Menu

Latest articles

Fedora 45 python-django5 Critical Server-side Attack Fix CVE-2026-15307
Fedora 45 GNATCOLL Important Patch for Core Vulnerabilities 2026-c8b1bb0c97
Fedora 45 addresses Denial of Service flaw in nodejs-undici CVE-2026-18149
Fedora 45 sblim-cmpi-base Important Local Temp File Issue CVE-2026-73585
Ubuntu 26.04 Bubblewrap Low Regression Issue USN-8779-2
AI coding agents’ 0-click RCE flaw could hand attackers keys to the kingdom
A zero-click vulnerability that allows remote code execution affects all of the major AI coding agents – Anthropic’s Claude Code, OpenAI’s Codex, [...]
Linux Security Researcher Uses AI to Find Four Python Code-Execution Flaws
Security researcher Sai Teja Erukude disclosed four alarming Python security flaws between June and August 2026 after combining specialized AI models with [...]
CISA Warns of Active Attacks on a Critical Cisco ISE Flaw
Attackers are exploiting a critical Cisco ISE flaw that can open the product’s web management interface without a valid login. Cisco disclosed [...]
Ubuntu 26.04 Bubblewrap Notable Denial of Service Vulnerability USN-8779-1
How a PowerPC Guest Could Trigger a KVM Use-After-Free
A PowerPC KVM use-after-free could leave the Linux host kernel accessing a nested-guest object after another virtual CPU caused that object to be removed [...]
SUSE cjose Important Buffer Overflow Vulnerability Patch 2026-4237-1
openSUSE gvfs Addresses Significant Memory Leak and Buffer Overflow Bugs
SUSE gvfs Important OOB Memory Access Issues Vuln 2026-4238-1
SUSE libpcap Essential Out-Of-Band Access Update 2026-4239-1
openSUSE gvfs Important Out Of Bounds Issues Vuln 2026-4240-1
Important Security Update for SUSE 2026-4240-1 gvfs Released
openSUSE pcre2 Important Out-of-Bounds Issues Advisory 2026-4241-1
SUSE pcre2 Important Patch for Six Vulnerabilities 2026-4241-1
SUSE OpenVPN Important Remote DoS Patch CVE-2026-84732 2026-4242-1
openSUSE Kernel Important Live Patch for Multiple Issues 2026-4231-1
Debian LTS xz-utils Security Update DLA-4783-1 Fixes Memory Corruption
SUSE Linux Enterprise 15 SP6 Kernel Important Threats Patch 2026-4231-1
DSA-6503-1 thunderbird – security update
DSA-6502-1 mkvtoolnix – security update
DSA-6501-1 firefox-esr – security update
DSA-6500-1 tor – security update
Debian Chromium Critical Code Execution Denial of Service DSA-6506-1
Red Hat Quay Build Workflow Could Expose Registry Credentials
As of September 17, Red Hat had documented a flaw in a Red Hat Quay build workflow that could expose container registry credentials to code retrieved from [...]
Researchers find way to listen in on headphones from afar
Researchers based in China have devised a way to eavesdrop on signals handled by analog components in devices such as headphones, landline handsets, and [...]
Debian DSA-6505-1 BIND Critical Denial of Service and Cache Poisoning Fix
Debian libapache2-mod-auth-openidc Key Denial of Service Patch DSA-6504-1
China’s Salt Typhoon backdoors Latin American orgs with new snooping malware
China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across [...]
Cyberthreats are moving faster than SMBs: Readiness must accelerate
As AI adoption expands the attack surface and adds to the security workload, businesses need automation backed by experts
TypeSafe AI’s new models work with machines, not humans
Today’s large language models are verbose, even if they’re being asked to recommend a simple decision, driving up usage costs through the sheer volume of [...]
Rocky Linux 8 RLSA-2026-67908 libevent Important Denial of Service Issues
Rocky Linux libsoup Moderate WebSocket DoS RLSA-2026-68266
London property manager breach may have exposed bank details and lockbox codes
London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys [...]
US Coast Guard and FBI board oil tanker to investigate cyber attack
Self-modifying AI agents expose a blind spot in enterprise security
As debate over AI safety intensifies, new research is drawing attention to a more immediate risk for enterprises: AI agents that can alter the models they [...]
Cisco drops another exploited zero-day, this time a perfect 10
Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed [...]
Test environment let anyone access live customer data
Welcome back to PWNED, the weekly column where we learn important life lessons about how we let cybercrims access our data through carelessness. Hopefully, [...]
Container Security Failure Could Let a Malicious Image Reach the Linux Host
Container security can fail before a workload fully enters its root filesystem, the private file tree the container is meant to see.
Linux SMB Security Fixes Restore Ownership and Input-Trust Boundaries
SMB, or Server Message Block, lets Linux systems access files shared over a network.
How Transparent Huge Pages Could Lose Rewritten Data During Reclaim
Transparent huge pages let Linux manage memory in larger blocks for better performance.
Why eBPF Security Depends on Matching Metadata Lifetimes
eBPF lets verified programs run inside the Linux kernel. Linux eBPF security depends on supporting data remaining available for as long as those programs [...]
Effective Encryption Strategies to Safeguard Your Online Identity
In today’s world, almost every part of our lives is directly or indirectly linked to the Internet. As cyberattacks in network security grow more advanced, [...]
Ofcom discovers issuing Online Safety Act fines is easier than collecting them
Ofcom chiefs have acknowledged that most fines issued under the Online Safety Act (OSA) remain unpaid, highlighting limitations in the comms [...]
Stop tuning your models and fix your data
Walk into any boardroom or technology conference today, and the conversation is entirely consumed by the promise of agentic AI. We are told that autonomous [...]
MSBuild explained: Understanding Microsoft’s build platform
Visual Studio is a lot more than an editor and debugger; it’s the host for Microsoft’s cross-platform build tools. MSBuild is one of those forgotten [...]
Your AI testing dashboards are green. That’s the problem
The green dashboard is one of the most comforting objects in software engineering. It says the build passed, the tests passed, the service is healthy and [...]
How Linux File Permissions Become a Root Trust Boundary
Linux file permissions are usually introduced as a way to decide who may read, write, or execute a file. On a production server, they do something more [...]
Fedora 43 open62541 Security Advisory on Critical Denial of Service Issues
Fedora 43 php-pecl-mongodb2 Important Out-of-Bounds Read Fix CVE-2026-84968
Fedora 43 Roundcube 1.6.19 Security Updates Address XSS Email Issues
Fedora 44 python-django6 Important Updates for XSS and DoS Vulnerabilities
Fedora 44 open62541 Key Fixes for Denial of Service and Code Execution
Fedora 44 php-pecl-mongodb2 Important Out-Of-Bounds Read CVE-2026-84968
Fedora 44 Roundcube 1.7.4 Security Fix XSS Email Header CVE-2026-38c637be37
Fedora 44 python-jwcrypto Minor Risk Security Updates 2026-8caad572b0
Fedora 45 Python Django 6 Key Denial of Service XSS Patch 2026-522a9411e7
Fedora 45 open62541 Critical Code Execution Denial of Service Patch 2026
Fedora 45 Roundcube 1.7.4 Security Update for XSS and Injection Issues
Fedora 45 Python JWCrypto Low Severity Security Fix 2026-6d094c5360
Docker Sandboxes Flaw Lets a Guest Reach Host Unix Sockets
Docker has fixed a high-severity Docker Sandboxes vulnerability that allowed a malicious guest to redirect a host-side relay toward Unix sockets outside [...]
Acronis Backup Flaw Is Being Exploited on Linux Hosting Servers
Acronis has fixed a high-severity vulnerability in its Linux hosting backup integrations after detecting exploitation in limited, targeted attacks. The [...]
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Slackware mozilla-thunderbird Critical Security Update 2026-259-02
Slackware 15.0 Mozilla-Firefox Medium Security Fix 2026-259-01
AI agents can modify themselves without humans telling them to do so
The list of dodgy things AI agents can and will do on their own – like stealing people’s credentials, escaping onto the open internet, communicating [...]
Rocky Linux 10 and .NET 9.0 Advisory for CVE-2026-58649 CVE-2026-69806
Rocky Linux 10 NET 8.0 Moderate Info Leak CVE-2026-58649 RLSA-2026-67525
Rocky Linux 10 RLSA-2026-67584 Rsyslog Moderate Remote Crash
Rocky Linux 10 RLSA-2026-67530 .NET 10.0 Important Elevation of Privilege
Rocky Linux .NET 9.0 Important Security Update RLSA-2026-67614
Rocky Linux PostgreSQL Important Security Fix RLSA-2026-67848
Rocky Linux 9 RLSA-2026-54184 grafana Important Denial of Service
Rocky Linux RLSA-2026-67608 leapp-repository Important Security Update
Rocky Linux 9 Kernel Important Security Advisories RLSA-2026-67470
Rocky Linux 9 RLSA-2026-67524 .NET 8.0 Moderate Information Disclosure
Rocky Linux RLSA-2026-67583 Rsyslog Low Configuration Crash Advisory
Rocky Linux 9 .NET 10.0 Important Security Update RLSA-2026-67613
Rocky Linux Grafana Important Privilege Escalation DoS RLSA-2026-54243
Ubuntu 26.04 libheif Important Denial of Service USN-8774-1
Ubuntu python-cryptography Important Cipher Timing DoS Threats USN-8776-1
Debian ThunderBird Important Arbitrary Code Exec Vulnerabilities DSA-6503-1
SUSE gvfs Important OOB Memory Access Vulnern 2026-4200-1
SUSE 12 SP5 pcre2 Important Security Issue Resolution 2026-4201-1
SUSE Corosync Important Buffer Overflow Integer Overflow Vuln 2026-4202-1
SUSE Tomcat Important DoS Authentication Issues Fix 2026-4203-1
SUSE glibc Moderate DoS Buffer Overflow Vuln 2026-4204-1
SUSE lcms2 Low Information Disclosure Threat Advisory 2026-4205-1
SUSE google-cloud-sap-agent Important Denial of Service Vuln 2026-4206-1
SUSE Important kbd Local Privilege Escalation Vulnern 2026-4207-1
SUSE ClamAV Important Security Update Advisory 2026-4208-1
SUSE Containerized-Data-Importer Important Security Update 2026-4209-1
SUSE Alloy Important Security Update for Seven Issues 2026-4210-1
SUSE 15 SP7 kbd Important Local Privilege Escalation Fix CVE-2026-72693
SUSE Important Security Update 2026-4212-1 Fixes 21 Issues
SUSE OpenVPN Important Remote Access Denial of Service Vulnern 2026-4213-1
SUSE 16.0 Helm Important DoS Credential Exfiltration Vulnern 2026-23688-1