Menu

Latest articles

BIND a popular name server (DNS) was affected by a vulnerability. If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers

NHS pays £46K to prep next Microsoft licensing round
Hands-on with the Google Agent Development Kit
Are AI certifications worth the investment?
AI has to be dull before it can be sexy

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

China wants AI to prepare school lessons and mark homework
Anthropic’s mysterious Mythos AI threatens to upend the infosec world

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure or incomplete permission checks. For the oldstable distribution (bookworm), these problems have been fixed in version 1:1.39.17-1+deb12u2.

Multiple security vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps, which could allow a Flatpak app to delete arbitrary hosts on the host or break out of the sandbox resulting in code execution in the host context. For the stable distribution (trixie), these problems have been fixed in

MGASA-2026-0096 – Updated libpng12 packages fix security vulnerability

MGASA-2026-0095 – Updated tomcat packages fix security vulnerabilities

MGASA-2026-0094 – Updated squid packages fix security vulnerabilities

Moderate: kernel security update

https://security-tracker.debian.org/tracker/DSA-6208-1

https://security-tracker.debian.org/tracker/DSA-6207-1

Recovery scammers hit you when you’re down: Here’s how to avoid a second strike

If you’ve been the victim of fraud, you’re likely already a lead on a ‘sucker list’ – and if you’re not careful, your ordeal may be about to get worse.

Navigating the Mythos-haunted world of platform security
MCP security: Logging and runtime security measures

Important: kea security update

Two different attackers poisoned popular open source tools – and showed us the future of supply chain compromise

Several vulnerabilities were discovered in the inetutils implementation of telnetd and telnet, which may result in privilege escalation or information disclosure. CVE-2026-28372 Ron Ben Yizhak from SafeBreach found that the fix for CVE-2026-24061 was

Hungarian government creds left in the safe hands of ‘FrankLampard’

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 140.9.1esr-1~deb11u1.

https://security-tracker.debian.org/tracker/DSA-6206-1

Swift for Visual Studio Code comes to Open VSX Registry

https://security-tracker.debian.org/tracker/DSA-6204-1

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

AI and cryptocurrency scams are costing Americans billions, FBI reports
CPUID site hijacked to serve malware instead of HWMonitor downloads
AWS targets AI agent sprawl with new Bedrock Agent Registry
Project Glasswing and open source software: The good, the bad, and the ugly
Britain seeks views before it drops the hammer on signal jammers
Cloud degrees are moving online
AI agents aren’t failing. The coordination layer is failing

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

Unpacking AI security in 2026 from experimentation to the agentic era

New upstream release (#2442363) fixing various security issues

Update to latest upstream

Microsoft’s reauthentication snafu cuts off developers globally

https://security-tracker.debian.org/tracker/DSA-6205-1

Anthropic rolls out Claude Managed Agents
Crypto? Huh. Good gawd y’all, what is it good for? $45M in this case
‘Several dozen’ high-value corporations hit by new extortion crew in helpdesk phishing spree
Meta’s Muse Spark: a smaller, faster AI model for broad app deployment
Chevin pulls the handbrake on FleetWave software after security scare
Months-old Adobe Reader zero-day uses PDFs to size up targets
Microsoft locks out VeraCrypt and WireGuard devs, blames verification process
Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse

An update that solves six vulnerabilities can now be installed.

An update that solves six vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

An update that solves eight vulnerabilities can now be installed.

Important: fontforge security update

Moderate: ncurses security update

Zephyr Energy loses £700K in cyber hit that rerouted contractor payment
Bringing databases and Kubernetes together
Rethinking Angular forms: A state-first perspective
How Agile practices ensure quality in GenAI-assisted development
Sticky-note security turned gym into hall of ’80s horrors
Cryptographers place $5,000 bet whether quantum will matter
Minimus Welcomes Yael Nardi as CBO to Facilitate Strategic Growth
Visual Studio Code 1.115 introduces VS Code Agents app
Visual Studio Code 1.115 introduces VS Code Agents app
Smashing Security podcast #462: LinkedIn is spying on you, and you agreed to nothing

https://security-tracker.debian.org/tracker/DSA-6201-1

Criminal wannabes even more dangerous than the pros, says ex-FBI cyber chief
Microsoft announces end of support for ASP.NET Core 2.3
As breakout time accelerates, prevention-first cybersecurity takes center stage

Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.

AWS turns its S3 storage service into a file system for AI agents
Dutch healthcare software vendor goes dark after ransomware attack
Z.ai unveils GLM-5.1, enabling AI coding agents to run autonomously for hours
NHS Scotland-linked domains caught serving pr0n and dodgy sports streams
Microsoft’s new Agent Governance Toolkit targets top OWASP risks for AI agents
Get started with Python’s new frozendict type
The winners and losers of AI coding
Microsoft hints at bit bunkers for war zones

Important: fontforge security update

Important: fontforge security update

Moderate: kernel security update

Moderate: crun security update

Moderate: kernel security update

Moderate: crun security update

https://security-tracker.debian.org/tracker/DSA-6202-1

Anthropic: All your zero-days are belong to Mythos
Iran cyber actors disrupting US water, energy facilities, FBI warns
GitHub Copilot CLI adds Rubber Duck review agent

https://security-tracker.debian.org/tracker/DSA-6197-2

Hundreds of orgs compromised daily in Microsoft device code phishing attacks
US cybercrime losses pass $20B for first time as AI boosts online fraud
Russia’s Fancy Bear still attacking routers to boost fake sites, NCSC warns