Menu

Latest articles

https://security-tracker.debian.org/tracker/DSA-6308-1

https://security-tracker.debian.org/tracker/DSA-6307-1

An update that solves 6 vulnerabilities can now be installed.

ICE to keep an eye on your eyes under $25M biometric scanner deal
No fix yet for critical RCE bug in open-source Git service Gogs – exploit module is out
ESET APT Activity Report Q4 2025–Q1 2026

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026

Amazon deletes devs’ tokenmaxxing leaderboard to minimize costs
23andMe inherits lawsuit over ‘disturbing’ DNA data breach
DNS-AID will make AI agents easier to discover, says Linux Foundation
Certifiably random: Swiss researchers claim perfect random number source
Dutch cops wrest 17M devices from mystery botnet’s clutches
How To Understand Failed Authentication Patterns in Linux Logs
How to Respond After Detecting a Compromised Linux Server
ChatGPT blindly trusts browser content, turning the page into a payload
Russia-linked threat group put ChatGPT to work from lure to payload
ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak
How are enterprises using cloud today?
Police arrest man following hack of Ajax football club
IBM and Red Hat want to become the ‘security clearinghouse’ for open source applications in the enterprise
Lack of response to critical vulnerability in Gogs is a reminder of the limits of open source projects

https://security-tracker.debian.org/tracker/DSA-6311-1

https://security-tracker.debian.org/tracker/DSA-6310-1

https://security-tracker.debian.org/tracker/DSA-6309-1

https://security-tracker.debian.org/tracker/DSA-6304-1

https://security-tracker.debian.org/tracker/DSA-6303-1

https://security-tracker.debian.org/tracker/DSA-6302-1

https://security-tracker.debian.org/tracker/DSA-6301-1

Troops’ phones gave away location data to foreign adversaries
Disgruntled 0-day hunter ‘humiliated’ by Microsoft pledges ‘bone shattering drop’ as Redmond calls cops
Snowflake buys Natoma to help freeze out rogue agents
What to consider before asking an AI chatbot for health advice

Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe.

Microsoft tests the 15-character limit of Windows Server admins’ patience
MyPillow listed on ransomware gang’s leak site, but denies it has been breached
SSH Key Sprawl on Linux Unmanaged Access Threats and Cleanup Guide
How to Diagnose Suspicious Outbound Connections on Linux Servers 
Supply chain battles intensify as takedowns meet AI-driven noise
Carnival confirms ShinyHunters cruised off with 6M customer records after April breach
Developers on H-1B face a tighter job market as AI shifts hiring priorities
Snowflake to acquire MCP-focused Natoma to boost governance for AI agents
An open-source toolkit for controlling out-of-control AI agents
Stop checking AI-generated code. Start generating less of it
Company CEO flooded file share with smut, called for help after he deleted it

https://security-tracker.debian.org/tracker/DSA-6306-1

https://security-tracker.debian.org/tracker/DSA-6305-1

Smashing Security podcast #469: What your Oura ring won’t tell you

https://security-tracker.debian.org/tracker/DSA-6300-1

https://security-tracker.debian.org/tracker/DSA-6299-1

https://security-tracker.debian.org/tracker/DSA-6298-1

Several security issues were fixed in Samba.

Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix, which might result in bypass of access checks, overwrite of files in unintended situations using the WORM vfs module, installing CA certificates over http without verification when auto-enrollment GPO is enabled, denial of service or remote code

CrowdStrike, Google shatter Glassworm botnet
BTMOB: A stealthy RAT burrowing deep into Android devices

The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise

Bosses blinded by confidence about shadow AI use by workers
FBI: Get to know your IT guy – extortion crews are visiting law firms pretending to be tech support
FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework
India’s cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat
Context-aware advisor recommendations in Red Hat Lightspeed
Building the levee: Why Red Hat’s post-quantum strategy is already in production
LinuxSecurity.com Major Update for Improved Threat Discovery and Research
How to guarantee a speaker gig: Hack the system. Literally
What do software developers do now?
Docker Sandboxes and microVMs, explained

Dnsmasq could be made to crash or run programs if it received specially crafted network traffic.

libssh2 could be made to crash if it received specially crafted network traffic.

Multiple vulnerabilities were discovered in SPIP, a website engine for publishing, which may result in remote code execution or an open redirect. For the stable distribution (trixie), these problems have been fixed in version 4.4.15+dfsg-0+deb13u1.

GitHub Actions Compromise CI/CD Supply Chain Risks Explored
VPN Strategies for Linux Developers Managing Mobile Security Risks

Several security issues were fixed in the Linux kernel.

SimpleEval could be made to run programs if it received specially crafted input.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in Rclone.

ngtcp2 could be made to run programs as your login if it received specially crafted network traffic when qlog was enabled.

An update that solves one vulnerability can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 23 vulnerabilities can now be installed.

An update that solves 6 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 13 vulnerabilities and has 13 bug fixes can now be installed.

An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.

An update that solves one vulnerability and has 4 bug fixes can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.

An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed.

An update that solves 20 vulnerabilities and has one bug fix can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.

MyPillow must decide whether to be firm or soft as ransomware crims demand pay
FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required
Misuse of Cron Jobs for Long-Term Access in Linux Environments
Inside the New LinuxSecurity.com: Smarter Linux Security Research and Threat Discovery
Experts pour cold borscht on Farage’s Russian hack claim
Why most AI agents disappoint in production (and what to fix first)
Taming the generative AI back end
The Big Three cloud providers are more alike than not

MGASA-2026-0156 – Updated nginx packages fix security vulnerabilities

MGASA-2026-0155 – Updated x11-server, x11-server-xwayland & tigervnc packages fix security vulnerabilities