Menu

Latest articles

Databricks adds MemAlign to MLflow to cut cost and latency of LLM evaluation
The ‘Super Bowl’ standard: Architecting distributed systems for massive concurrency
How to reduce the risks of AI-generated code
Beyond NPM: What you need to know about JSR
What is context engineering? And why it’s the new AI architecture
Deno Sandbox launched for running AI-generated code
Three clues that your LLM may be poisoned with a sleeper-agent back door

MGAA-2026-0010 – Updated libformula & ant-contrib packages fix bug

Satya Nadella decides Microsoft needs an engineering quality czar
What Is AppArmor? A Practical Look for Linux Admins

Fix CVE-2026-24882: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution

Regenerate vendor tarball. Fixes CVE-2025-13465.

Regenerate vendor tarball. Fixes CVE-2025-13465.

Version 12.5.8 – 2026-01-27 Changed To prevent Poisoned Pipeline Execution (PPE) attacks using prepared .coverage files in pull requests, a PHPT test will no longer be run if the temporary file for writing code coverage information already exists before the test runs

Smashing Security podcast #453: The Epstein Files didn’t hide this hacker very well

https://security-tracker.debian.org/tracker/DSA-6118-1

AWS intruder achieved admin access in under 10 minutes thanks to AI assist, researchers say
Apple’s Xcode 26.3 brings integrated support for agentic coding
Critical SolarWinds Web Help Desk bug under attack
Nitrogen ransomware is so broken even the crooks can’t unlock your files
GitHub eyes restrictions on pull requests to rein in AI-based code deluge on maintainers
Universal £7,500 payout offered to PSNI staff over major data breach
Azure outage disrupts VMs and identity services for over 10 hours
4 self-contained databases for your apps
AI is not coming for your developer job
Six reasons to use coding agents

A security issue was discovered in Thunderbird, which could result in information disclosure. For Debian 11 bullseye, this problem has been fixed in version 1:140.7.1esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

Several security issues were fixed in ImageMagick.

Several security issues were fixed in MySQL.

Clouds rush to deliver OpenClaw-as-a-service offerings

MGAA-2026-0009 – Updated subversion packages fix bug

What Is SELinux? A Practical Take for Linux Admins
Vercel revamps AI-powered v0 development platform
AI agents can’t yet pull off fully autonomous cyberattacks – but they are already very helpful to crims
Critical React Native Metro dev server bug under attack as researchers scream into the void
CISA updated ransomware intel on 59 bugs last year without telling defenders
A slippery slope: Beware of Winter Olympics scams and other cyberthreats

It’s snow joke – sporting events are a big draw for cybercriminals. Make sure you’re not on the losing side by following these best practices.

X marks the raid: French cops swoop on Musk’s Paris ops
Microsoft finally sends TLS 1.0 and 1.1 to the cloud retirement home
Polish cops bail 20-year-old bedroom botnet operator
DIY AI bot farm OpenClaw is a security ‘dumpster fire’
British military to get legal OK to swat drones near bases

xrdp is an open source RDP server. It was found that xrdp contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code

Several security issues were fixed in CRaC JDK 21.

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 8.

Several security issues were fixed in OpenJDK 11.

15.x 15.1 (2026-01-24) Fix #15088: When building a new train, the refit button state may be incorrect (#15162) Fix #15160: Incorrect company names displayed in load game window (#15161)

Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor
StopICE hacked to send alarming text messages, admins accuse border patrol agent of sabotage
Russia-linked APT28 attackers already abusing new Microsoft Office zero-day
McDonald’s is not lovin’ your bigmac, happymeal, and mcnuggets passwords
OpenClaw patches one-click RCE as security Whac-A-Mole continues
Notepad++ update service hijacked in targeted state-linked attack

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Infrastructure cyberattacks are suddenly in fashion. We can buck the trend
How should AI agents consume external data?
AI will not save developer productivity

An update that solves five vulnerabilities and contains one feature can now be installed.

An update that solves five vulnerabilities and contains one feature can now be installed.

An update that solves three vulnerabilities can now be installed.

Why native cloud security falls short

An update that fixes one vulnerability is now available.

Open-source AI is a global security nightmare waiting to happen, say researchers
Enterprise Spotlight: Manufacturing Reimagined
AI security startup CEO posts a job. Deepfake candidate applies, inner turmoil ensues.

Multiple vulnerabilities have been found in Pillow, an image processing library for Python. CVE-2021-23437 The getrgb function is susceptible to a ReDoS. CVE-2022-24303

Ceph is a distributed object, block, and file storage platform. CVE-2022-0670 A flaw was found in Openstack manilla owning a Ceph File system “share”, which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the

Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2025-67724 Custom reason phrases can cause multiple vulnerabilities (like XSS, header injection, …) due to being used unescaped in HTTP headers.

Security fix for CVE-2026-24049

Update to 0.46.3, fixes CVE-2026-24049.

Fix CVE-2025-15536

This month in security with Tony Anscombe – January 2026 edition

The trends that emerged in January offer useful clues about the risks and priorities that security teams are likely to contend with throughout the year

DynoWiper update: Technical analysis and attribution

ESET researchers present technical details on a recent data destruction incident affecting a company in Poland’s energy sector

FBI takes notorious RAMP ransomware forum offline

MGAA-2026-0008 – Updated remove-old-kernels packages fix bugs

AI use may speed code generation, but developers’ skills suffer

https://security-tracker.debian.org/tracker/DSA-6117-1

Important: openssl security update

Moderate: glibc security update

Moderate: gcc-toolset-15-binutils security update

Important: openssl security update

Moderate: curl security update

January blues return as Ivanti coughs up exploited EPMM zero-days
How Banco do Brasil uses hyperautomation and platform engineering to drive efficiency
From if to how: A year of post-quantum reality
Thousands more Oregon residents learn their health data was stolen in TriZetto breach
Google expands BigQuery with conversational agent and custom agent tools

A security issue was discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), this problem has been fixed in version 144.0.7559.109-1~deb12u1.

The best free cloud computing courses in 2026
Are you ready for JavaScript in 2026?

An update that solves seven vulnerabilities can now be installed.

Best Open-Source Linux Patch Management Software for Secure Linux Servers
Who profits from AI? Not OpenAI, says think tank

MGASA-2026-0029 – Updated openssl packages fix security vulnerabilities

MGASA-2026-0028 – Updated gpsd packages fix security vulnerabilities

MGASA-2026-0027 – Updated libxml2 packages fix security vulnerabilities