Menu

Latest articles

An update that solves two vulnerabilities and contains one feature can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto
Broadcom beefs up Spring security to protect against AI-enabled attacks
Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix

Several vulnerabilities have been discovered in the GNU C Library, the C standard library implementation used by Debian. CVE-2025-8058 posix: Fix double-free after allocation failure in regcomp The regcomp function in the GNU C library version from 2.4 to 2.41 is

Ransomware sends Illinois high school on an early summer vacation

Multiple security issues were found in libxml2, the GNOME XML library, which could lead to Denial of Service. CVE-2025-8732 Catalog parsing functions were missing cycle detection. When a catalog file contains a CATALOG directive pointing to itself,

Cron Job Abuse For Linux Persistence Mechanisms Detection
IronWorm Supply Chain Threat from Linux Credential Theft
Initiating Your Journey With Linux Server Security and Optimal Safeguarding
GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections
Protocol Buffers schemas expose remote code execution risk
NSO Group back in Meta’s crosshairs after alleged WhatsApp targeting
10 MCP servers to connect LLMs with databases
Making sense of too much code

Update to 149.0.7827.53 fix 429 CVEs ( CVE-2026-10881 through CVE-2026-11309)

Update to 1.9.22 — fix systemd sandboxing: add ReadWritePaths=/dev/shm for semaphore creation Backport fix for CVE-2026-41054: privilege escalation via command socket

https://security-tracker.debian.org/tracker/DSA-6331-1

https://security-tracker.debian.org/tracker/DSA-6329-1

https://security-tracker.debian.org/tracker/DSA-6328-1

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result privilege escalation, information disclosure, SQL injections, LDAP authentication bypass, cross-site scripting or spreadsheet (CSV/formula) injection. For the oldstable distribution (bookworm), these problems have been fixed

Multiple vulnerabilities were discoverd in Nginx, a high-performance web and reverse proxy server, which could result in remote code execution, denial of service or memory disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 1.22.1-9+deb12u8.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 149.0.7827.53-1~deb12u1.

An update that solves 5 vulnerabilities can now be installed.

An update that solves 15 vulnerabilities can now be installed.

An update that solves 14 vulnerabilities can now be installed.

An update that solves 6 vulnerabilities can now be installed.

An update that solves 45 vulnerabilities can now be installed.

An update that solves 3 vulnerabilities can now be installed.

An update that solves 6 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

New samba packages are available for Slackware 15.0 to fix security issues.

It was discovered that incorrect cookie header accounting in the HTTP/2 implementation of the Apache HTTP server may result in denial of service (excessive resources consumption). For Debian 11 bullseye, this problem has been fixed in version 2.4.67-1~deb11u2.

Security update

Security update

Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0

Fixes CVE-2026-41565

This update addresses CVE-2026-7598, a potential heap buffer overflow, which could be triggered remotely by supplying very long username and/or password strings.

Fix for CVE-2026-6067 .

Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0

Fixes CVE-2026-41565

Multiple security vulnerabilities have been discovered in Tomcat 9, a Java based web server, servlet and JSP engine which may result in a denial of service, authentication bypass or the disclosure of sensitive information. In order to address certain vulnerabilities and restore the compatibility with Tomcat 9, an upgrade of the Tomcat native library, libtcnative-1, […]

https://security-tracker.debian.org/tracker/DSA-6326-1

https://security-tracker.debian.org/tracker/DSA-6325-1

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 8 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 3 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result privilege escalation, information disclosure, SQL injections, LDAP authentication bypass, cross-site scripting or spreadsheet (CSV/formula) injection. For the oldstable distribution (bookworm), these problems have been fixed

It was discovered that incorrect cookie header accounting in the HTTP/2 implementation of the Apache HTTP server may result in denial of service (excessive resources consumption). For the oldstable distribution (bookworm), this problem has been fixed in version 2.4.67-1~deb12u3.

It was discovered that missing input sanitising in the DIGEST-MD5 parser of the GNU SASL library could result in denial of service. For Debian 11 bullseye, this problem has been fixed in version 1.10.0-4+deb11u2. We recommend that you upgrade your gsasl packages.

An update that solves 23 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves six vulnerabilities and has five fixes can now be installed.

Security update

Security update

Oxford Uni student data pwned yet again – this time via career platform breach

Update to latest upstream version.

New upstream release (151.0.3)

Add support for half-width fonts. Improve content filter compilation by avoiding file copies. Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches. Fix painting scrollbars when their width changes.

libinput 1.31.3, fixes a udev property inject via uinput devices that can lead to local privilege escalation

Update to Rust 1.96.0: New Range* types Assert matching patterns Changes to WebAssembly targets Stabilized APIs

An update that contains security fixes can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 11 vulnerabilities can now be installed.

An update that solves 11 vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves three vulnerabilities can now be installed.

https://security-tracker.debian.org/tracker/DSA-6324-1

https://security-tracker.debian.org/tracker/DSA-6323-1

Security update

Security update

Security update