Menu

Latest articles

An update that solves one vulnerability can now be installed.

AFC Ajax drops ball as flaws let hackers play admin with tickets and bans
OpenAI adds plugin system to Codex to help enterprises govern AI coding agents
Anthropic throttles Claude subscriptions to meet capacity
Iran war drives urgent need to counter underwater attack drones
On the pleasures and dangers of open source Python
Edge clouds and local data centers reshape IT
Security boffins scoured the web and found hundreds of valid API keys
Context Hub vulnerable to supply chain attacks, says tester
Visual Studio Code previews chat customizations editor

https://security-tracker.debian.org/tracker/DSA-6178-1

World Leaks data extortion: What you need to know
Virtual machines, virtually everywhere – and with real security gaps

Cloud VMs offer unmatched speed, scale and flexibility – all of which could eventually count for little if they’re left to fend for themselves

Databricks pitches Lakewatch as a cheaper SIEM — but is it really?
Brit lawmaker targeted by AI deepfake fails to get answers from US Big Tech
What does “AI security” mean and why does it matter to your business?
Smashing Security podcast #460: Never knock on the door of a nuclear submarine base and ask for a selfie
Google targets AI inference bottlenecks with TurboQuant
UK wants to know if banning under-16s from social media does anything useful
Basic and advanced Java serialization
Rethinking VM data protection in cloud-native environments
Swift 6.3 boosts C interoperability, Android SDK

An update that solves two vulnerabilities and has one security fix can now be installed.

An update that solves nine vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

Indian government probes CCTV espionage operation linked to Pakistan

Update to 146.0.7680.164 * High CVE-2026-4673: Heap buffer overflow in WebAudio * High CVE-2026-4674: Out of bounds read in CSS * High CVE-2026-4675: Heap buffer overflow in WebGL * High CVE-2026-4676: Use after free in Dawn

Claude Code AI tool getting auto mode
AI supply chain attacks don’t even require malware…just post poisoned documentation
Scammers have virtual smartphones on speed dial for fraud
Jen Easterly, cybersecurity’s ‘relentless optimist,’ hopes feds come back to RSAC next year
Only Trump can decide when cyberwar turns into real war
Cloud workload security: Mind the gaps

As IT infrastructure expands, visibility and control often lag behind – until an incident forces a reckoning

PyPI warns developers after LiteLLM malware found stealing cloud and CI/CD credentials
Cloudflare launches Dynamic Workers for AI agent execution
How one man used 10,000 bots to steal $8,000,000 from music artists
Oracle adds pre-built agents to Private Agent Factory in AI Database 26ai
Speed boost your Python programs with new lazy imports
Stop worrying: Instead, imagine software developers’ next great pivot
TypeScript 6.0 arrives

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 146.0.7680.164-1~deb12u1.

Enterprise PCs are unreliable, unpatched, and unloved compared to Macs

Update to release v1.9.1

Update to 146.0.7680.153 * CVE-2026-4439: Out of bounds memory access in WebGL * CVE-2026-4440: Out of bounds read and write in WebGL * CVE-2026-4441: Use after free in Base * CVE-2026-4442: Heap buffer overflow in CSS

Update to version 1.3.1 to fix CVE-2026-28356.

Update to release v1.9.1 Resolves: rhbz#2448053, rhbz#2423997, rhbz#2424031 Upstream fixes

Update to 146.0.7680.153 * CVE-2026-4439: Out of bounds memory access in WebGL * CVE-2026-4440: Out of bounds read and write in WebGL * CVE-2026-4441: Use after free in Base * CVE-2026-4442: Heap buffer overflow in CSS

https://security-tracker.debian.org/tracker/DSA-6177-1

New JetBrains platform manages AI coding agents
EFF has a new boss to lead the fight against privacy-sucking forces of doom
1K+ cloud environments infected following Trivy supply chain attack
LiteLLM loses game of Trivy pursuit, gets compromised
HackerOne slams supplier for delayed breach notice after staff data exposed

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that solves 11 vulnerabilities and has two security fixes can now be installed.

An update that solves 11 vulnerabilities and has two security fixes can now be installed.

An update that solves one vulnerability and has two security fixes can now be installed.

An update that solves one vulnerability and has two security fixes can now be installed.

Country that put backdoors into Cisco routers to spy on world bans foreign routers
New ‘StoatWaffle’ malware auto‑executes attacks on developers
Russian initial access broker who fed ransomware crews gets 81 months in US prison
An architecture for engineering AI context
7 safeguards for observable AI agents
Designing self-healing microservices with recovery-aware redrive frameworks
When Windows 11 sneezes, Azure catches cold
VS Code now updates weekly
Claude attacks were ‘Rorschach test’ for infosec community, scaring former NSA boss
Public-private partnerships vital in disrupting China’s Typhoons, says RSA panel with no government speakers
Lightning-fast exploits make it essential to patch fast, ask questions later

https://security-tracker.debian.org/tracker/DSA-6175-1

Google unleashes Gemini AI agents on the dark web
Smooth criminals talking their way into cloud environments, Google says
US chip testing firm shrugged off ransomware hit as minor – then came the data leak
RSAC 2026: Uncle Sam backs out, and AI agents are everywhere
Microsoft fixes broken Windows update days after vowing fewer broken updates

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The drone swarm is coming, and NATO air defenses are too expensive to cope
How to land a software development job in an AI-focused world
The agent security mess

Net-CIDR could allow unintended access to network services.

Debian Goodies could be made to crash or run programs as your login if it opened a specially crafted file.

# Security update for helm Announcement ID: SUSE-SU-2026:0948-1 Release Date: 2026-03-20T18:07:28Z Rating: important References:

https://security-tracker.debian.org/tracker/DSA-6176-1

Russians are posing as Signal support to launch phishing attacks

https://security-tracker.debian.org/tracker/DSA-6173-1

Jul Blobul discovered that SPIP, a website engine for publishing, is prone to a privilege escalation vulnerability. For the stable distribution (trixie), this problem has been fixed in version 4.4.13+dfsg-0+deb13u1. We recommend that you upgrade your spip packages.

Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

https://security-tracker.debian.org/tracker/DSA-6174-1

https://security-tracker.debian.org/tracker/DSA-6171-1

Move fast and save things: A quick guide to recovering a hacked account

What you do – and how fast – after an account is compromised often matters more than it may seem

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.