Menu

Latest articles

What will AI-first UX look like?
Will the hyperscalers own AI workloads forever?

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Security update

Security update

Security update

Security update

Security update

A vulnerability was discovered in yelp, the GNOME help browser, that allows a crafted help document to read files accessible to the user and exfiltrate them to a remote server through resources loaded by the embedded web view. When yelp is launched from a sandboxed application (for example via the Flatpak OpenURI portal), this also […]

updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the

keep GTK4 in rawhide for now switch to GTK4 for GVim Fix CVE-2026-46483

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl’s built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.

Update to 1.25.1 (rhbz#2480119) Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto Networks, for the report.

This is an update fixing CVE-2026-43964.

CVE-2026-27851: lib-var-expand: Safe filter marks all following pipelines safe. CVE-2026-33603: auth: CRAM-SHA-*-PLUS channel binding could be faked. MITM attacker with a certificate trusted by the client could have bypassed the requirement for channel binding. CVE-2026-40020: IMAP folders can be shared-spammed to everyone.

Update to Samba 4.24.3 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238

Update to Samba 4.24.3 – Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238

Update to 3.26.4, fixes CVE-2026-8631, CVE-2026-8632

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl’s built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.

This is an update fixing CVE-2026-43964.

CVE-2026-27851: lib-var-expand: Safe filter marks all following pipelines safe. CVE-2026-33603: auth: CRAM-SHA-*-PLUS channel binding could be faked. MITM attacker with a certificate trusted by the client could have bypassed the requirement for channel binding. CVE-2026-40020: IMAP folders can be shared-spammed to everyone.

https://security-tracker.debian.org/tracker/DSA-6320-1

https://security-tracker.debian.org/tracker/DSA-6319-1

Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week

https://security-tracker.debian.org/tracker/DSA-6316-1

Election interlopers register 5K+ domains, hope to catch some voting phish
Why Linux Rootkits Still Matter in Cloud and VMware Environments 

An update that solves 60 vulnerabilities and has three security fixes can now be installed.

An update that solves 60 vulnerabilities and has three security fixes can now be installed.

An update that solves 29 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

Qt Declarative could be made to use excessive resources if it received specially crafted input.

Evolution Data Server could be made to remove files.

GTA cheat service Atlas Menu hacked as attacker alleges screenshot spying
Linux IDS vs IPS: Operational Differences and Deployment Tradeoffs

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 68 vulnerabilities, contains one feature and has 10 security fixes can now be installed.

An update that solves 68 vulnerabilities, contains one feature and has 10 security fixes can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Palo Alto VPN bug graduates from advisory to active exploitation
Flowise’s MCP implementation can run ghost commands
Password manager Dashlane suspends customer accounts amid brute-force attacks

Several security issues were fixed in rsync.

Putin sends submarines to survey Britain’s subsea cables. UK deploys Royal Navy, mobilizes parliamentary draftsmen

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the kernel.

How to succeed with AI-powered devops tools
How to run enterprise GenAI like a production service
AI’s brave new world of technical debt

An update that solves six vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

SUSE Linux 15 SP7 Kernel RT Important Live Patch 13 Local Root Exploit
An update that solves three vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

Several vulnerabilities have been found in aiohttp, an asynchronous HTTP client/server framework for asyncio and Python. CVE-2025-53643 Request smuggling vulnerability due to not parsing trailer sections of an HTTP request.

Update to 1.5.4. Fixes a buffer overflow caused by integer promotion rules in OFBMPImageFormatHandler and OFQOIImageFormatHandler. Update to 1.5.3

Update to 1.5.4. Fixes a buffer overflow caused by integer promotion rules in OFBMPImageFormatHandler and OFQOIImageFormatHandler. Update to 1.5.3

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 148.0.7778.215-1~deb12u1.

https://security-tracker.debian.org/tracker/DSA-6318-1

https://security-tracker.debian.org/tracker/DSA-6317-1

10 essential reads to optimize performance, security, and ROI in the AI era
7 features of Red Hat Identity Management you need to know for the modern enterprise
Advancing post-quantum capabilities of SSH in Red Hat Enterprise Linux

https://security-tracker.debian.org/tracker/DSA-6315-1

https://security-tracker.debian.org/tracker/DSA-6314-1

https://security-tracker.debian.org/tracker/DSA-6313-1

https://security-tracker.debian.org/tracker/DSA-6312-1

This month in security with Tony Anscombe – May 2026 edition

In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit

Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries