news
Security Leftovers
-
OpenSSF (Linux Foundation) ☛ OpenSSF Newsletter – February 2026
-
LWN ☛ Security updates for Thursday
Security updates have been issued by AlmaLinux (freerdp), Debian (firefox-esr and libstb), Fedora (389-ds-base, chromium, firefox, munge, opentofu, python3-docs, python3.14, and vim), Oracle (buildah, containernetworking-plugins, gimp, grafana, grafana-pcp, kernel, podman, runc, and skopeo), Red Hat (go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, mariadb:10.11, podman, and skopeo), SUSE (cacti, docker-stable, expat, firefox-esr, freerdp, freerdp2, libjxl, libsoup-2_4-1, python-tornado, python-urllib3_1, python3, python311-Django4, python312, python313, python39, and redis), and Ubuntu (ceph, mongodb, protobuf, and rlottie).
-
Tom's Hardware ☛ Researchers discover massive Wi-Fi vulnerability affecting multiple access points — AirSnitch lets attackers on the same network intercept data and launch machine-in-the-middle attacks
A team of researchers discovered that they can break cryptographic client isolation on a number of wireless routers by taking advantage of how Wi-Fi networks work.
-
Security Week ☛ Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers
Already added to CISA’s KEV catalog, the flaw allows attackers to bypass authentication and gain administrative privileges.
-
Security Week ☛ Trend Micro Patches Critical Apex One Vulnerabilities [Ed: Your proprietary 'security' products is a security hole]
TrendAI has fixed eight critical and high-severity issues in backdoored Windows and macOS endpoint security products.
-
Security Week ☛ Zyxel Patches Critical Vulnerability in Many Device Models
The issue impacts the UPnP function of multiple device models and could be exploited for remote code execution.
-
Security Week ☛ Claude Code Flaws Exposed Developer Devices to Silent Hacking
Anthropic has patched vulnerabilities whose impact was demonstrated by Check Point via malicious configuration files.
-
Richard W.M. Jones: Veritasium
I was interviewed on Veritasium about the rise of GNU/Linux and the XZ hack.