news
Security Leftovers
-
LWN ☛ Security updates for Thursday
Security updates have been issued by AlmaLinux (389-ds-base, ansible-core, buildah, expat, glib2, gpsd, gpsd-minimal, gzip, kernel, kernel-rt, opentelemetry-collector, osbuild-composer, perl-DBI, python-lxml, python3.12-lxml, qt5-qtbase, thunderbird, valkey, vim, and xz), Debian (pyasn1), Fedora (darktable, freeipa, freerdp2, gdk-pixbuf2, GitPython, libsoup3, openssl, perl-Net-DNS, rust-ppmd-rust, samba, and valkey), Mageia (ceph, firefox, nss, perl-DBI, thunderbird, and wget), Oracle (389-ds-base, buildah, expat, git-lfs, glib2, glibc, gpsd, gpsd-minimal, grafana-pcp, kernel, libssh, nginx, perl-GD, python3.14-cryptography, redis:7, skopeo, thunderbird, valkey, xmlrpc-c, and xz), Slackware (xz), SUSE (bzip2, cpio, curl, dracut, fuse-overlayfs, golang-github-vpenso-prometheus_slurm_exporter, helm, java-1_8_0-ibm, kbfs, kernel, kernel-devel, libopenslide-devel, libsoup, libssh2_org, libusb-1_0, libvirt, libzypp, zypper, mcphost, multipath-tools, NetworkManager, opensc, openssl-3, perl-Net-DNS, python-aiohttp, python-Authlib, python-pip, python-sqlparse, python313-dnspython, python313-idna, rpcbind, sssd, strongswan, systemd, tomcat11, ucode-intel, and wget), and Ubuntu (dotnet8, dotnet10, ffmpeg, flatpak, netty, and perl).
-
OpenSSF (Linux Foundation) ☛ Open by Default After AI: The GDS Guidance and the Enforcement Question
-
OpenSSF (Linux Foundation) ☛ Tech Talk Recap: A Practitioner’s Guide to CRA Readiness
The EU Cyber Resilience Act is no longer a distant regulatory concept. With vulnerability reporting obligations to ENISA arriving on September 11 and the full weight of the law landing in December 2027, open source maintainers, foundations, and the companies who build on top of open source all have real questions about what comes next.
-
Qt ☛ Security advisory: CVE-2026-13326 Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC module.
An out-of-bounds read and integer underflow vulnerability in the QNdefNfcTextRecord class of the Qt NFC module (qtconnectivity) has been discovered and has been assigned the CVE id CVE-2026-13326.
-
LWN ☛ Forgejo 16.0.4 and 15.0.8 address critical security vulnerability
The Forgejo software-forge project has announced the release of versions 16.0.4 and 15.0.8, which fixes two security vulnerabilities. One is a critical flaw that would allow remote-code execution (RCE): [...]
-
Security Week ☛ Organizations Warned of Cisco Secure FMC Exploitation
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.
-
Security Week ☛ 4.1 Million Impacted by AdaptHealth Data Breach
In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems.
-
Security Week ☛ Widened Scan Turns Up Fourth Rogue Claude Cyber Incident
Anthropic is most concerned about Claude Mythos 5’s reckless behavior after recent incidents in which real systems were hacked.
-
Security Week ☛ Critical NetScaler Vulnerability Exploited in Attacks
Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.
-
HackRead ☛ F5 BIG-IP APM Linux Malware Hides PHP Web Shell in Apache Memory
Sophos has published details of a Linux implant found on compromised F5 BIG-IP Access Policy Manager (APM) systems that can hide a PHP web shell inside Apache’s memory. The implant modifies legitimate BIG-IP APM PHP scripts as they are loaded, while leaving the original files unchanged on disk. This allows the web shell to operate without appearing in the files security teams would normally examine for signs of compromise.