news
Security Leftovers
-
LWN ☛ Security updates for Wednesday
Security updates have been issued by AlmaLinux (kernel, kernel-rt, libkcapi, nginx, nginx:1.24, openssl, osbuild-composer, perl, perl:5.32, python-tornado, rsync, and rust), Debian (cjose and nginx), Fedora (environment-modules, erlang, GitPython, knot, perl-Authen-SASL, python-configargparse, ruby, rubygems, and sblim-sfcb), Oracle (firefox, git-lfs, gstreamer1-plugins-base, kernel, libkcapi, nginx, nginx:1.26, openssl, osbuild-composer, perl, perl-YAML-Syck, postgresql18, python-tornado, and rust), Red Hat (fence-agents, git-lfs, microcode_ctl, osbuild-composer, podman, python-pyasn1, and resource-agents), SUSE (389-ds, ant, bson-devel, chirp-20260911, docker, gimp, google-cloud-sap-agent, hauler, kernel, kimi-code, libpcap, python-GitPython, python310, syncthing, yast2-samba-client, and zstd-jni), and Ubuntu (aom, imagemagick, kitty, openssh, phpseclib, policykit-1, python-sql, python-webob, shibboleth-sp, simplesamlphp, snapcast, srt, and suricata-update).
-
OpenSSF (Linux Foundation) ☛ We’re In: Enterprise Commitment to Sustainable Package Registries
The OpenSSF Governing Board and major tech enterprises are partnering to support sustainable funding models for public package registries. This commitment aims to secure and scale the global software supply chain while ensuring open source stays free and accessible for individual developers.
-
Security Week ☛ Pixel Modem Zero-Day Exploited in Targeted Attacks
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15.
-
Security Week ☛ US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.
-
Scoop News Group ☛ Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.”
-
Scoop News Group ☛ CISA promotes a fresh way to deter cyberattackers: Lie to them
It’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries.
-
Security Week ☛ 280,000 Impacted by Premier Medical Group Data Breach
In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information.
-
Security Week ☛ Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities.
-
Latvia ☛ President pardons inventor who warned CSDD about IT vulnerability
Latvian President Edgars Rinkēvičs has pardoned inventor Raimonds Skuruls, who was recently convicted of extortion in connection with a security vulnerability discovered in the Road Traffic Safety Directorate's (CSDD) information technology (IT) system, presidential advisor Mārtiņš Drēģeris confirmed to the LETA newswire on Wednesday.
-
Qt ☛ Security advisory: CVE-2026-76151 out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module)
An out-of-bounds read (buffer over-read) vulnerability in the HTTP Cache-Control response header parsing of the Qt Framework (QtNetwork module) has been discovered and has been assigned the CVE id CVE-2026-76151.
-
GamingOnLinux ☛ GamingOnLinux ☛ Valve now say your data is safe from the CEVA Logistics cyberattack | GamingOnLinux
Back in early August, we covered the CEVA Logistics cyberattack which affected Steam hardware deliveries in Europe and now we have an update for you.
-
Cisco zero-day goes straight to root, BambooToken branches into Linux, CenterPoint breach claim hits 7M+