Menu

Latest articles

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

https://security-tracker.debian.org/tracker/DSA-6174-1

https://security-tracker.debian.org/tracker/DSA-6171-1

Move fast and save things: A quick guide to recovering a hacked account

What you do – and how fast – after an account is compromised often matters more than it may seem

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex

Upstream announcements: WordPress 6.9.2 Release WordPress 6.9.3 and 7.0 beta 4 WordPress 6.9.4 Release

Update to 1.73.3; Fixes: RHBZ#2426392, RHBZ#2415186

Update to 0.37.1 (rbhz#2445943) Fixes Denial of Service via malformed Content-Length header (CVE-2026-31870 Reenables 32-bit build Update to 0.37.0 (rhbz#2441656)

Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)

https://security-tracker.debian.org/tracker/DSA-6172-1

Cryptographers engage in war of words over RustSec bug reports and subsequent ban

https://security-tracker.debian.org/tracker/DSA-6170-1

https://security-tracker.debian.org/tracker/DSA-6169-1

OpenAI’s desktop superapp: The end of ChatGPT as we know it?
Google’s Stitch UI design tool is now AI-powered
EDR killers explained: Beyond the drivers

ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers

Stop using AI to submit bug reports, says Google
Denver’s crosswalks hacked to broadcast anti-Trump messages
UK police force presses pause on live facial recognition after study finds racial bias
Feds disrupt monster IoT botnets behind record-breaking DDoS attacks
Jaguar Land Rover’s cyber bailout sets worrying precedent, watchdog warns

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Introducing OpenShift Service Mesh 3.3 with post-quantum cryptography
LeakNet ransomware: what you need to know
Starmer’s digital ID reboot raises same old questions as its Blair-era ancestor
AI optimization: How we cut energy costs in social media recommendation systems
Cloud at 20: Cost, complexity, and control
Google adds vibe design to Stitch UI design tool
While you’re here, could you go out of your way to do an impossible job?

This is the March 2026 release of .NET 10. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.4/10.0.104.md Runtime: https://github.com/dotnet/core/blob/main/release-

CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex

Fix CVE-2026-31812: Bump quinn-proto to 0.11.14 – Closes rhbz#2446359

Update to 146.0.7680.80 * CVE-2026-3909: Out of bounds write in Ski

OpenAI buys Python tools builder Astral
OpenAI buys non-AI coding startup to help its AI to program

https://security-tracker.debian.org/tracker/DSA-6168-1

Unknown attackers exploit yet another critical SharePoint bug
Google gives Android users a way to install unverified apps if they prove they really, really want to
Lock down Microsoft Intune, feds warn after Stryker attack

An update that solves one vulnerability can now be installed.

Several security issues were fixed in python2.7

9 reasons Java is still great
How to create AI agents with Neo4j Aura Agent
Why AI evals are the new necessity for building effective AI agents

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

OpenAI’s $50B AWS deal puts its Microsoft alliance to the test
Smashing Security podcast #459: This clever scam nearly hijacked a tech CEO’s Apple ID

https://security-tracker.debian.org/tracker/DSA-6167-1

https://security-tracker.debian.org/tracker/DSA-6166-1

Java future calls for boosts with records, primitives, classes
Edge.js launched to run Node.js for AI
Okta made a nightmare micromanager for your AI agents
State snoops and spyware vendors planting info-stealing malware on iPhones, Google warns
Amazon security boss says crims abused max-security Cisco firewall flaw weeks before disclosure
n8n 1.122.0 Critical RCE Auth Bypass Exploit CVE-2025-68613
North Korea’s 100,000-strong fake IT worker army rake in $500M a year for Kim Jong Un
Snowflake’s new ‘autonomous’ AI layer aims to do the work, not just answer questions
Britain’s satellite-watching gap to be plugged with £17.5M eyeball in Cyprus

Important: libpng security update

Flask could be made to expose sensitive information over the network.

USN-8102-1 introduced a regression in snapd

I ran Qwen3.5 locally instead of Claude Code. Here’s what happened.
We mistook event handling for architecture
Markdown is now a first-class coding language: Deal with it

# Security update for container-suseconnect Announcement ID: SUSE-SU-2026:0909-1 Release Date: 2026-03-17T17:34:35Z Rating: important References:

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

USAT Leverages Times Square Crowd to Demonstrate Instant Digital Dollar Payments
Iran’s cyberattack against med tech firm is ‘just the beginning’
Linux Foundation kicks off effort to shield FOSS maintainers from AI slop bug reports
Japan to allow ‘proactive cyber-defense’ from October 1st
WorldCoin‘s newest pitch: Scan your eyeballs to prove AI agents really represent you
Project Detroit, bridging Java, Python, JavaScript, moves forward
EU sanctions Iranian cyber front over election meddling, Charlie Hebdo breach
Fraudsters are using public planning records to target permit applicants

Important: libvpx security update

Several security issues were fixed in the Linux kernel.

Too big to ignore, too small to be served: the midmarket security gap
Switzerland built a secure alternative to BGP. The rest of the world hasn’t noticed yet

Important: container-tools:rhel8 security update

Important: container-tools:rhel8 security update

Gartner suggests Friday afternoon Copilot ban because tired users may be too lazy to check its mistakes

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Bank built its own threat hunting agent because vendors can’t keep pace with new threats

Update to openexr-3.4.6 resp 3.3.8.

Robotics surgical biz Intuitive discloses phishing attack
Cybercrime has skyrocketed 245% since the start of the Iran war
Free parking in Russia after Distributed Denial-of-Service attack knocks city’s parking system offline
AI finally delivers those elusive productivity gains… for cybercriminals
Startups accuse Microsoft of ‘billing trap’ in Azure AI Foundry after unexpected charges
Linux Kernel eBPF Monitoring Rootkit Threats and Evasion Techniques
Flaw in UK’s corporate registry let directors rummage through rival records
Open VSX extensions hijacked: GlassWorm malware spreads via dependency abuse