Menu

Latest articles

DIY AI bot farm OpenClaw is a security ‘dumpster fire’
British military to get legal OK to swat drones near bases

xrdp is an open source RDP server. It was found that xrdp contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code

Several security issues were fixed in CRaC JDK 21.

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 8.

Several security issues were fixed in OpenJDK 11.

15.x 15.1 (2026-01-24) Fix #15088: When building a new train, the refit button state may be incorrect (#15162) Fix #15160: Incorrect company names displayed in load game window (#15161)

Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor
StopICE hacked to send alarming text messages, admins accuse border patrol agent of sabotage
Russia-linked APT28 attackers already abusing new Microsoft Office zero-day
McDonald’s is not lovin’ your bigmac, happymeal, and mcnuggets passwords
OpenClaw patches one-click RCE as security Whac-A-Mole continues
Notepad++ update service hijacked in targeted state-linked attack

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Infrastructure cyberattacks are suddenly in fashion. We can buck the trend
How should AI agents consume external data?
AI will not save developer productivity

An update that solves five vulnerabilities and contains one feature can now be installed.

An update that solves five vulnerabilities and contains one feature can now be installed.

An update that solves three vulnerabilities can now be installed.

Why native cloud security falls short

An update that fixes one vulnerability is now available.

Open-source AI is a global security nightmare waiting to happen, say researchers
Enterprise Spotlight: Manufacturing Reimagined
AI security startup CEO posts a job. Deepfake candidate applies, inner turmoil ensues.

Multiple vulnerabilities have been found in Pillow, an image processing library for Python. CVE-2021-23437 The getrgb function is susceptible to a ReDoS. CVE-2022-24303

Ceph is a distributed object, block, and file storage platform. CVE-2022-0670 A flaw was found in Openstack manilla owning a Ceph File system “share”, which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the

Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2025-67724 Custom reason phrases can cause multiple vulnerabilities (like XSS, header injection, …) due to being used unescaped in HTTP headers.

Security fix for CVE-2026-24049

Update to 0.46.3, fixes CVE-2026-24049.

Fix CVE-2025-15536

This month in security with Tony Anscombe – January 2026 edition

The trends that emerged in January offer useful clues about the risks and priorities that security teams are likely to contend with throughout the year

DynoWiper update: Technical analysis and attribution

ESET researchers present technical details on a recent data destruction incident affecting a company in Poland’s energy sector

FBI takes notorious RAMP ransomware forum offline

MGAA-2026-0008 – Updated remove-old-kernels packages fix bugs

AI use may speed code generation, but developers’ skills suffer

https://security-tracker.debian.org/tracker/DSA-6117-1

Important: openssl security update

Moderate: glibc security update

Moderate: gcc-toolset-15-binutils security update

Important: openssl security update

Moderate: curl security update

January blues return as Ivanti coughs up exploited EPMM zero-days
How Banco do Brasil uses hyperautomation and platform engineering to drive efficiency
From if to how: A year of post-quantum reality
Thousands more Oregon residents learn their health data was stolen in TriZetto breach
Google expands BigQuery with conversational agent and custom agent tools

A security issue was discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), this problem has been fixed in version 144.0.7559.109-1~deb12u1.

The best free cloud computing courses in 2026
Are you ready for JavaScript in 2026?

An update that solves seven vulnerabilities can now be installed.

Best Open-Source Linux Patch Management Software for Secure Linux Servers
Who profits from AI? Not OpenAI, says think tank

MGASA-2026-0029 – Updated openssl packages fix security vulnerabilities

MGASA-2026-0028 – Updated gpsd packages fix security vulnerabilities

MGASA-2026-0027 – Updated libxml2 packages fix security vulnerabilities

MGASA-2026-0026 – Updated xen packages fix security vulnerabilities

Microsoft previews GitHub Copilot app modernization for C++
Java developers want container security, just not the job that comes with it

https://security-tracker.debian.org/tracker/DSA-6116-1

Maybe CISA should take its own advice about insider threats hmmm?

https://security-tracker.debian.org/tracker/DSA-6114-1

Suse offers cloud sovereignty assessment tool
Hacking attack leaves Russian car owners locked out of their vehicles
New PDF compression filter will save space, need software updates
Apiiro’s Guardian Agent guards against insecure AI code
Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan

ESET researchers discover an Android spyware campaign targeting users in Pakistan via romance scam tactics, revealing links to a broader spy operation

To stop crims, Google starts dismantling residential proxy network they use to hide
AV vendor goes to war with security shop over update server scare
Seven habits that help security teams reduce risk without slowing delivery
ShinyHunters swipes right on 10M records in alleged dating app data grab
Patch or perish: Vulnerability exploits now dominate intrusions
Cyberattack on Poland’s power grid could have turned deadly in winter cold

Several security issues were fixed in containerd.

Several security issues were fixed in wlc.

Get started with Angular: Introducing the modern reactive workflow
Why your next microservices should be streaming SQL-driven

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves seven vulnerabilities can now be installed.

Upgrade to upstream. Eliminates distributing harfbuzz sources. Upgrade to upstream 0.032.

Crooks are hijacking and reselling AI infrastructure: Report
Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock

https://security-tracker.debian.org/tracker/DSA-6115-1

https://security-tracker.debian.org/tracker/DSA-6113-1

Google’s LiteRT adds advanced hardware acceleration
Ransomware crims forced to take off-RAMP as FBI seizes forum
Four arrested in crackdown on Discord-based SWATting and doxing
Everybody is WinRAR phishing, dropping RATs as fast as lightning
Drowning in spam or scam emails? Here’s probably why

Has your inbox recently been deluged with unwanted and even outright malicious messages? Here are 10 possible reasons – and how to stem the tide.

Fortinet unearths another critical bug as SSO accounts borked post-patch
Old Windows quirks help punch through new admin defenses
End-to-end security for AI: Integrating AltaStata Storage with Red Hat OpenShift confidential containers
Beware! Fake ChatGPT browser extensions are stealing your login credentials
Teradata unveils enterprise AgentStack to push AI agents into production
CPython vs. PyPy: Which Python runtime has the better JIT?
Is code a cow path?

An update that solves six vulnerabilities can now be installed.