The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A version 2 Linux kernel patch series posted on August 31 proposes a new eBPF security interface for applying Landlock policy during program execution. The 15-…
An eBPF security system can produce precise Linux telemetry while leaving a harder question unanswered: what happens if the eBPF layer itself is misconfigured,…
Jonghyuk Kim submitted a Linux Direct Rendering Manager scheduler patch series on Aug 28, 2026 that targets a use-after-free read shared by several GPU drivers…
Linux kernel vulnerability news dominated the security updates published from August 20 through August 27. Ubuntu, Debian, Fedora, Mageia, Oracle Linux, Rocky …
The Linux IPMI maintainer accepted a patch on Aug 26, 2026 that restores an RCU grace period before command-receiver objects are freed. The one-line change add…
A Linux dm-integrity patch posted on Aug 24, 2026 targets a writeback race that can leave stored data with the wrong integrity tag after a crash. Chen Cheng pr…
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerabilit…
A Linux BPF patch posted on August 21, 2026, expands validation for program replacement across cgroup and Linux Security Module hooks. Version 3 addresses case…
A flaw in Kata Containers weakened container security in some Confidential Containers deployments. It allowed a malicious host operator to make the protected g…
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-…
This week’s Linux security updates affect cloud hosts, public servers, and services used across entire networks. Ubuntu, Debian, and Rocky Linux released impor…
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP…
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software b…
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to ach…
Security researchers have disclosedFence2Pwn, a new Linux kernel exploitation technique that uses KFENCE’s alternate memory-allocation path to bypass protectio…
A disclosure posted to the oss-security mailing list on August 16, 2026, reports that OpenZFS on Linux accepts namespace-local CAP_SYS_ADMIN for several host-l…
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced pers…
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts.The vulnerability, tracked as CVE-2026-58231, …
Two fixes posted August 13 correct separate per-CPU map failures on Linux systems whose logical CPU IDs contain gaps.
This week’s Linux security updates cover several areas administrators cannot afford to overlook. Debian, Ubuntu, Fedora, SUSE, openSUSE, and other distribution…
A step-by-step method for finding and proving CORS misconfiguration vulnerabilities: the header checks, the edge cases developers miss, and how to fix them.How…
A proposed Linux kernel patch addresses a private-futex race that a recent security fix left unresolved. Security researcher Hyunwoo Kim found that a rare sequ…
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.The vu…
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution.…