Menu

Latest articles

https://security-tracker.debian.org/tracker/DSA-6194-1

https://security-tracker.debian.org/tracker/DSA-6193-1

https://security-tracker.debian.org/tracker/DSA-6191-1

https://security-tracker.debian.org/tracker/DSA-6190-1

An update that solves two vulnerabilities can now be installed.

They thought they were downloading Claude Code source. They got a nasty dose of malware instead
Digital assets after death: Managing risks to your loved one’s digital estate

Fraudsters often target the accounts of the deceased or their grieving relatives. Here’s how to keep the scammers at bay.

Moderate: mariadb:10.11 security update

Kilo targets shadow AI agents with a managed enterprise platform
Why ‘curate first, annotate smarter’ is reshaping computer vision development
Spring AI tutorial: How to develop AI agents with Spring
Building enterprise voice AI agents: A UX approach

Undertow would allow unintended access to user sessions over the network.

The company’s biggest security hole lived in the breakroom

CVE-2026-4897 aisle.com fix of unsanitized getline

Security fix for CVE-2026-4519

Automatic update for crun-1.27-1.fc43. Changelog for crun * Wed Mar 25 2026 Packit – 1.27-1 – Update to 1.27 upstream release * Mon Dec 22 2025 Packit – 1.26-1

Fix CVE-2026-31812: Bump tar-rs to .5.45 – Closes rhbz#2449672

AI recruiting biz Mercor says it was ‘one of thousands’ hit in LiteLLM supply-chain attack
Smashing Security podcast #461: This man hid $400 million in a fishing rod. Then it vanished

https://security-tracker.debian.org/tracker/DSA-6189-1

https://security-tracker.debian.org/tracker/DSA-6188-1

Amazon security boss: AI makes pentesting 40% more efficient
Vim and GNU Emacs: Claude Code helpfully found zero-day exploits for both
This month in security with Tony Anscombe – March 2026 edition

The past four weeks have seen a slew of new cybersecurity wake-up calls that showed why every organization needs a well-thought-out cyber-resilience plan

‘People’s Panel’ to check if UK wants controversial Digital ID will cost £630K

Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2026-31958 Introduce new limits on the size and complexity of multipart bodies, including a default limit of 100 parts per request to mitigate a

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

Meta shows structured prompts can make LLMs more reliable for code review
Alleged RedLine malware developer extradited to United States
PEP 816: How Python is getting serious about Wasm
What next for junior developers?
UK manufacturers under cyber fire with 80% reporting attacks
Don’t open that WhatsApp message, Microsoft warns
Iran targets M365 accounts with password-spraying attacks
CI/CD Pipelines Vulnerabilities in Trusted Execution Paths March 2026
Announcing Red Hat Advanced Cluster Security for Kubernetes 4.10

Several security issues were fixed in Pillow.

Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines
A GitHub tinkerer teaches Claude to talk less, and that may matter more than it seems
How Apache Kafka flexed to support queues
What front-end engineers need to know about AWS
Enterprises demand cloud value
Azure’s new AI modernization tools

An update that solves 25 vulnerabilities can now be installed.

An update that solves 25 vulnerabilities can now be installed.

Several security issues were fixed in pyasn1.

Several security issues were fixed in ImageMagick.

Iranian hackers breach FBI director’s personal email, and post his CV and photos online

MGAA-2026-0024 – Updated zynaddsubfx packages fix bug

OpenAI patches ChatGPT flaw that smuggled data over DNS
Telnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach
Citrix NetScaler bug exploited in days, may be multiple flaws in a trench coat

Multiple vulnerabilities were discovered in asterisk, an Open Source Private Branch Exchange (PBX) and telephony toolkit. CVE-2026-23738 XSS vulnerability in the /httpstatus page. Cookie names/values and GET parameter names/values are rendered without HTML-escaping, allowing

An update that solves 655 vulnerabilities, contains four features and has 57 fixes can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves seven vulnerabilities can now be installed.

Leak reveals Anthropic’s ‘Mythos,’ a powerful AI model aimed at cybersecurity use cases
European Commission admits attackers broke into public web systems, but says little else
How to build an enterprise-grade MCP registry
The starkly uneven reality of enterprise AI adoption
Security contractor blew the whistle on support crew’s viral indifference
US foreign router ban criticized for being ‘industrial policy disguised as cybersecurity’

https://security-tracker.debian.org/tracker/DSA-6187-1

https://security-tracker.debian.org/tracker/DSA-6186-1

https://security-tracker.debian.org/tracker/DSA-6185-1

https://security-tracker.debian.org/tracker/DSA-6184-1

https://security-tracker.debian.org/tracker/DSA-6183-1

MGASA-2026-0073 – Updated python-ujson packages fix security vulnerabilities

MGASA-2026-0072 – Updated strongswan packages fix security vulnerability

Security fix for CVE-2026-4519.

Security fix for CVE-2026-4519.

Rebuilt with rust-tar 0.4.45 for CVE-2026-33056

Rebuilt with rust-tar 0.4.45 for CVE-2026-33056

https://security-tracker.debian.org/tracker/DSA-6181-1

RSAC 2026 wrap-up – Week in security with Tony Anscombe

This year, AI agents took the center stage – as a defensive capability, but more pressingly as a risk many organizations haven’t caught up with

A cunning predator: How Silver Fox preys on Japanese firms this tax season

Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them

AI security: Identity and access control

MGASA-2026-0071 – Updated nodejs packages fix security vulnerabilities

MGASA-2026-0070 – Updated libpng packages fix security vulnerabilities

Update to 146.0.7680.164 * High CVE-2026-4673: Heap buffer overflow in WebAudio * High CVE-2026-4674: Out of bounds read in CSS * High CVE-2026-4675: Heap buffer overflow in WebGL * High CVE-2026-4676: Use after free in Dawn

Update to v2.0.52

Update to 1.23.1

Update to 1.23.1

https://security-tracker.debian.org/tracker/DSA-6182-1

Kotlin 2.3.20 harmonizes with C, JavaScript/Typescript

https://security-tracker.debian.org/tracker/DSA-6180-1

https://security-tracker.debian.org/tracker/DSA-6179-1

Final training of AI models is a fraction of their total cost

An update that solves seven vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.