Collected every two hours from specialised publications — each link leads to the original article.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in a bypass of security/authorisation res…
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are …
Kubernetes groups one or more containers into a pod, the basic unit it deploys.
As of September 17, Red Hat had documented a flaw in a Red Hat Quay build workflow that could expose container registry credentials to code retrieved from a mu…
A Linux system can be hardened, monitored, and carefully administered while still receiving untrusted code through a package, dependency, container image, buil…
SUSE released a security update for kubevirt and related containers, addressing 16 vulnerabilities including risks of denial of service and privilege escalatio…
Linux security problems rarely stay in one place. An authentication issue can lead to unexpected privilege. A container problem can reach the host. Missing log…
Ubuntu 16.04 LTS received security updates for the linux-aws-hwe kernel to correct several vulnerabilities that could allow local attackers to escalate privile…
Ubuntu Security Notice USN-8529-2 reveals multiple vulnerability fixes in the Linux kernel affecting Ubuntu 16.04 LTS, with local attackers potentially escalat…
Fedora has released an update for fuse-overlayfs to version 1.17, addressing a privilege escalation vulnerability related to SUID/SGID bit preservation on file…
An AI-driven threat actor called JADEPUFFER built ransomware that hunts AI model files specifically, entering through a known Langflow RCE and pivoting via an …
An update for the moby-engine in Fedora 43 has been released, addressing upstream security vulnerabilities and introducing version 29.6.2, making Docker contai…
Before the week gets away from you, take a look at what's landed across the Linux ecosystem. The volume of security advisories hasn't slowed, and while not eve…
The 7.0.14-101/201 kernel builds contain a fix for an unprivileged container / jail escape. This has not been assigned a CVE number yet, but a POC is in the wi…
Multiple security issues were discovered in LXD, a system container and virtual machine manager, which could result in a bypass of security restrictions or the…
Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in a bypass of security restrictions or t…
The compromise of Nx Console shows how much infrastructure now sits behind a single developer account. GitHub repositories, CI/CD pipelines, container build sy…
An attacker compromises a Linux container, launches a cryptominer, sets up a way to stay in the system through a background task, and disappears before the inv…
Linux runs a massive part of the internet. Cloud platforms, databases, containers, web hosting, APIs, and internal business infrastructure all depend heavily o…
Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any art…
Multiple security issues were discovered in LXD, a system container and virtual machine manager, which could result in denial of service. For the oldstable dis…