Linux

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages 2026-09-14 at 10:40 By Sinisa Markovic The Debian project shipped Debian 13.7 codenamed “trixie.” The project folded in 92 security advisories it had already published separately, added corrections to 106 source packages, and rebuilt the installer around both. Six of the 92 advisories […]

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages Read More »

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors 2026-09-11 at 07:07 By Anamarija Pogorelec Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release. Anyone installing fresh now gets those corrections baked in from the start, cutting the batch of updates […]

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors Read More »

North Korean Hackers Deploy New Linux Espionage Toolkit

North Korean Hackers Deploy New Linux Espionage Toolkit 2026-09-07 at 15:12 By Ionut Arghire The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

North Korean Hackers Deploy New Linux Espionage Toolkit Read More »

Debian developers rejected an LLM ban and left disclosure voluntary

Debian developers rejected an LLM ban and left disclosure voluntary 2026-08-31 at 11:08 By Anamarija Pogorelec A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and Kurt Roeckx, the project secretary, announced the result: […]

Debian developers rejected an LLM ban and left disclosure voluntary Read More »

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems 2026-08-28 at 15:36 By Eduard Kovacs CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek. This article is an […]

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems Read More »

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5 2026-08-11 at 12:15 By Anamarija Pogorelec Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived […]

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5 Read More »

Tengu botnet reboots Linux devices to survive removal

Tengu botnet reboots Linux devices to survive removal 2026-07-29 at 16:52 By Sinisa Markovic A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a […]

Tengu botnet reboots Linux devices to survive removal Read More »

AI-generated reports push GNOME to shorten its disclosure window

AI-generated reports push GNOME to shorten its disclosure window 2026-07-21 at 06:53 By Anamarija Pogorelec Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising […]

AI-generated reports push GNOME to shorten its disclosure window Read More »

Debian 13.6 security update patches over a hundred advisories in trixie

Debian 13.6 security update patches over a hundred advisories in trixie 2026-07-13 at 01:25 By Anamarija Pogorelec Most PCs still run with a UEFI Secure Boot certificate authority, installed by default since 2013, that has now expired. That certificate signed the bootloaders letting machines start with Secure Boot turned on. Its expiry sits at the […]

Debian 13.6 security update patches over a hundred advisories in trixie Read More »

15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google

15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google 2026-07-09 at 14:52 By Ionut Arghire Affecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access. The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google Read More »

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems 2026-07-07 at 13:00 By Ionut Arghire The 16-year-old Januscape flaw affects Linux’s KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host. The post Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems appeared first on […]

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems Read More »

Apple Container: Open-source tool for Linux containers on the Mac

Apple Container: Open-source tool for Linux containers on the Mac 2026-07-07 at 08:00 By Anamarija Pogorelec Developers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and […]

Apple Container: Open-source tool for Linux containers on the Mac Read More »

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability 2026-07-06 at 15:48 By Ionut Arghire Organizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit. The post Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability appeared first on SecurityWeek. This article is an excerpt from […]

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability Read More »

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) 2026-06-30 at 13:25 By Zeljka Zorz Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with cloud […]

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) Read More »

Kali Linux 2026.2 trims VM boot times, refreshes its desktops

Kali Linux 2026.2 trims VM boot times, refreshes its desktops 2026-06-30 at 11:16 By Sinisa Markovic Penetration testers who run Kali Linux inside virtual machines boot their systems faster after the 2026.2 release. The change comes from a decision about graphics firmware, the code that drives NVIDIA, AMD, and Intel GPUs. That firmware has grown […]

Kali Linux 2026.2 trims VM boot times, refreshes its desktops Read More »

‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access

‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access 2026-06-29 at 14:20 By Ionut Arghire A variant of DirtyFrag, the flaw allows unprivileged local users to manipulate the Linux page cache and gain root privileges. The post ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access Read More »

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages 2026-06-16 at 13:51 By Ionut Arghire Arch Linux suspended account registrations in response to the wave of malicious packages being uploaded to AUR. The post Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Read More »

China-linked spies backdoored authentication stack to stay hidden for years

China-linked spies backdoored authentication stack to stay hidden for years 2026-06-15 at 18:27 By Zeljka Zorz A China-linked cyber espionage group known as Velvet Ant spent nearly a decade inside the internal network of an unnamed organization without being detected, according to the results of a forensic investigation published by cybersecurity firm Sygnia. The group’s […]

China-linked spies backdoored authentication stack to stay hidden for years Read More »

Organizations Warned of Exploited Linux Kernel Vulnerability

Organizations Warned of Exploited Linux Kernel Vulnerability 2026-06-03 at 14:56 By Ionut Arghire An improper authentication bug allows attackers to escalate their privileges and escape containers. The post Organizations Warned of Exploited Linux Kernel Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Organizations Warned of Exploited Linux Kernel Vulnerability Read More »

KDE Linux security audit cuts kernel modules and unused packages

KDE Linux security audit cuts kernel modules and unused packages 2026-06-02 at 11:55 By Anamarija Pogorelec KDE Linux, the in-progress operating system from the KDE community, removed several kernel modules and software packages after a security audit of the components shipped with the system. The work followed the discovery of multiple security issues in the […]

KDE Linux security audit cuts kernel modules and unused packages Read More »

Scroll to Top