of events leading up to OpenAI’s agents attacking Hugging Face and other organizations in July began months earlier, and involved agents asking [...]
August 6, 2026
SUSE pcp Critical DoS Command Injection Advisory 2026-3506-1
August 6, 2026
DSA-6415-1 linux – security update
August 6, 2026
DSA-6414-1 udisks2 – security update
August 6, 2026
DSA-6413-1 libde265 – security update
August 6, 2026
Java 28 starts to take shape
Java Development Kit (JDK) 28, a non-LTS (Long-Term Support) or “feature release” of standard Java due in March 2027, has started to take shape. Features [...]
August 5, 2026
Oracle Thunderbird Significant Revision ELSA-2026-49922
August 5, 2026
Oracle Linux 8 ELSA-2026-500121 Kernel Important Update
August 5, 2026
Prompt injection isn’t the bug, AI agent frameworks are
Nearly a dozen flaws, some critical, in major AI agent frameworks that enterprises use to build apps reveal a security failure that extends beyond prompt [...]
August 5, 2026
Strengthening Linux Cybersecurity in Enterprise Infrastructure
Linux runs cloud platforms, containerized applications, and business-critical servers. It is the engine that powers much of today’s business [...]
August 5, 2026
Visual Studio Code 1.132 advances built-in dictation
Visual Studio Code 1.132, the latest version of Microsoft’s popular, open-source code editor, has been released. The brings improvements to built-in [...]
August 5, 2026
Choosing the Right Secrets Detection Platform
Not every security incident begins with sophisticated malware or a compromised server. Sometimes it is nothing more than a developer pushing code before [...]
August 5, 2026
IBM’s agentic AI platform is under active attack – patch now
A critical vulnerability in IBM-owned, low-code AI builder Langflow lets unauthenticated attackers execute code remotely on vulnerable default deployments, [...]
August 5, 2026
AWS updates DynamoDB with native vector search to ease AI application development
AWS is finally adding native vector search to its managed NoSQL database DynamoDB, which is typically used to store high-volume operational and [...]
August 5, 2026
Reducing Attack Surface Without Breaking Production
When people talk about Linux hardening, the conversation often quickly turns to enterprise security platforms, EDR agents, and complex monitoring stacks.
August 5, 2026
London cops handed victim’s new address and number to her stalker, watchdog says
UPDATED The UK’s data protection regulator has criticized London’s Metropolitan Police Service (MPS) after its officers handed a victim’s [...]
August 5, 2026
UK charities count the cost of Beacon CRM cyberattack
Beacon CRM has confirmed it was hit by a cyberattack that exposed data belonging to a growing list of UK charities. The company, which markets its software [...]
August 5, 2026
Five ways to evaluate AI agent orchestration platforms
AI agent orchestration platforms coordinate role-based and task-based AI agents, along with the tools, data, and people they depend on, into multistep [...]
August 5, 2026
A trip down shareware lane
I hope you’ll indulge me this week as I take a break from my usual rantings about agentic coding and meander down memory lane. I learned to code BASIC in [...]
August 5, 2026
Ruby on Rails critical bug puts every image upload under scrutiny
A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066, could turn a seemingly innocuous image into a front [...]
August 5, 2026
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project
The UK’s AI Security Institute has observed AI models performing what it calls “unsanctioned action” 19 times during security tests. The Institute (AISI) [...]
August 5, 2026
