Menu

Latest articles

Flaw in UK’s corporate registry let directors rummage through rival records
Open VSX extensions hijacked: GlassWorm malware spreads via dependency abuse
How to build an AI agent that actually works
Migrating from Apache Airflow v2 to v3
How AI is changing open source

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that exploits for both CVEs exist in the wild. For the oldstable distribution (bookworm), these problems have been fixed

Update to 146.0.7680.71 CVE-2026-3913: Heap buffer overflow in WebML CVE-2026-3914: Integer overflow in WebML CVE-2026-3915: Heap buffer overflow in WebML CVE-2026-3916: Out of bounds read in Web Speech

Update to pgadmin4-9.13.

Update to qgis-3.44.8.

https://security-tracker.debian.org/tracker/DSA-6165-1

Outsourcer Telus admits to attack – may have lost a petabyte of data to ShinyHunters

New upstream snapshot. Fixes CVEs 2025-11494, 2025-11495, 2026-2341, 2026-3441, 2026-3442. Fixes CVEs 2025-69644, 2025-69645, 2025-69646. Fixes FTBFS. Relax BR of itcl/itk/iwidgets.

Rebased pcs to the newest major version (see CHANGELOG.md) Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.2 (see CHANGELOG_WUI.md) Fixed FTBFS with Python 3.15 Fixed issues with installing pcs on Fedora 43+, upgrade and uninstall

Initial build after rename and update to 0.31.1

New version 4.6.4

Update to 1.89.0 Update to 1.88.0

0.9.31

Face value: What it takes to fool facial recognition

ESET’s Jake Moore used smart glasses, deepfakes and face swaps to ‘hack’ widely-used facial recognition systems – and he’ll demo it all at RSAC 2026

Latest upstream snapshot from stable-2.0 branch. Fixes CVE-2025-14369 in bundled dr_flac.

Update to 3.23.0 to fix CVE-2026-26965, CVE-2026-26955, CVE-2026-26271, CVE-2026-25997, CVE-2026-25959, CVE-2026-25955, CVE-2026-25954, CVE-2026-25953, CVE-2026-25952, CVE-2026-25942, CVE-2026-25941

Update to 146.0.7680.71 * CVE-2026-3913: Heap buffer overflow in WebML * CVE-2026-3914: Integer overflow in WebML * CVE-2026-3915: Heap buffer overflow in WebML * CVE-2026-3916: Out of bounds read in Web Speech

Latest snapshot from 3.0 branch. Fixes CVE-2025-14369.

Latest upstream snapshot from stable-2.0 branch. Fixes CVE-2025-14369 in bundled dr_flac.

MGASA-2026-0057 – Updated python-nltk packages fix security vulnerability

https://security-tracker.debian.org/tracker/DSA-6164-1

https://security-tracker.debian.org/tracker/DSA-6163-1

https://security-tracker.debian.org/tracker/DSA-6162-1

https://security-tracker.debian.org/tracker/DSA-6161-1

Credential-stealing crew spoofs VPN clients from Cisco, Fortinet, and others
Cyber fallout from the Iran war: What to have on your radar

The cybersecurity implications of the war in the Middle East extend far beyond the region. Here’s where to focus your defenses.

Save money by canceling more software projects, says survey
Microsoft accelerates pace of VS Code development

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. The Qualys Threat Research Unit (TRU) discovered several vulnerabilities in Apparmor. Details can be found in the Qualys advisory at

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. The Qualys Threat Research Unit (TRU) discovered several vulnerabilities in Apparmor. Details can be found in the Qualys advisory at

Interpol cybercrime crackdown leads to 94 arrests, 45,000 IP takedowns

An update that solves two vulnerabilities and has one security fix can now be installed.

NanoClaw latches onto Docker Sandboxes for safer AI agents
Intrusion Detection Systems vs Prevention Systems Snort Overview
Google rushes Chrome update fixing two zero-days already under attack
Databricks launches Genie Code to automate data science and engineering tasks
The AI coding hangover
Migrating Python to Rust with Claude: What could go wrong?

FreeType could be made to leak sensitive information.

Rebuilt with updated dr_wav to fix CVE-2026-29022

Update to new release, includes updated dependencies that fix for a number of CVEs

Rogue AI agents can work together to hack systems and steal secrets
Gemini CLI introduces plan mode

https://security-tracker.debian.org/tracker/DSA-6160-1

JetBrains unveils AI tracing library for Kotlin and Java
Why Postgres® has won as the de facto database: Today and for the agentic future
Operating Lightning takes down SocksEscort proxy network blamed for tens of millions in fraud
CISA warns max-severity n8n bug is being exploited in the wild

An update that solves three vulnerabilities and has one security fix can now be installed.

An update that solves three vulnerabilities and has one security fix can now be installed.

Your Signal account is safe – unless you fall for this trick
What’s missing from AI-assisted software development
Running agents in Amazon Bedrock AgentCore
Nvidia launches Nemotron 3 Super to power enterprise AI agents

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves 37 vulnerabilities can now be installed.

An update that solves 37 vulnerabilities can now be installed.

Databricks buys Quotient AI to boost enterprise‑grade AI agent performance
China’s CERT warns OpenClaw can inflict nasty wounds
Smashing Security podcast #458: How not to steal $46 million from the US government
Iran plots ‘infrastructure warfare’ against US tech giants
Microsoft’s .NET 11 Preview 2 offers cleaner stack traces

https://security-tracker.debian.org/tracker/DSA-6159-1

Iran-linked cyber crew says they hit US med-tech firm
Sednit reloaded: Back in the trenches

The resurgence of one of Russia’s most notorious APT groups

Meta, international cops use handcuffs and AI to stop scammers
ICO fines Police Scotland over data-sharing debacle in gross misconduct case
Oracle rejects request it give up control of MySQL
Swiss e-voting pilot can’t count 2,048 ballots after USB keys fail to decrypt them
Dutch cops bust teen suspected of posing as bank staff to steal cards
EU legal eagle says banks should refund cybercrime victims first, argue later

GeoPandas could be vulnerable to SQL injection attacks.

Drive business productivity through open collaboration, AI and document creation
Building the UK’s next generation of cyber talent
First look: Electrobun for TypeScript-powered desktop apps
An LLM that will help you build a nuclear weapon
Pity the developers who resist agentic coding

An update that solves seven vulnerabilities and has one security fix can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Amazon is linking site hiccups to AI efforts

0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS

0.011 – Update data pointer on resize for rdrand; Clean up string length handling 0.010 – Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS

Claude Code adds code reviews

https://security-tracker.debian.org/tracker/DSA-6158-1

TypeScript 6.0 reaches release candidate stage
Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack
Cybercrime isn’t just a cover for Iran’s government goons – it’s a key part of their operations
Crooks compromise WordPress sites to push infostealers via fake CAPTCHA prompts
Twitter suspended 800 million accounts last year – so why does manipulation remain so rampant?
JetBrains launches Air and Junie CLI for AI-assisted development
Fake job applications pack malware that kills EDR before stealing data

An update that solves two vulnerabilities and has one security fix can now be installed.