Menu

Latest articles

MGASA-2026-0026 – Updated xen packages fix security vulnerabilities

Microsoft previews GitHub Copilot app modernization for C++
Java developers want container security, just not the job that comes with it

https://security-tracker.debian.org/tracker/DSA-6116-1

Maybe CISA should take its own advice about insider threats hmmm?

https://security-tracker.debian.org/tracker/DSA-6114-1

Suse offers cloud sovereignty assessment tool
Hacking attack leaves Russian car owners locked out of their vehicles
New PDF compression filter will save space, need software updates
Apiiro’s Guardian Agent guards against insecure AI code
Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan

ESET researchers discover an Android spyware campaign targeting users in Pakistan via romance scam tactics, revealing links to a broader spy operation

To stop crims, Google starts dismantling residential proxy network they use to hide
AV vendor goes to war with security shop over update server scare
Seven habits that help security teams reduce risk without slowing delivery
ShinyHunters swipes right on 10M records in alleged dating app data grab
Patch or perish: Vulnerability exploits now dominate intrusions
Cyberattack on Poland’s power grid could have turned deadly in winter cold

Several security issues were fixed in containerd.

Several security issues were fixed in wlc.

Get started with Angular: Introducing the modern reactive workflow
Why your next microservices should be streaming SQL-driven

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves seven vulnerabilities can now be installed.

Upgrade to upstream. Eliminates distributing harfbuzz sources. Upgrade to upstream 0.032.

Crooks are hijacking and reselling AI infrastructure: Report
Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock

https://security-tracker.debian.org/tracker/DSA-6115-1

https://security-tracker.debian.org/tracker/DSA-6113-1

Google’s LiteRT adds advanced hardware acceleration
Ransomware crims forced to take off-RAMP as FBI seizes forum
Four arrested in crackdown on Discord-based SWATting and doxing
Everybody is WinRAR phishing, dropping RATs as fast as lightning
Drowning in spam or scam emails? Here’s probably why

Has your inbox recently been deluged with unwanted and even outright malicious messages? Here are 10 possible reasons – and how to stem the tide.

Fortinet unearths another critical bug as SSO accounts borked post-patch
Old Windows quirks help punch through new admin defenses
End-to-end security for AI: Integrating AltaStata Storage with Red Hat OpenShift confidential containers
Beware! Fake ChatGPT browser extensions are stealing your login credentials
Teradata unveils enterprise AgentStack to push AI agents into production
CPython vs. PyPy: Which Python runtime has the better JIT?
Is code a cow path?

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

# Recommended update for kernel-firmware Announcement ID: SUSE-SU-2026:0305-1 Release Date: 2026-01-27T16:15:14Z Rating: important References:

An update that solves two vulnerabilities can now be installed.

Gemini Flash model gets visual reasoning capability
OpenSilver 3.3 runs Blazor components inside XAML apps
Paranoid WhatsApp users rejoice: Encrypted app gets one-click privacy toggle

https://security-tracker.debian.org/tracker/DSA-6111-1

Let them eat sourdough: ShinyHunters claims Panera Bread as stolen credentials victim
China-linked group accused of spying on phones of UK prime ministers’ aides – for years
The AI Fix #85: ChatGPT gets ads, pets get AI therapists, and everyone’s wrong about LLMs
France to replace US videoconferencing wares with unfortunately named sovereign alternative
Anthropic integrates third‑party apps into Claude, reshaping enterprise AI workflows
Microsoft illegally installed cookies on schoolkid’s tech, data protection ruling finds
Alibaba’s Qwen3-Max-Thinking expands enterprise AI model choices
High Court to grill London cops over live facial recognition creep
Office zero-day exploited in the wild forces Microsoft OOB patch
From devops to CTO: 8 things to start doing now
What is the future for MySQL?
The private cloud returns for AI workloads

An update that solves 22 vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves 22 vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves 22 vulnerabilities, contains one feature and has six security fixes can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks. For the stable distribution (trixie), these problems have been fixed in version 21.0.10+7-1~deb13u1.

Unplugged holes in the npm and yarn package managers could let attackers bypass defenses against Shai-Hulud
Descope introduces Agentic Identity Hub 2.0 for managing AI agents

https://security-tracker.debian.org/tracker/DSA-6112-1

Canva among ~100 targets of ShinyHunters Okta identity-theft campaign
Kotlin-based Ktor 3.4 boosts HTTP client handling
Zero-trust data governance needed to protect AI models from slop
EU looking into Elon Musk’s X after Grok produces deepfake sex images
Data thieves borrow Nike’s ‘Just Do It’ mantra, claim they ran off with 1.4TB
Moscow likely behind wiper attack on Poland’s power grid, experts say
Stop treating force multiplication as a side gig. Make it intentional
Oracle AI sailed the world on Royal Navy flagship via cloud-at-the-edge kit
Why your AI agents need a trust layer before it’s too late
UK digital ID goes in-house, government swears it isn’t an ID card
16 open source projects transforming AI and machine learning
AI makes the database matter again

An update that solves 395 vulnerabilities, contains 29 features and has 43 security fixes can now be installed.

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Pwn2Own Automotive 2026 uncovers 76 zero-days, pays out more than $1M
Understanding security embargoes at Red Hat
New observability features in Red Hat OpenShift 4.20 and Red Hat Advanced Cluster Management 2.15

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks. For the oldstable distribution (bookworm), these problems have been fixed in version 17.0.18+8-1~deb12u1.

An update that solves one vulnerability and has 2 bug fixes can now be installed.

An update that solves 4 vulnerabilities and has 5 bug fixes can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

https://security-tracker.debian.org/tracker/DSA-6110-1