Menu

Latest articles

A simple CodeBuild flaw put every AWS environment at risk – and pwned ‘the central nervous system of the cloud’
Smashing Security podcast #450: From Instagram panic to Grok gone wild
US regulator tells GM to hit the brakes on customer tracking
Woman bailed as cops probe doctor’s surgery data breach
Improving VirtOps: Manage, migrate or modernize with Red Hat and Cisco
Manage clusters and applications at scale with Argo CD Agent on Red Hat OpenShift GitOps
Microsoft taps UK courts to dismantle cybercrime host RedVDS
Ofcom keeps X under the microscope despite Grok ‘nudify’ fix
When your platform team can’t say yes: How away-teaming unlocks stuck roadmaps
AWS flips switch on Euro cloud as customers fret about digital sovereignty
What is GitOps? Extending devops to Kubernetes and beyond
For agentic AI, other disciplines need their own Git
Getting started with GitHub Copilot in Visual Studio or VS Code

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

From typos to takeovers: Inside the industrialization of npm supply chain attacks
Compose Multiplatform brings auto-resizing to interop views
New Linux malware targets the cloud, steals creds, and then vanishes
Output from vibe coding tools prone to critical security flaws, study finds
Your personal information is on the dark web. What happens next?

If your data is on the dark web, it’s probably only a matter of time before it’s abused for fraud or account hijacking. Here’s what to do.

France fines telcos €42M for sub-par security prior to 24M customer breach
Chinese AI firm trains state-of-the-art model entirely on Huawei chips
‘Imagination the limit’: DeadLock ransomware gang using smart contracts to hide their work
Cyber-stricken Belgian hospitals refuse ambulances, transfer critical patients
Eurail passengers taken for a ride as data breach spills passports, bank details
UK backtracks on digital ID requirement for right to work
Spanish power giant sparks breach probe amid claims of massive data grab
Rust slow to compile? Here’s how to speed it up
When writing code is no longer the bottleneck
Anthropic expands Claude Code beyond developer tasks with Cowork

Viral Vaghela discovered an SQL injection vulnerability in Parsl, a parallel scripting library for Python. For the stable distribution (trixie), this problem has been fixed in version 2025.01.13+ds-1+deb13u1. We recommend that you upgrade your python-parsl packages.

Anthropic finds $1.5 million to help Python Foundation improve security

Version 2.9.3 – 2025-12-30 Security: Fixed ANSI sequence injection (GHSA-59pp-r3rg-353g / CVE-2025-67746) Fixed COMPOSER_NO_SECURITY_BLOCKING env var not being respected for updates done via the install command, and added –no-security-blocking flag to install as well (#12677)

New upstream release (147.0)

Update to 2.69.0

Update to Upstream version 0.1.2 – https://github.com/complytime/complyctl/releases/tag/v0.1.2

Version 2.9.3 – 2025-12-30 Security: Fixed ANSI sequence injection (GHSA-59pp-r3rg-353g / CVE-2025-67746) Fixed COMPOSER_NO_SECURITY_BLOCKING env var not being respected for updates done via the install command, and added –no-security-blocking flag to install as well (#12677)

Windows info-disclosure 0-day bug gets a fix as CISA sounds alarm

https://security-tracker.debian.org/tracker/DSA-6099-1

https://security-tracker.debian.org/tracker/DSA-6098-1

Java 27 gets its first feature
Popular Python libraries used in Hugging Face models subject to poisoned metadata attack
AI and automation could erase 10.4 million US roles by 2030
Dutch cops cuff alleged AVCheck malware kingpin in Amsterdam
Federal agencies told to fix or ditch Gogs as exploited zero-day lands on CISA hit list
Google’s Universal Commerce Protocol aims to simplify life for shopping bots… and devs
Mandiant open sources tool to prevent leaky Salesforce misconfigs

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability can now be installed.

Court tosses appeal by hacker who opened port to coke smugglers with malware

Google Guest Agent could be made to crash if it received specially crafted network traffic.

Britain goes shopping for a rapid-fire missile to help Ukraine hit back
From distributed monolith to composable architecture on AWS: A modern approach to scalable software
Hackers get hacked, as BreachForums database is leaked
Which development platforms and tools should you learn now?
Why hybrid cloud is the future of enterprise platforms
Oracle unveils Java development plans for 2026
India demands crypto outfits geolocate customers, get a selfie to prove they’re real
No fire sale for firewalls as memory shortages could push prices higher
‘Violence-as-a-service’ suspect arrested in Iraq, extradition underway
AI is causing developers to abandon Stack Overflow
Stack thinking: Why a single AI platform won’t cut it
Businesses in 2026: Maybe we should finally look into that AI security stuff
Block CISO: We red-teamed our own AI agent to run an infostealer on an employee laptop
Postman snaps up Fern to reduce developer friction around API documentation and SDKs
Infamous BreachForums forum breached, spilling data on 325K users
Ofcom officially investigating X as Grok’s nudify button stays switched on
Tories vow to boot under-16s off social media and ban phones in schools

Several security issues were fixed in PHP.

How to succeed with AI-powered, low-code and no-code development tools
Why ‘boring’ VS Code keeps winning

Several security issues were fixed in libheif.

India’s government denies it plans to demand smartphone source code
Malaysia and Indonesia block X over failure to curb deepfake smut

Update to 143.0.7499.192 * High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1

This update adds a patch to fix CVE-2025-56225, a flaw in the bundled version of fluidsynth.

Meta admits to Instagram password reset mess, denies data leak
What Is a WAF? A Linux Security Admins Practical Guide

MGASA-2026-0006 – Updated zlib packages fix security vulnerability

MGAA-2026-0004 – Updated nvidia470 packages fix bug

Update to 143.0.7499.192 * High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1

Backport fix for CVE-2025-22921

Version 1.0.21 This point release includes all the changes from 1.0.20-stable, which include a security fix for the crypto_core_ed25519_is_valid_point() function, as well as two new sets of functions: The new crypto_ipcrypt_* functions implement mechanisms for securely

Backport fix for CVE-2025-64512 / GHSA-wf5f-4jwr-ppcp

https://security-tracker.debian.org/tracker/DSA-6097-1

UK government exempting itself from flagship cyber law inspires little confidence

MGASA-2026-0005 – Updated libpcap packages fix security vulnerability

MGASA-2026-0004 – Updated sodium packages fix security vulnerability

MGASA-2026-0003 – Updated curl packages fix security vulnerabilities

MGASA-2026-0002 – Updated wget2 packages fix security vulnerability

A security issue was discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), this problem has been fixed in version 143.0.7499.192-1~deb12u1.

MariaDB 10.11.15 Release notes: server/10.11/10.11.15

Visual Studio Code adds support for agent skills