Latest news

  1. Vulnerabilities via Simon Willison

    datasette 1.0a40

    Release: datasette 1.0a40 Same security fix as 0.65.5, plus some neat new features and bug fixes: Plugins can now launch and manage background tasks using the new…

  2. AI Security via Simon Willison

    datasette 0.65.5

    Release: datasette 0.65.5 Security fix for an issue where a trailing newline in a requested table name could bypass table permissions and expose private rows, reported…

  3. Vulnerabilities via Chrome Releases

    Early Stable Update for Desktop

    The Stable channel has been updated to 154.0.8037.44/.45 for Windows. as part of our early stable release to a small percentage of users. A full list of changes in this…

  4. Ransomware via Graham Cluley

    Smashing Security podcast #485: These researchers got drunk to hack an LG TV

    Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up…

  5. AI Security via The Register

    AI agents can modify themselves without humans telling them to do so

    The list of dodgy things AI agents can and will do on their own - like stealing people’s credentials, escaping onto the open internet, communicating via sneaky message…

  6. Vulnerabilities via Doyensec

    The skb that wasn't freed - the Fragnesia primitive via Open vSwitch

    TLDR: Exploit. This is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions…

  7. Vulnerabilities via Debian Security

    DSA-6506-1 chromium - security update

    https://security-tracker.debian.org/tracker/DSA-6506-1

  8. Vulnerabilities via Debian Security

    DSA-6505-1 bind9 - security update

    https://security-tracker.debian.org/tracker/DSA-6505-1

  9. Vulnerabilities via Debian Security

    DSA-6504-1 libapache2-mod-auth-openidc - security update

    https://security-tracker.debian.org/tracker/DSA-6504-1

  10. AI Security via Dark Reading

    AI Security Spending Jumps as Fear Outpaces Proof of Value

    CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?

  11. via Ars Technica

    Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack

    The International Meteor Organization, the nonprofit that coordinates and publishes amateur and professional observations of meteor phenomena, said its infrastructure…

  12. Vulnerabilities via The Register

    CISA decides weekly vulnerability bulletin isn't necessary anymore

    If you rely on the Cybersecurity and Infrastructure Security Agency’s weekly vulnerability bulletin to keep you up to date on the latest threats, we have bad news. It’s…

  13. Breaches via CyberScoop

    CISA promotes a fresh way to deter cyberattackers: Lie to them

    For the first time, the Cybersecurity and Infrastructure Security Agency is advising critical infrastructure owners and operators on how to set up phony systems…

  14. AI Security via Cloudflare

    When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

    A modern storefront can look perfectly healthy while malicious JavaScript works underneath: siphoning affiliate revenue, hijacking searches and clicks, tampering with…

  15. Vulnerabilities via Canadian Centre for Cyber Security

    ISC BIND security advisory (AV26-931)

    Serial Number: AV26-931 Date: September 16, 2026 As of September 16, 2026, ISC is affected by vulnerabilities in the following product: ISC BIND 9 Prior to or equal to…

  16. Vulnerabilities via Canadian Centre for Cyber Security

    Apple security advisory (AV26-930)

    Serial Number: AV26-930 Date: September 16, 2026 As of September 14, 2026, Apple is affected by vulnerabilities in the following products: iOS and iPadOS Prior to 27…

  17. Vulnerabilities via Canadian Centre for Cyber Security

    Oracle Corporation security advisory (AV26-929)

    Serial number: AV26-929 Date: September 16, 2026 As of September 15, 2026, Oracle Corporation is affected by vulnerabilities in the following products: Helidon Oracle…

  18. Breaches via SANS Internet Storm Center

    Scans Targeting Hospitality Applications, (Wed, Sep 16th)

    Earlier today, I noted an odd request showing up in our "First Seen" report: GET /PIAF-HMS/ HTTP/1.1 Host: [redacted] User-Agent: Farez-Sorter/1.0 Accept-Encoding: gzip…

  19. Vulnerabilities via Canadian Centre for Cyber Security

    HPE security advisory (AV26-928)

    Serial number: AV26-928 Date: September 16, 2026 As of September 15, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: HPE…

  20. Vulnerabilities via Chrome Releases

    Chrome Beta for Android Update

    Hi everyone! We've just released Chrome Beta 155 (155.0.8059.4) for Android. It's now available on Google Play.