Menu

Latest articles

EU legal eagle says banks should refund cybercrime victims first, argue later

GeoPandas could be vulnerable to SQL injection attacks.

Drive business productivity through open collaboration, AI and document creation
Building the UK’s next generation of cyber talent
First look: Electrobun for TypeScript-powered desktop apps
An LLM that will help you build a nuclear weapon
Pity the developers who resist agentic coding

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Amazon is linking site hiccups to AI efforts

0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS

0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS

Claude Code adds code reviews

https://security-tracker.debian.org/tracker/DSA-6158-1

TypeScript 6.0 reaches release candidate stage
Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack
Cybercrime isn’t just a cover for Iran’s government goons – it’s a key part of their operations
Crooks compromise WordPress sites to push infostealers via fake CAPTCHA prompts
Twitter suspended 800 million accounts last year – so why does manipulation remain so rampant?
JetBrains launches Air and Junie CLI for AI-assisted development
Fake job applications pack malware that kills EDR before stealing data

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves two vulnerabilities and has one security fix can now be installed.

Ericsson blames vendor vishing slip-up for breach exposing thousands of records
Protecting democracy means democratizing cybersecurity. Bring on the hackers
Polish cops bust alleged teen DDoS kit sellers – youngest just 12
MariaDB taps GridGain to keep pace with AI-driven data demands
5 requirements for using MCP servers to connect AI agents
How developers can bring voice AI into telephony applications
Neoclouds run AI cheaper and better
Port Scanning Explained: Tools, Techniques, and Best Open-Source Port Scanners for Linux

Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools

Update to 1.3.2.

Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. Current versions of the module strip leading zeros from octets.

Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools

AI vs AI: Agent hacked McKinsey’s chatbot and gained full read-write access in just two hours
Ruby sinking in popularity, buried by Python – Tiobe
ShinyHunters claims more high-profile victims in latest Salesforce customers data heist
EV charger biz ELECQ zapped by ransomware crooks, customer contact data stolen
Dutch cops warn 100 alleged scammers: Turn yourselves in or we tell Grandma
Russian cybercrims phish their way into officials’ Signal and WhatsApp accounts
Microsoft Azure CTO set Claude on his 1986 Apple II code, says it found vulns
Anthropic debuts Claude Marketplace to target AI procurement bottlenecks
How generative UI cut our development time from months to weeks
Royal Navy races to arm ships against drone threat
19 large language models for safety or danger
Coding for agents

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves six vulnerabilities can now be installed.

Iran is the first out-loud cyberwar the US has fought
FBI is investigating breach that may have hit its wiretapping tools

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

AI agents now help attackers, including North Korea, manage their drudge work
What cybersecurity actually does for your business

The ability to continue operating safely in an unsafe environment where competitors cannot is a competitive advantage that is rarely measured or discussed

Update to 145.0.7632.116 * CVE-2026-3061: Out of bounds read in Media * CVE-2026-3062: Out of bounds read and write in Tint * CVE-2026-3063: Inappropriate implementation in DevTools

Update to 2.87.3

Update to 2.69.4

Rename from golang-github-prometheus and upgrade to 3.10.0

hex_core ver. 0.12.2

Rename from golang-honnef-tools and update to 2026.1

MCP C# SDK 1.0 arrives with improved authorization server discovery
Firefox taps Anthropic AI bug hunter, but rancid RAM still flipping bits
Spyware disguised as emergency-alert app sent to Israeli smartphones
How hackers bypassed MFA with a $120 phishing kit – until a global takedown shut it down
Cisco warns of two more SD-WAN bugs under active attack
Microsoft spots ClickFix campaign getting users to self-pwn on Windows Terminal
Son of government contractor arrested after alleged $46M crypto heist from US Marshals
Microsoft finally gets around to fixing Windows 10 Recovery Environment after breaking it in October
Microsoft finally gets around to fixing Windows 10 Recovery Environment after breaking it in October
Transport for London says 2024 breach affected 7M customers, not 5,000
Transport for London says 2024 breach affected 7M customers, not 5,000
Why enterprises are still bad at multicloud
Why local-first matters for JavaScript

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 145.0.7632.159-1~deb12u1.

Important: postgresql16 security update

Important: postgresql16 security update

Rust 1.94 arrives with array windows to iterate slices
Google says spyware makers and China-linked groups dominated zero-day attacks last year
Google says spyware makers and China-linked groups dominated zero-day attacks last year
Visual Studio Code previews agent plugins
Iran intelligence backdoored US bank, airport, software outfit networks
Iran intelligence backdoored US bank, airport, software outfit networks
UK watchdog eyes Meta’s smart glasses after workers say they ‘see everything’
UK watchdog eyes Meta’s smart glasses after workers say they ‘see everything’
How SMBs use threat research and MDR to build a defensive edge

We speak to Director of ESET Threat Research Jean-Ian Boutin about where solutions that blend advanced technology with human expertise provide the most practical value for businesses

What I learned as an undercover agent on Moltbook
The revenge of SQL: How a 50-year-old language reinvents itself