news
Security Leftovers
-
LWN ☛ Security updates for Friday
Security updates have been issued by AlmaLinux (apr-util and qt6-qt5compat), Debian (libevent and ruby-rack), Fedora (bluez, corosync, curl, dokuwiki, grpcurl, libevent, and rest), Oracle (gstreamer1-plugins-bad-free, perl-DBI, python-urllib3, qt5-qtbase, qt6-qt5compat, and thunderbird), Red Hat (osbuild-composer), SUSE (azure-storage-azcopy, chromedriver, corosync, ggml-devel, helm, kernel, libmariadb-devel, libzypp, zypper, opensc, php7, tomcat10, and waylyrics), and Ubuntu (apache2, beets, glibc, kissfft, libebml, linux-nvidia-6.17, php8.1, php8.3, php8.5, and python2.7, python3.4, python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.14).
-
OpenSSF (Linux Foundation) ☛ A Community Guide to the EU CRA September 11 Deadline for Manufacturers
The EU Cyber Resilience Act (CRA) introduces new cybersecurity requirements for products with digital elements. Discover what the September 11, 2026 reporting deadline for manufacturers means for the open source community, maintainers, and stewards, and how you can prepare to support downstream ecosystems.
-
Raspberry Pi ☛ The EU Cyber Resilience Act: mandatory reporting requirements
The Cyber Resilience Act (CRA) is the EU’s primary legislation focused on the cybersecurity of digital products. It places binding requirements on manufacturers of connected products sold on the EU market. Under the CRA, a specific set of reporting obligations takes effect from 11 September 2026; if you sell hardware or software into the EU, this is something to think about.
-
Raspberry Pi ☛ Raspberry Pi and the European Cyber Resilience Act (CRA) [PDF]
Choosing Raspberry Pi helps integrators easily meet the CRA requirements. While Raspberry Pi Ltd cannot discharge your obligations as a manufacturer, it has already built, tested, and maintained the infrastructure the CRA requires you to have, offering a mature platform to build upon. The infrastructure Raspberry Pi Ltd provides is the hardest to build from scratch; this includes a software bill of materials (SBOM), which is generated automatically for every software release; signed secure-boot and full-diskencryption paths; automated updates and rollback; an update channel that reaches devices behind customer firewalls without opening a port; and a vulnerability disclosure process that is already in place.
As the integrator, you must still conduct the risk assessment and classification processes, choose your conformity route, and meet the reporting obligation should it be required. However, having this infrastructure in place ensures your own compliance effort can focus on factors that are genuinely specific to your products, rather than on re-inventing device identity, artefact integrity, and rollback from first principles.
-
Security Week ☛ Surfshark Systems Targeted by Hackers
A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.
-
Security Week ☛ GitLab Vulnerability Exploited One Day After Disclosure
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.
-
Qt ☛ Security advisory: CVE-2026-11573 Uncontrolled recursion in QDomDocument serialization
Updated 11 September 2026: the affected version range in this advisory has been corrected. It originally read "from 6.7.0 to 6.8.1". Further source review established that the recursive serialization code has been present since Qt 2.2.0, so all Qt versions before the fixed releases listed below are affected. The CVE record has been updated accordingly.
-
Security Week ☛ Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.
-
Qt ☛ Security advisory: CVE-2026-13326 Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC module
An out-of-bounds read and integer underflow vulnerability in the QNdefNfcTextRecord class of the Qt NFC module (qtconnectivity) has been discovered and has been assigned the CVE id CVE-2026-13326.
-
Qt ☛ Security advisory: CVE-2026-19248: Unbounded recursion vulnerability in the QDomNode destructor of Qt XML impacts Qt
Unbounded destructor recursion in the QDomNode destructor of Qt XML has been discovered and has been assigned the CVE id CVE-2026-19248.
-
Scoop News Group ☛ Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
A Department of Transportation rule published last week says that airlines complying with cybersecurity regulations will have reduced customer obligations in the event of an attack.
-
Security Week ☛ Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.
-
Scoop News Group ☛ Researchers say Proprietary Chaffbot Company agents were behind May hacking campaign targeting RubyGems [Ed: At what point do this slop companies receive a corporate death sentence?]
OpenAI confirmed their agents were behind a campaign in May that researchers say flooded the popular online code repository with malicious software packages.