Menu

Latest articles

OpenAI developing GitHub rival as AI coding platform race intensifies
Smashing Security podcast #457: How a cybersecurity boss framed his own employee
WebAssembly proposal touted to improve Wasm web integration

https://security-tracker.debian.org/tracker/DSA-6157-1

MCP security: Implementing robust authentication and authorization
‘Hundreds’ of Iranian hacking attempts have hit surveillance cameras since the missile strikes
‘Hundreds’ of Iranian hacking attempts have hit surveillance cameras since the missile strikes
Malware-laced OpenClaw installers get Bing AI search boost
LexisNexis confirms data breach at Legal & Professional arm, some customer records affected
Kaspersky dismisses claims Coruna iPhone exploit kit is connected to NSA-linked operation
Linux Security Strategies for Cloud and IoT Environments
Protecting education: How MDR can tip the balance in favor of schools

The education sector is notoriously short on cash, but rich in assets for threat actors to target. How can managed detection and response (MDR) help learning institutions regain the initiative?

What I learned using Claude Sonnet to migrate Python to Rust
The right way to architect modern web applications
An ode to craftsmanship in software development
Google feels the need for security speed, so will ship Chrome updates every two weeks
Angular releases patches for SSR security issues
Dev stunned by $82K Gemini bill after unknown API key thief goes to town
Postman API platform adds AI-native, Git-based workflows
Chat at your own risk! Data brokers are selling deeply personal bot transcripts
Cyberwarriors elevated to big leagues in US war with Iran
They seized $4.8m in crypto… then gave the master key to the internet
Turns out most cybercriminals are old enough to know better
Until last month, attackers could’ve stolen info from Perplexity Comet users just by sending a calendar invite
Chrome Gemini panel became privilege escalator for rogue extensions
Cybercriminals swipe 15.8M medical records from French doctors ministry
Why AI requires rethinking the storage-compute divide
Under the hood with .NET 11 Preview 1
Cloud architects earn the highest salaries
Gamers furious as indie studio Cloud Imperium quietly admits to data breach
Phish of the day: Microsoft OAuth scams abuse redirects for malware delivery

https://security-tracker.debian.org/tracker/DSA-6156-1

https://security-tracker.debian.org/tracker/DSA-6155-1

Rust developers have three big worries – survey
Iran’s cyberwar has begun
UK businesses told to brace cyber defenses amid Iran conflict risk
Buyer’s guide: Comparing the leading cloud data platforms
Memory scalpers hunt scarce DRAM with bot blitz
Scammers try to SIM-swap Dubai citizens hours after Iranian missile strikes
FinOps for agents: Loop limits, tool-call caps and the new unit economics of agentic SaaS
AI makes networking matter again
UK government’s Vulnerability Monitoring System is working – fixes flow far faster
South Korea’s tax office apologizes for leaking seed phrase to seized crypto

https://security-tracker.debian.org/tracker/DSA-6154-1

AI trust through open collaboration: A new chapter for responsible innovation

https://security-tracker.debian.org/tracker/DSA-6153-1

Denizens of DEF CON are ‘fed up with government’
This month in security with Tony Anscombe – February 2026 edition

In this roundup, Tony looks at how opportunistic threat actors are taking advantage of weak authentication, unmanaged exposure, and popular AI tools

What Is ClamAV? A Linux Admins Guide to Risk, Monitoring, and Real-World Use

https://security-tracker.debian.org/tracker/DSA-6152-1

Double whammy: Steaelite RAT bundles data theft, ransomware in one evil tool
Suspected Nork digital intruders caught breaking into US healthcare, education orgs
Ransomware payments cratered in 2025, but attacks surged to record highs
French DIY etailer ManoMano admits customer data stolen
Cops back Dutch telco Odido after second wave of ShinyHunters leaks
Mobile app permissions (still) matter more than you may think

Start using a new app and you’ll often be asked to grant it permissions. But blindly accepting them could expose you to serious privacy and security risks.

Your staff are your biggest security risk: AI is making it worse
Rapid AI-driven development makes security unattainable, warns Veracode
Notorious ransomware gang allegedly blackmailed by fake FSB officer
Scattered Lapsus$ Hunters auditioning female voices to sharpen social engineering
Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover
Understanding the Snort NIDS: What It Changes in Your Monitoring and Risk Model
Claude collaboration tools left the door wide open to remote code execution
Smashing Security podcast #456: How to lose friends and DDoS people

https://security-tracker.debian.org/tracker/DSA-6151-1

https://security-tracker.debian.org/tracker/DSA-6150-1

https://security-tracker.debian.org/tracker/DSA-6149-1

The nervous system gets a soul: why sovereign cloud is telco’s real second act
Google catches Beijing spies using Sheets to spread espionage across 4 continents
Fake ‘interview’ repos lure Next.js devs into running secret-stealing malware
Ex-L3Harris exec jailed 7 years for selling exploits to Russia
Wynn Resorts takes attacker’s word for it that stolen staff data was deleted
OpenAI says Chinese cops used ChatGPT to plan and track smear ops against opponents
$10,000 bounty offered if you can hack Ring cameras to stop them sharing your data with Amazon
Threat intelligence supply chain is full of weak links, researchers find
What Is Fail2ban?

https://security-tracker.debian.org/tracker/DSA-6148-1

MCP security: The current situation
AI has gotten good at finding bugs, not so good at swatting them
Patch these 4 critical, make-me-root SolarWinds bugs ASAP
North Korea’s Lazarus Group targets healthcare orgs with Medusa ransomware
Go library maintainer brands GitHub’s Dependabot a ‘noise machine’
UK data watchdog fines Reddit £14.47M for letting kids slip past the gate
Korean cops charge teens over bike hire breach that exposed data on 4.62M riders
Faking it on the phone: How to tell if a voice call is AI or not

Can you believe your ears? Increasingly, the answer is no. Here’s what’s at stake for your business, and how to beat the deepfakers.

Spanish police say they have arrested hacker who booked luxury hotel rooms for just one cent
PromptSpy ushers in the era of Android threats using GenAI

ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow

Is Poshmark safe? How to buy and sell without getting scammed

Like any other marketplace, the social commerce platform has its share of red flags. It pays to know what to look for so you can shop or sell without headaches.

Smashing Security podcast #455: Face off: Meta’s Glasses and America’s internet kill switch
Dutch police arrest man for “hacking” after accidentally sending him confidential files
Is it OK to let your children post selfies online?

When it comes to our children’s digital lives, prohibition rarely works. It’s our responsibility to help them build a healthy relationship with tech.

Zero CVEs: The symptom of a larger problem
Extend trust across the software supply chain with Red Hat trusted libraries
Chasing the holy grail: Why Red Hat’s Hummingbird project aims for “near zero” CVEs
Urgent warnings from UK and US cyber agencies after Polish energy grid attack
Naming and shaming: How ransomware groups tighten the screws on victims

When corporate data is exposed on a dedicated leak site, the consequences linger long after the attack fades from the news cycle

Polish hacker charged seven years after massive Morele.net data breach
Smashing Security podcast #454: AI was not plotting humanity’s demise. Humans were
From challenge to champion: Elevate your vulnerability management strategy
Taxing times: Top IRS scams to look out for in 2026

It’s time to file your tax return. And cybercriminals are lurking to make an already stressful period even more edgy.