Menu

Latest articles

GitHub: Woah, a genuinely helpful AI-assisted bug report that isn’t total slop. Here, Wiz, take this wad of cash

Several security issues were fixed in OpenSSH.

An update that solves two vulnerabilities and has one security fix can now be installed.

Alleged Silk Typhoon hacker extradited to the United States to face charges

Multiple vulnerabilities where identified in polkit, a toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes. CVE-2021-4115 Kevin Backhouse of GitHub Security Lab (GHSL) found that there is a

EU waves through open source age-check tool to keep kids safe online
Critical GitHub RCE bug exposed millions of repositories

PackageKit could be made to install packages as the administrator.

Oracle NetSuite announces AI coding skills for SuiteCloud developers
GoDaddy customer claims registrar transferred 27-year-old domain without any security checks
Why it’s so hard to create stand-alone Python apps
A new challenge for software product managers

An update that solves 14 vulnerabilities and has five security fixes can now be installed.

An update that solves 14 vulnerabilities and has five security fixes can now be installed.

30 ClawHub skills secretly turn AI agents into a crypto swarm
More fake extensions linked to GlassWorm found in Open VSX code marketplace

https://security-tracker.debian.org/tracker/DSA-6237-1

https://security-tracker.debian.org/tracker/DSA-6236-1

https://security-tracker.debian.org/tracker/DSA-6231-1

Don’t pay Vect a ransom – your data’s likely already wiped out
Kernel Hardening Trends: Whats Changing in Upstream Security Controls
Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leak

Important: grafana security update

Important: sudo security update

Important: kernel security update

Important: firefox security update

Important: gdk-pixbuf2 security update

Important: firefox security update

GitHub shifts Copilot to usage-based billing, signaling a new cost model for enterprise AI tools
Xiaomi releases MIT‑licensed MiMo models for long‑running AI agents
OpenAI’s Symphony spec pushes coding agents from prompts to orchestration
SUSE’s sovereignty pitch meets an inconvenient $6 billion question
The front-end architecture trilemma: Reactivity vs. hypermedia vs. local-first apps
Enterprise AI is missing the business core
French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches

https://security-tracker.debian.org/tracker/DSA-6235-1

https://security-tracker.debian.org/tracker/DSA-6234-1

https://security-tracker.debian.org/tracker/DSA-6233-1

https://security-tracker.debian.org/tracker/DSA-6232-1

Ongoing supply-chain attack ‘explicitly targeting’ security, dev tools
Medical and utility tech companies hacked by digital intruders

Several security issues were fixed in nginx.

Pillow could be made to crash if it opened a specially crafted file.

HAProxy could be made to expose sensitive information over the network.

Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile.

ClamAV could be made to crash if it opened a specially crafted HTML file.

Several security issues were fixed in strongSwan.

Ubuntu PackageKit Critical Local Privilege Escalation CVE-2026-41651
Trump’s Golden Dome gets $3.2BN of contractors and an AI sprinkle
Confidential clusters for Red Hat OpenShift: Developer Preview now available on Microsoft Azure with AMD SEV-SNP
Cybersec is a thankless job: expanding workload and shrinking pay packet
Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attempt
Microsoft updates the Windows Update Experience: You can hit pause now
ICO chief John Edwards steps back as workplace probe quietly unfolds
The best JavaScript certifications for getting hired
Google begins putting the guardrails on agentic AI
Anthropic’s magic code-sniffer: More Swiss cheese than cheddar, for now
Google Cloud Next proves what we suspected: Everything is AI now

An update that solves 25 vulnerabilities can now be installed.

Important: kernel-rt security update

Important: kernel-rt security update

Important: kernel-rt security update

How Linux Pentesting Improves Network Security
AI-Driven Cybersecurity Upgrades: 3 Strategic Uses
Tails 7.7 Surfaces Secure Boot Risk as 2026 Certificate Expiry Approaches
Boost Linux Security Through Clear and Readable Coding Practices

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.10.0esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.

Hot take: AI’s not going to kill open source code security

https://security-tracker.debian.org/tracker/DSA-6230-1

The calm before the ransom: What you see is not all there is

A breach claims the systems as well as the confidence that was, in retrospect, a major vulnerability

Understanding Log Management and Analysis Tools for Linux Systems
Crime crew impersonates help desk, abuses Microsoft Teams to steal your data

Backport security patches from OpenSSL 3.5.6

CVE-2026-35385: Fix privilege escalation via scp legacy protocol when not in preserving file mode CVE-2026-35388: Add connection multiplexing confirmation for proxy-mode multiplexing sessions CVE-2026-35387: Fix incomplete application of PubkeyAcceptedAlgorithms and

Fix CVE-2026-35535

Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-5713, CVE-2026-6100

Fix CVE-2026-40192.

Update to 147.0.7727.101 Critical CVE-2026-6296: Heap buffer overflow in ANGLE Critical CVE-2026-6297: Use after free in Proxy Critical CVE-2026-6298: Heap buffer overflow in Skia Critical CVE-2026-6299: Use after free in Prerender

Meta’s compute grab continues with agreement to deploy tens of millions of AWS Graviton cores
Germany’s sovereign AI hope changes hands
Former OpenAI research scientist launches new AI model for Tencent
GopherWhisper: A burrow full of malware

ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions

US clarifies mobile hotspots part of foreign router ban despite rarity of American made consumer kit
ShinyHunters claim they have cruise giant Carnival’s booty as 7.5M emails surface
Governments on high alert after CISA snuffs out Firestarter backdoor on fed network
More ancient Linux device support faces the chop
Intel bets the farm on AI inference to drag CPU back to the top table
Microsoft beefs up Remote Desktop security with … hard-to-read messages
It’s a myth that you need Mythos to find bugs: Open source models can do it just as well
Integrating Red Hat Lightspeed with CrowdStrike for enhanced malware detection coverage

Several security issues were fixed in GStreamer Bad Plugins.

Greece relaxes Euro biometric border entry rules amid airport chaos
Why world models are AI’s next frontier
Where to begin a cloud career

An update that solves 10 vulnerabilities, contains one feature and has one security fix can now be installed.

An update that solves nine vulnerabilities, contains one feature and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.