Latest news

  1. Vulnerabilities via Zero Day Initiative

    ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability

    This vulnerability allows physically present attackers to escalate privileges on affected installations of Linux Kernel. Authentication is not required to exploit this…

  2. Vulnerabilities via Zero Day Initiative

    ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to…

  3. Vulnerabilities via Zero Day Initiative

    ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute…

  4. Vulnerabilities via Zero Day Initiative

    ZDI-26-699: Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerability

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to…

  5. Vulnerabilities via Zero Day Initiative

    ZDI-26-698: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to…

  6. Vulnerabilities via Zero Day Initiative

    ZDI-26-697: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to…

  7. Vulnerabilities via Zero Day Initiative

    ZDI-26-696: Linux Kernel NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerability

    This vulnerability allows local attackers to execute arbitrary code on affected installations of Linux Kernel. An attacker must first obtain the ability to execute…

  8. Vulnerabilities via Zero Day Initiative

    ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability…

  9. Vulnerabilities via Zero Day Initiative

    ZDI-26-694: Linux Kernel Net Scheduler Clsact Qdisc Use-After-Free Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute…

  10. Threat Intel via SANS Internet Storm Center

    ISC Stormcast For Monday, September 14th, 2026 https://isc.sans.edu/podcastdetail/10092, (Mon, Sep 14th)

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

  11. AI Security via Simon Willison

    commit-rewriter 0.1

    Release: commit-rewriter 0.1 I built this little web app the other day to help edit the commit messages for the Datasette security releases. The initial commits were…

  12. Threat Intel via Recorded Future

    What is Proactive Threat Intelligence? | Recorded Future

    An alert may be the first sign a security team sees, but it rarely marks the beginning of an attack. Before an intrusion reaches the network, threat actors may research…

  13. Threat Intel via Elastic Security Labs

    The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

    Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author…

  14. Breaches via Hudson Rock

    Infostealers Weekly Report: 2026-09-07 – 2026-09-14

    InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As…

  15. AI Security via Simon Willison

    shot-scraper 1.12

    Release: shot-scraper 1.12 I've added WebP support to my shot-scraper screenshot automation tool. You can now take a WebP screenshot of a web page like this…

  16. Vulnerabilities via Debian Security

    DSA-6498-1 network-manager-l2tp - security update

    https://security-tracker.debian.org/tracker/DSA-6498-1

  17. Breaches via Have I Been Pwned

    Chess.com (2026) - 4,653,212 breached accounts

    In August 2026, millions of records allegedly sourced from Chess.com were posted online. The data contained 7.3M rows with 4.6M unique email addresses, along with…

  18. AI Security via Simon Willison

    Generating running routes with GPT-6 Astra and ChatGPT Work

    Here's a neat thing I had ChatGPT Work with GPT-6 Astra (Max) do this morning: I live at . Figure out 5K and 10K running routes from me that loop from my house. Use OSM…

  19. AI Security via Simon Willison

    California Brown Pelican

    California Brown Pelican, in San Mateo County, CA, US The Pacifica Pier shut down at the start of June after a crack in the concrete walkway made access to the pier…

  20. AI Security via Simon Willison

    Quoting Paul Ford

    For a while, I must admit, it looked as if software developer roles like mine were done for. How could we fight against tireless robots? But our industry is slowly…