Menu

Latest articles

1 in 8 employees totally cool with selling work credentials
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games

Why Linux Supply Chain Attacks Are Becoming a Nightmare for DevOps Teams
Iran cybersnoops still LARPing as ransomware crooks in espionage ops
Linux Systems Running Wireshark May Be Exposed to Remote Attacks
UK age-gating plans risk breaking the internet, privacy groups warn

Important: golang security update

Important: grafana-pcp security update

Moderate: freeipmi security update

Important: grafana security update

Important: dovecot security update

Important: kernel security update

Your Linux Logs Probably Arent Catching Attacks: 2026 Detection Gaps
Building AI apps and agents with Microsoft Foundry
Designing front-end systems for cloud failure
No, AI won’t destroy software development jobs
India orders infosec red alert in case Mythos sparks crime spree

https://security-tracker.debian.org/tracker/DSA-6248-1

Supply-chain attacks take aim at your AI coding agents
Oracle will patch more often to counter AI cybersecurity threat
Attackers are cashing in on fresh ‘CopyFail’ Linux flaw
CVE-2026-31431: How Red Hat Advanced Cluster Security and Red Hat Advanced Cluster Management can help
Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking

An update that solves six vulnerabilities can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

ShinyHunters claims dump puts 119K Vimeo emails in the wild
AI finds 20-year-old bugs in PostgreSQL and MariaDB
Romance scammers turn sweet talk into £102M payday

Multiple vulnerabilities have been discovered in libarchive, a multi-format archive and compression C library, which also provides the following command-line tools: bsdcat, bsdcpio, bsdtar and bsdunzip. CVE-2026-4111 A flaw was identified in the RAR5 archive decompression logic of the

NHS to close-source hundreds of GitHub repos over AI, security concerns
Diskless databases: What happens when storage isn’t the bottleneck
Vibe coding or spec-driven development? How to choose
The agentic AI distraction
Microsoft’s bad obsession is showing up in shabby services and slipshod software. Here’s proof
SAP to acquire data lakehouse vendor Dremio
Singapore boffins get diverse SIEMs singing in harmony with agentic rule translation

https://security-tracker.debian.org/tracker/DSA-6247-1

Kids say they can beat age checks by drawing on a fake mustache
Control Panel Authentication Failures Expose Entire Linux Servers
Shadow IT has given way to shadow AI. Enter AI-BOMs

curl could be made to expose sensitive information over the network.

Several security issues were fixed in Exim.

sed could be made to overwrite files.

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.10.1esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.

Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

If the vote you rocked, your personal info can be grokked
Small language models: Rethinking enterprise AI architecture
Making AI work through eval hygiene
Five Eyes spook shops warn rapid rollouts of agentic AI are too risky

Important: libcap security update

Important: libcap security update

Important: sudo security update

Update to version 0.6.0. Addresses RUSTSEC-2026-0109.

Fix CVE-2026-6846.

This update provides various security fixes. Buffer overflow in scanf %mc (CVE-2026-5450) ns_sprintrrf buffer overreads (CVE-2026-6238) ns_sprintrrf buffer overflow in TSIG record processing (CVE-2026-5435) Memory corruption in ungetwc (CVE-2026-5928)

https://security-tracker.debian.org/tracker/DSA-6246-1

https://security-tracker.debian.org/tracker/DSA-6245-1

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For Debian 11 bullseye, these problems have been fixed in version 6.1.170-1~deb11u1.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For Debian 11 bullseye, these problems have been fixed in version 5.10.251-3.

Brace for the patch tsunami: AI is unearthing decades of buried code debt

This update provides various security fixes. Buffer overflow in scanf %mc (CVE-2026-5450) ns_sprintrrf buffer overreads (CVE-2026-6238) ns_sprintrrf buffer overflow in TSIG record processing (CVE-2026-5435) Memory corruption in ungetwc (CVE-2026-5928)

Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) Add upstream patches to build against openssl 4.0 Make configure.ac work with autoconf 2.73

Fixes security defects GHSA-rpm5-65cw-6hj4, GHSA-x2qx-6953-8485, GHSA-7545-fcxq-7j24, and GHSA-v87r-6q3f-2j67.

oxenstored keeps quota related use counts across domain destruction [XSA-483, CVE-2026-23556] Xenstored DoS via XS_RESET_WATCHES command [XSA-484, CVE-2026-23557] grant table v2 race in status page mapping [XSA-486, CVE-2026-23558] x86: Floating Point Divider State Sampling [XSA-488, CVE-2025-54505]

https://security-tracker.debian.org/tracker/DSA-6244-1

https://security-tracker.debian.org/tracker/DSA-6238-1

This month in security with Tony Anscombe – April 2026 edition

Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 – here’s some of what made the headlines this month

Enterprise Spotlight: Transforming software development with AI
Seccomp, AppArmor, SELinux: Where Linux Security Controls Fall Short
Ubuntu Copy Fail High Local Privilege Escalation Threat Advisory 2026-31431
First reports come in of victims of critical cPanel vuln as ‘millions’ of sites potentially exposed
Why Memory Safety Is Becoming a Core Requirement in Modern Software

Three security vulnerabilities were discovered in libexif, a library to reads and writes EXIF metainformation from and to images files, that can causes crashes or information leaks. CVE-2026-32775 If the exif_mnote_data_get_value function in MakerNotes gets passed

Important: vim security update

Important: yggdrasil security update

Important: yggdrasil-worker-package-manager security update

Important: xorg-x11-server-Xwayland security update

Important: libtiff security update

OpenAI locks GPT-5.5-Cyber behind velvet rope despite slamming Anthropic for doing exactly that
Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down
Passport to £££: Home Office adds £216M to travel doc contract before a single bid’s been placed
Running AI in the cloud is easy – and expensive
Are we ready to give AI agents the keys to the cloud? Cloudflare thinks so

https://security-tracker.debian.org/tracker/DSA-6243-1

https://security-tracker.debian.org/tracker/DSA-6242-1

https://security-tracker.debian.org/tracker/DSA-6240-1

https://security-tracker.debian.org/tracker/DSA-6197-3

https://security-tracker.debian.org/tracker/DSA-6239-1

The never-ending supply chain attacks worm into SAP npm packages, other dev tools
Bot her emails: most modern phishing campaigns are AI-enabled
FBI cyber boss: China’s hacker-for-hire ecosystem ‘out of control’
Google’s fix for critical Gemini CLI bug might break your CI/CD pipelines
French prosecutors link 15-year-old to mega-breach at state’s secure document agency
Redefining security data: Red Hat’s new VEX experience heading to Red Hat Summit 2026

Important: xorg-x11-server security update