news
Security Leftovers
-
LWN ☛ Security updates for Thursday
Security updates have been issued by AlmaLinux (bind, firefox, freerdp, ghostscript, glibc, kernel, kernel-rt, perl-DBI, python3.12, rust-rpm-sequoia, rust-sequoia-sq, rust-sequoia-sqv, and vim), Debian (gst-plugins-base1.0, python3.11, and xz-utils), Fedora (7zip, chromium, curl, docker-buildx, kernel, Lmod, and sos), Mageia (tesseract), Oracle (dovecot, firefox, freerdp, gd, ghostscript, kernel, librabbitmq, perl-DBI, python3.12, rust-rpm-sequoia, rust-sequoia-sqv, sg3_utils, vim, and virtuoso-opensource), Slackware (xorg-server), SUSE (aliyun-cli, busybox, cadvisor, chromedriver, chromium, crane, distribution-registry, fetchmail, fio, ghostscript, golang-github-prometheus-alertmanager, google-osconfig-agent, govulncheck-vulndb, libsoup, libXtst, openexr, prometheus-blackbox_exporter, python-fsspec, rpcbind, rsyslog, rustup, wireshark, wpa_supplicant, and zcode), and Ubuntu (erlang, golang-golang-x-net, gst-plugins-ugly1.0, lxml, poppler, and sudo).
-
Pen Test Partners ☛ Your Hey Hi (AI) can access it. Can an attacker?
That does not make prompt injection trivial. It just means the easy examples sometimes hide why it matters.
-
Security Week ☛ FortiBleed Attackers Locking Victims Out of Fortinet Devices
Attackers are creating new accounts and deleting existing ones and passwords to prevent legitimate access.
-
Security Week ☛ Oracle Health Data Breach Tally Climbs to Nearly 20 Million
The figure is far higher than the counts that surfaced in earlier filings and patient notifications.
-
Security Week ☛ TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.
-
Security Week ☛ SonicWall and Splunk Patch Critical Vulnerabilities
Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges.
-
Security Week ☛ Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication
Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products.
-
Security Week ☛ Cisco Patches a Dozen Critical Vulnerabilities
The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution.