Latest news
-
Vulnerabilities via Simon Willison
datasette 1.0a40
Release: datasette 1.0a40 Same security fix as 0.65.5, plus some neat new features and bug fixes: Plugins can now launch and manage background tasks using the new…
-
AI Security via Simon Willison
datasette 0.65.5
Release: datasette 0.65.5 Security fix for an issue where a trailing newline in a requested table name could bypass table permissions and expose private rows, reported…
-
Vulnerabilities via Chrome Releases
Early Stable Update for Desktop
The Stable channel has been updated to 154.0.8037.44/.45 for Windows. as part of our early stable release to a small percentage of users. A full list of changes in this…
-
Ransomware via Graham Cluley
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up…
-
AI Security via The Register
AI agents can modify themselves without humans telling them to do so
The list of dodgy things AI agents can and will do on their own - like stealing people’s credentials, escaping onto the open internet, communicating via sneaky message…
-
Vulnerabilities via Doyensec
The skb that wasn't freed - the Fragnesia primitive via Open vSwitch
TLDR: Exploit. This is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions…
-
Vulnerabilities via Debian Security
DSA-6506-1 chromium - security update
https://security-tracker.debian.org/tracker/DSA-6506-1
-
Vulnerabilities via Debian Security
DSA-6505-1 bind9 - security update
https://security-tracker.debian.org/tracker/DSA-6505-1
-
Vulnerabilities via Debian Security
DSA-6504-1 libapache2-mod-auth-openidc - security update
https://security-tracker.debian.org/tracker/DSA-6504-1
-
AI Security via Dark Reading
AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
-
via Ars Technica
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
The International Meteor Organization, the nonprofit that coordinates and publishes amateur and professional observations of meteor phenomena, said its infrastructure…
-
Vulnerabilities via The Register
CISA decides weekly vulnerability bulletin isn't necessary anymore
If you rely on the Cybersecurity and Infrastructure Security Agency’s weekly vulnerability bulletin to keep you up to date on the latest threats, we have bad news. It’s…
-
Breaches via CyberScoop
CISA promotes a fresh way to deter cyberattackers: Lie to them
For the first time, the Cybersecurity and Infrastructure Security Agency is advising critical infrastructure owners and operators on how to set up phony systems…
-
AI Security via Cloudflare
When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
A modern storefront can look perfectly healthy while malicious JavaScript works underneath: siphoning affiliate revenue, hijacking searches and clicks, tampering with…
-
Vulnerabilities via Canadian Centre for Cyber Security
ISC BIND security advisory (AV26-931)
Serial Number: AV26-931 Date: September 16, 2026 As of September 16, 2026, ISC is affected by vulnerabilities in the following product: ISC BIND 9 Prior to or equal to…
-
Vulnerabilities via Canadian Centre for Cyber Security
Apple security advisory (AV26-930)
Serial Number: AV26-930 Date: September 16, 2026 As of September 14, 2026, Apple is affected by vulnerabilities in the following products: iOS and iPadOS Prior to 27…
-
Vulnerabilities via Canadian Centre for Cyber Security
Oracle Corporation security advisory (AV26-929)
Serial number: AV26-929 Date: September 16, 2026 As of September 15, 2026, Oracle Corporation is affected by vulnerabilities in the following products: Helidon Oracle…
-
Breaches via SANS Internet Storm Center
Scans Targeting Hospitality Applications, (Wed, Sep 16th)
Earlier today, I noted an odd request showing up in our "First Seen" report: GET /PIAF-HMS/ HTTP/1.1 Host: [redacted] User-Agent: Farez-Sorter/1.0 Accept-Encoding: gzip…
-
Vulnerabilities via Canadian Centre for Cyber Security
HPE security advisory (AV26-928)
Serial number: AV26-928 Date: September 16, 2026 As of September 15, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: HPE…
-
Vulnerabilities via Chrome Releases
Chrome Beta for Android Update
Hi everyone! We've just released Chrome Beta 155 (155.0.8059.4) for Android. It's now available on Google Play.
