Menu

Latest articles

https://security-tracker.debian.org/tracker/DSA-6105-1

Crims compromised energy firms’ Microsoft accounts, sent 600 phishing emails
FortiGate firewalls hit by silent SSO intrusions and config theft
Europe’s GDPR cops dished out €1.2B in fines last year as data breaches piled up
Bank of England: Financial sector failing to implement basic cybersecurity controls
MuleSoft gains Agent Scanners to rein in enterprise AI chaos
Ancient telnet bug happily hands out root to attackers
Another week, another emergency patch as Cisco plugs Unified Comms zero-day
European Space Agency’s cybersecurity in freefall as yet another breach exposes spacecraft and mission data
TypeScript levels up with type stripping
AI agents and IT ops: Cowboy chaos rides again

An update that solves three vulnerabilities can now be installed.

Kyu Neushwaistein discovered that telnetd from inetutils does not sanitize the USER environment variable before passing it on to login. A remote attacker can take advantage of this flaw to login as root, bypassing normal authentication processes. For the oldstable distribution (bookworm), this problem has been fixed

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Evolving Linux Malware Threats: A Guide for Admins in Cloud-Native Contexts
Smashing Security podcast #451: I hacked the government, and your headphones are next
jQuery 4.0.0 JavaScript library features trusted types

https://security-tracker.debian.org/tracker/DSA-6106-1

GitLab 2FA login protection bypass lets attackers take over accounts
Davos discussion mulls how to keep AI agents from running wild

https://security-tracker.debian.org/tracker/DSA-6104-1

Don’t click on the LastPass ‘create backup’ link – it’s a scam
Old habits die hard: 2025’s most common passwords were as predictable as ever

Once again, data shows an uncomfortable truth: the habit of choosing eminently hackable passwords is alive and well

GLib could be made to crash or run programs if it received specially crafted input.

An update that solves two vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves five vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

Everest ransomware gang said to be sitting on mountain of Under Armour data
EU considers whether there’s Huawei of axing Chinese kit from networks within 3 years
Ireland wants to give its cops spyware, ability to crack encrypted messages
Best of British: UK’s infosec envoys include Cisco, Palo Alto, and Accenture
Pro-Russian denial-of-service attacks target UK, NCSC warns
How to use Pandas for data analysis in Python
Tailwind meets AI headwind
Curl shutters bug bounty program to remove incentive for submitting AI slop
Three vulnerabilities in Anthropic Git MCP Server could let attackers tamper with LLMs
Cloudflare whacks WAF bypass bug that opened side door for attackers
Remember VoidLink, the cloud-targeting Linux malware? An AI agent wrote it
The AI Fix #84: A hungry ghost trapped in a jar gains access to the Pentagon’s network
AI framework flaws put enterprise clouds at risk of takeover
Anthropic quietly fixed flaws in its Git MCP server that allowed for remote code execution
For the price of Netflix, crooks can now rent AI to run cybercrime

An update that solves nine vulnerabilities can now be installed.

An update that solves nine vulnerabilities can now be installed.

A first look at XAML Studio 2.0
AI is rewriting the sustainability playbook

An update that solves 17 vulnerabilities, contains one feature and has one security fix can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves 10 vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

Akamai CEO wants help to defeat piracy, reckons he can handle edge AI alone
Broker who sold malware to the FBI set for sentencing
Don’t underestimate pro-Russia hacktivists, warns UK’s cyber crew
Windows 11 shutdown bug forces Microsoft into out-of-band damage control
Ingram Micro admits summer ransomware raid exposed thousands of staff records
ClickHouse buys Langfuse as data platforms race to own the AI feedback loop
UK prime minister stares down barrel of ban on social media for kids
Warwickshire school to reopen after cyberattack crippled IT
Royal Navy’s helicopter drone makes its first autonomous flight
Edge AI: The future of AI inference is smarter local compute
AI coding requires developers to become better managers

An update that contains one feature can now be installed.

An update that contains one feature can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves seven vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

ATM maintenance tech broke the bank by forgetting to return a key
Microsoft hiring energy strategists to power its Asian datacenters
Mandiant releases quick credential cracker, to hasten the death of a bad protocol

An update that solves 10 vulnerabilities and has one bug fix can now be installed.

New efficiency upgrades in Red Hat Advanced Cluster Management for Kubernetes 2.15

Update to 144.0.7559.59 * CVE-2026-0899: Out of bounds memory access in V8 * CVE-2026-0900: Inappropriate implementation in V8 * CVE-2026-0901: Inappropriate implementation in Blink * CVE-2026-0902: Inappropriate implementation in V8

This update adds a patch to fix CVE-2025-56225, a flaw in the bundled version of fluidsynth.

Upgrade to libtpms 0.10.2 fixing CVE-2026-21444

Update to 144.0.7559.59 * CVE-2026-0899: Out of bounds memory access in V8 * CVE-2026-0900: Inappropriate implementation in V8 * CVE-2026-0901: Inappropriate implementation in Blink * CVE-2026-0902: Inappropriate implementation in V8

Upgrade to libtpms 0.10.2 fixing CVE-2026-21444

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

The business social networking site is a vast, publicly accessible database of corporate information. Don’t believe everyone on the site is who they say they are.

Fast Pair, loose security: Bluetooth accessories open to silent hijack

Several vulnerabilities were discovered in python-urllib3, a HTTP library with thread-safe connection pooling for Python3, which could result in denial of service or request forgery. For the oldstable distribution (bookworm), these problems have been fixed in version 1.26.12-1+deb12u2.

MGASA-2026-0012 – Updated gimp packages fix security vulnerabilities

MGASA-2026-0011 – Updated python-urllib3 packages fix security vulnerabilities

MGASA-2026-0010 – Updated libpng packages fix security vulnerabilities

MGASA-2026-0009 – Updated nodejs packages fix security vulnerabilities

MGAA-2026-0006 – Updated v4l2loopback packages fix bug

https://security-tracker.debian.org/tracker/DSA-6103-1

https://security-tracker.debian.org/tracker/DSA-6102-1

Astro web framework maker merges with Cloudflare

https://security-tracker.debian.org/tracker/DSA-6101-1

Visual Studio Code adds agent development extension
Google tests BigQuery feature to generate SQL queries from English
Sorry Dave, I’m afraid I can’t do that! PCs refuse to shut down after Microsoft patch
German cops add Black Basta boss to EU most-wanted list
RondoDox botnet linked to large-scale exploit of critical HPE OneView bug
Bankrupt scooter startup left one private key to rule them all