Menu

Latest articles

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

Chinese agents caught rebuilding botnets and stirring the pot on AI datacenter debate

https://security-tracker.debian.org/tracker/DSA-6341-1

https://security-tracker.debian.org/tracker/DSA-6340-1

https://security-tracker.debian.org/tracker/DSA-6339-1

https://security-tracker.debian.org/tracker/DSA-6338-1

Smashing Security podcast #471: This AI worm just rewrote its own rules

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 149.0.7827.102-1~deb12u1.

A flaw was discovered in jackson-core, a fast and powerful JSON library for Java, which may allow an attacker to cause a denial of service by using deeply nested JSON data. Please note that related and complementary jackson-* packages like jackson- databind or jackson-dataformat-smile had to be upgraded as well in

https://security-tracker.debian.org/tracker/DSA-6335-1

https://security-tracker.debian.org/tracker/DSA-6334-1

https://security-tracker.debian.org/tracker/DSA-6333-1

https://security-tracker.debian.org/tracker/DSA-6332-1

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

How to use virtual environments in Python
Angry bug hunter with Microsoft beef drops new Windows 0-day
Cybercriminals: the ‘auditors’ you never hired

Every organisation gets audited. The question is who does the auditing.

Security update

Security update

HTTP-Daemon could be made to run programs if it received specially crafted network traffic.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves 12 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 4 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

USN-6455-1 introduced a regression in Exim

Why schools remain one of cybercriminals’ favourite targets
GitHub pulls pin on npm’s auto-run scripts

An update that solves one vulnerability can now be installed.

An update that solves six vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

Several vulnerabilities have been discovered in dnsmasq, a caching DNS proxy and DHCP/TFTP server. CVE-2026-2291 dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries,

Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9

Several security issues were fixed in Tomcat.

EU rules on securing IT products could affect open source software users beginning this week
The tokenmaxxing backlash is coming

Security update

Security update

Security update

Security update

Security update

Security update

Enterprises know AI-generated code is vulnerable; they’re shipping it anyway

New upstream release (151.0.3)

Update to xserver 21.1.23, Security fixes for: ZDI-CAN-30136, ZDI-CAN-30159, ZDI-CAN-30160, ZDI-CAN-30161, ZDI-CAN-30163, ZDI-CAN-30164, ZDI-CAN-30165, ZDI-CAN-30168

This is an update fixing a pre-authentication information disclosure (CVE-2026-48840).

This is an update fixing several security related problems in putty.

Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.3 (see CHANGELOG_WUI.md) Fixed a crash when running pcs resource|stonith list Fixed order of resources in sets when listing configuration of constraints

This is an update fixing a pre-authentication information disclosure (CVE-2026-48840).

This is an update fixing several security related problems in putty.

Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.3 (see CHANGELOG_WUI.md) Fixed a crash when running pcs resource|stonith list Fixed order of resources in sets when listing configuration of constraints

Security update

Security update

Security update

AI is making Patch Tuesday (kinda) fun again

Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit, which may result in denial of service, information leaks, or potentially remote code execution. Additional details can be found in the upstream advisory: https://openssl-library.org/news/secadv/20260609.txt

Several vulnerabilities were discovered in poppler, a PDF rendering library, which could result in denial of service, information disclosure, or potentially the execution of arbitrary code if a specially crafted file is processed. For the oldstable distribution (bookworm), these problems have been fixed

Security update

USN-8414-1 fixed several vulnerabilities in OpenSSL.

Go Networking could allow unintended access to network services.

Several security issues were fixed in Lodash.

GDK-PixBuf could be made to crash or run programs if it opened a specially crafted file.

USN-8398-1 introduced a regression in nginx

Miasma worms its way onto GitHub as attack kit goes open source

Several security issues were fixed in Cyborg.

Several security issues were fixed in QEMU.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Apple’s iOS 27 goes all agentic on compromised passwords, promises to change them with one tap

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves one vulnerability and has 4 bug fixes can now be installed.

An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed.