Menu

Latest articles

US foreign router ban criticized for being ‘industrial policy disguised as cybersecurity’

https://security-tracker.debian.org/tracker/DSA-6187-1

https://security-tracker.debian.org/tracker/DSA-6186-1

https://security-tracker.debian.org/tracker/DSA-6185-1

https://security-tracker.debian.org/tracker/DSA-6184-1

https://security-tracker.debian.org/tracker/DSA-6183-1

MGASA-2026-0073 – Updated python-ujson packages fix security vulnerabilities

MGASA-2026-0072 – Updated strongswan packages fix security vulnerability

Security fix for CVE-2026-4519.

Security fix for CVE-2026-4519.

Rebuilt with rust-tar 0.4.45 for CVE-2026-33056

Rebuilt with rust-tar 0.4.45 for CVE-2026-33056

https://security-tracker.debian.org/tracker/DSA-6181-1

RSAC 2026 wrap-up – Week in security with Tony Anscombe

This year, AI agents took the center stage – as a defensive capability, but more pressingly as a risk many organizations haven’t caught up with

A cunning predator: How Silver Fox preys on Japanese firms this tax season

Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them

AI security: Identity and access control

MGASA-2026-0071 – Updated nodejs packages fix security vulnerabilities

MGASA-2026-0070 – Updated libpng packages fix security vulnerabilities

Update to 146.0.7680.164 * High CVE-2026-4673: Heap buffer overflow in WebAudio * High CVE-2026-4674: Out of bounds read in CSS * High CVE-2026-4675: Heap buffer overflow in WebGL * High CVE-2026-4676: Use after free in Dawn

Update to v2.0.52

Update to 1.23.1

Update to 1.23.1

https://security-tracker.debian.org/tracker/DSA-6182-1

Kotlin 2.3.20 harmonizes with C, JavaScript/Typescript

https://security-tracker.debian.org/tracker/DSA-6180-1

https://security-tracker.debian.org/tracker/DSA-6179-1

Final training of AI models is a fraction of their total cost

An update that solves seven vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

AFC Ajax drops ball as flaws let hackers play admin with tickets and bans
OpenAI adds plugin system to Codex to help enterprises govern AI coding agents
Anthropic throttles Claude subscriptions to meet capacity
Iran war drives urgent need to counter underwater attack drones
On the pleasures and dangers of open source Python
Edge clouds and local data centers reshape IT
Security boffins scoured the web and found hundreds of valid API keys
Context Hub vulnerable to supply chain attacks, says tester
Visual Studio Code previews chat customizations editor

https://security-tracker.debian.org/tracker/DSA-6178-1

World Leaks data extortion: What you need to know
Virtual machines, virtually everywhere – and with real security gaps

Cloud VMs offer unmatched speed, scale and flexibility – all of which could eventually count for little if they’re left to fend for themselves

Databricks pitches Lakewatch as a cheaper SIEM — but is it really?
Brit lawmaker targeted by AI deepfake fails to get answers from US Big Tech
What does “AI security” mean and why does it matter to your business?
Smashing Security podcast #460: Never knock on the door of a nuclear submarine base and ask for a selfie
Google targets AI inference bottlenecks with TurboQuant
UK wants to know if banning under-16s from social media does anything useful
Basic and advanced Java serialization
Rethinking VM data protection in cloud-native environments
Swift 6.3 boosts C interoperability, Android SDK

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

Indian government probes CCTV espionage operation linked to Pakistan

Update to 146.0.7680.164 * High CVE-2026-4673: Heap buffer overflow in WebAudio * High CVE-2026-4674: Out of bounds read in CSS * High CVE-2026-4675: Heap buffer overflow in WebGL * High CVE-2026-4676: Use after free in Dawn

Claude Code AI tool getting auto mode
AI supply chain attacks don’t even require malware…just post poisoned documentation
Scammers have virtual smartphones on speed dial for fraud
Jen Easterly, cybersecurity’s ‘relentless optimist,’ hopes feds come back to RSAC next year
Only Trump can decide when cyberwar turns into real war
Cloud workload security: Mind the gaps

As IT infrastructure expands, visibility and control often lag behind – until an incident forces a reckoning

PyPI warns developers after LiteLLM malware found stealing cloud and CI/CD credentials
Cloudflare launches Dynamic Workers for AI agent execution
How one man used 10,000 bots to steal $8,000,000 from music artists
Oracle adds pre-built agents to Private Agent Factory in AI Database 26ai
Speed boost your Python programs with new lazy imports
Stop worrying: Instead, imagine software developers’ next great pivot
TypeScript 6.0 arrives

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 146.0.7680.164-1~deb12u1.

Enterprise PCs are unreliable, unpatched, and unloved compared to Macs

Update to release v1.9.1

Update to 146.0.7680.153 * CVE-2026-4439: Out of bounds memory access in WebGL * CVE-2026-4440: Out of bounds read and write in WebGL * CVE-2026-4441: Use after free in Base * CVE-2026-4442: Heap buffer overflow in CSS

Update to version 1.3.1 to fix CVE-2026-28356.

Update to release v1.9.1 Resolves: rhbz#2448053, rhbz#2423997, rhbz#2424031 Upstream fixes

Update to 146.0.7680.153 * CVE-2026-4439: Out of bounds memory access in WebGL * CVE-2026-4440: Out of bounds read and write in WebGL * CVE-2026-4441: Use after free in Base * CVE-2026-4442: Heap buffer overflow in CSS

https://security-tracker.debian.org/tracker/DSA-6177-1

New JetBrains platform manages AI coding agents
EFF has a new boss to lead the fight against privacy-sucking forces of doom
1K+ cloud environments infected following Trivy supply chain attack
LiteLLM loses game of Trivy pursuit, gets compromised
HackerOne slams supplier for delayed breach notice after staff data exposed

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that solves 11 vulnerabilities and has two security fixes can now be installed.

An update that solves 11 vulnerabilities and has two security fixes can now be installed.

An update that solves one vulnerability and has two security fixes can now be installed.

An update that solves one vulnerability and has two security fixes can now be installed.

Country that put backdoors into Cisco routers to spy on world bans foreign routers
New ‘StoatWaffle’ malware auto‑executes attacks on developers
Russian initial access broker who fed ransomware crews gets 81 months in US prison
An architecture for engineering AI context
7 safeguards for observable AI agents
Designing self-healing microservices with recovery-aware redrive frameworks
When Windows 11 sneezes, Azure catches cold