Linux

Other users can watch your browsing and time your keystrokes through OS file notifications

Other users can watch your browsing and time your keystrokes through OS file notifications 2026-09-28 at 15:14 By Anamarija Pogorelec Researchers at Graz University of Technology have used the file-notification systems in Windows, Linux, and macOS to spy on activity in other accounts. On Windows, a standard unprivileged account detected 95.7 percent of another user’s […]

Other users can watch your browsing and time your keystrokes through OS file notifications Read More »

Windows, Linux, Android File Notification Systems Leak User Activity

Windows, Linux, Android File Notification Systems Leak User Activity 2026-09-25 at 13:53 By Eduard Kovacs Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events. The post Windows, Linux, Android File Notification Systems Leak User Activity appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Windows, Linux, Android File Notification Systems Leak User Activity Read More »

GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection

GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection 2026-09-24 at 11:32 By Sinisa Markovic GNOME 50.5, which the GNOME Release Team shipped on September 24, patches a CVE in the gvfs file system layer, a JavaScript injection flaw in the Epiphany web browser and a use-after-free bug in the librsvg image […]

GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection Read More »

Ubuntu kernel CVE fixes are moving to a weekly release schedule

Ubuntu kernel CVE fixes are moving to a weekly release schedule 2026-09-24 at 07:27 By Anamarija Pogorelec Ubuntu kernels will ship every week under a new release schedule from Canonical, which is merging its four-week cycle for regular Stable Release Updates (SRUs) and its two-week cycle for security fixes into a single two-week cycle. The […]

Ubuntu kernel CVE fixes are moving to a weekly release schedule Read More »

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities 2026-09-21 at 12:31 By Ionut Arghire Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory. The post Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities Read More »

Gopass: Open-source command-line password manager for teams

Gopass: Open-source command-line password manager for teams 2026-09-21 at 08:00 By Anamarija Pogorelec Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement for pass, the standard Unix password manager. Out of the box, Gopass encrypts each […]

Gopass: Open-source command-line password manager for teams Read More »

$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws 2026-09-15 at 19:00 By Kevin Townsend AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage. The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws Read More »

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages 2026-09-14 at 10:40 By Sinisa Markovic The Debian project shipped Debian 13.7 codenamed “trixie.” The project folded in 92 security advisories it had already published separately, added corrections to 106 source packages, and rebuilt the installer around both. Six of the 92 advisories […]

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages Read More »

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors 2026-09-11 at 07:07 By Anamarija Pogorelec Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release. Anyone installing fresh now gets those corrections baked in from the start, cutting the batch of updates […]

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors Read More »

North Korean Hackers Deploy New Linux Espionage Toolkit

North Korean Hackers Deploy New Linux Espionage Toolkit 2026-09-07 at 15:12 By Ionut Arghire The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

North Korean Hackers Deploy New Linux Espionage Toolkit Read More »

Debian developers rejected an LLM ban and left disclosure voluntary

Debian developers rejected an LLM ban and left disclosure voluntary 2026-08-31 at 11:08 By Anamarija Pogorelec A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and Kurt Roeckx, the project secretary, announced the result: […]

Debian developers rejected an LLM ban and left disclosure voluntary Read More »

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems 2026-08-28 at 15:36 By Eduard Kovacs CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek. This article is an […]

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems Read More »

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5 2026-08-11 at 12:15 By Anamarija Pogorelec Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived […]

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5 Read More »

Tengu botnet reboots Linux devices to survive removal

Tengu botnet reboots Linux devices to survive removal 2026-07-29 at 16:52 By Sinisa Markovic A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a […]

Tengu botnet reboots Linux devices to survive removal Read More »

AI-generated reports push GNOME to shorten its disclosure window

AI-generated reports push GNOME to shorten its disclosure window 2026-07-21 at 06:53 By Anamarija Pogorelec Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising […]

AI-generated reports push GNOME to shorten its disclosure window Read More »

Debian 13.6 security update patches over a hundred advisories in trixie

Debian 13.6 security update patches over a hundred advisories in trixie 2026-07-13 at 01:25 By Anamarija Pogorelec Most PCs still run with a UEFI Secure Boot certificate authority, installed by default since 2013, that has now expired. That certificate signed the bootloaders letting machines start with Secure Boot turned on. Its expiry sits at the […]

Debian 13.6 security update patches over a hundred advisories in trixie Read More »

15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google

15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google 2026-07-09 at 14:52 By Ionut Arghire Affecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access. The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google Read More »

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems 2026-07-07 at 13:00 By Ionut Arghire The 16-year-old Januscape flaw affects Linux’s KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host. The post Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems appeared first on […]

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems Read More »

Apple Container: Open-source tool for Linux containers on the Mac

Apple Container: Open-source tool for Linux containers on the Mac 2026-07-07 at 08:00 By Anamarija Pogorelec Developers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and […]

Apple Container: Open-source tool for Linux containers on the Mac Read More »

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability 2026-07-06 at 15:48 By Ionut Arghire Organizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit. The post Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability appeared first on SecurityWeek. This article is an excerpt from […]

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability Read More »

Scroll to Top