News
Dracut's Network-Boot Flaw Lets a Rogue DHCP Server Hijack Linux at Boot; Patches Are Out
InfrastructureSecurityLinux
A flaw in Dracut, the tool that handles the boot entry point for much of the Linux world (CVE-2026-6893, CVSS 8.8): a rogue server on the same network can hijack a machine with root privileges the moment it boots, striking the defenseless earliest boot stage. It affects network-boot (PXE, etc.) setups. Apply each distro's update and isolate the network.
2026.06.1138 views
News
Splunk August 2026: 60+ flaws, three rated 9.4 need no login
SecurityGlobal CompaniesInfrastructure
Two serious flaws in Splunk, the enterprise monitoring and log platform (CVE-2026-20253 and CVE-2026-20251, up to CVSS 9.8): files on the server can be created or destroyed with no login, and the server can be hijacked via arbitrary code execution from a low-privilege account. The company's watchtower becomes the target. Update Splunk Enterprise to 10.2.4 or 10.0.7 now.
2026.06.1146 views
News
Six Critical Flaws in Red Hat's OpenShift Migration Advisor: vCenter and Kubernetes Credentials at Risk, CVE-2026-53474 and More
InfrastructureSecurityGlobal Companies
Six serious flaws in Red Hat's free OpenShift Migration Advisor (CVE-2026-53469–53476, up to CVSS 9.6): broken SaaS tenant isolation stealing other tenants' config and tokens and wiping all customer data, SQL injection via RVTools reading Kubernetes keys, and plaintext agent-to-vCenter traffic leaking admin creds. Update the agent and rotate credentials.
2026.06.1126 views
News
Ghidra 12.1.2 Still Has an Unpatched Hole: CVE-2026-18718
SecurityDevelopment
Four serious flaws in NSA's free analysis tool Ghidra (CVE-2026-52751/49498/52754/52758, all CVSS 8.8). The worst, CVE-2026-52751, needs no auth: opening a crafted project file runs arbitrary code. The other three hit Ghidra Server with DB takeover and impersonation. Update to 12.1.2 now.
2026.06.1159 views
Column
Rebuilding Kakaku.com's 30-Year-Old Code With 71 AI Agents
AIJapanese CompaniesDevelopment
Kakaku.com is rebuilding its 30-year-old, 9.6M-line system with 71 AI agents on Python and FastAPI. I agree with the stack, but ask why the tied candidates lost, and the cost of over-trusting AI.
2026.06.1051 views
News
Claude Fable 5 Goes Public: Why Engineers Cheered, Then Revolted
Global CompaniesAI
On June 9 Anthropic released Claude Fable 5, the safety-wrapped public version of Mythos—the 'too dangerous' top model that governments and Japan's Diet had fought over for a month. Engineers cheered an 80.3% SWE-Bench Pro score, then revolted over a term that silently degrades performance and over-eager censorship.
2026.06.1033 views
News
Cisco SD-WAN CVE-2026-20245: Three Products Hit, Attack Timeline Out
Global CompaniesSecurityInfrastructure
Cisco Catalyst SD-WAN Manager (formerly vManage), which manages an enterprise's whole network, has a flaw already confirmed in attacks (CVE-2026-20245). On success, attackers seize the device's highest privilege and can push unauthorized config changes to edge devices. Cisco has released the fix 20.18.3.1; there is no workaround, so updating is required. Here are the affected versions and what to do now.
2026.06.1038 views
News
Chrome and Edge V8 Zero-Day: Fixed Versions and Current Status
SecurityMobileGlobal Companies
Google Chrome, the world's most-used browser, has a serious flaw already used in attacks (CVE-2026-11645), and an emergency fix is out. Opening a trap page alone can hand over your device, and this is the fifth such case in 2026. All Chrome users are affected, as are Edge and Brave. Update to 149.0.7827.103 now. Here's how to check and what's affected.
2026.06.1052 views
News
Ivanti Sentry CVE-2026-10520 Exploited (KEV): Patch the 10.0 RCE Now
MobileSecurityInfrastructure
A flaw lets attackers remotely take over Ivanti Sentry — the gateway between staff phones and corporate email — with no password (CVE-2026-10520, severity 10.0). Paired with an authentication-bypass flaw that creates administrators at will (CVE-2026-10523), it requires an update to R10.5.2 / R10.6.2 / R10.7.1. The product has been attacked repeatedly before. Here are the affected versions and what to do now.
2026.06.1047 views
News
Apache HTTP Server HTTP/2 Bomb: Affected Versions and the 2.4.68 Fix
InfrastructureSecurityAI
A flaw called the 'HTTP/2 Bomb' (CVE-2026-49975) lets even a single home PC take Apache and other major web servers offline in seconds. OpenAI's AI 'Codex' found it before humans did, a proof-of-concept is public, and Shodan shows 880,000+ servers exposed. Apache fixed it in 2.4.68, released June 8. Here are the affected versions and what to update now.
2026.06.09178 views
News
The Security Risks of Outdated VPN Protocols Like IKEv1 (and the CVE-2026-50751 Attack, Explained)
InfrastructureGlobal CompaniesSecurity
Check Point VPN gateways have a flaw (CVE-2026-50751) that lets attackers into corporate networks with no valid password, and a Qilin ransomware crew is already exploiting it. It affects setups using the legacy IKEv1 protocol. Apply the hotfix now.
2026.06.09176 views
News
LiteLLM CVE-2026-42271: 1.83.7 isn't enough, upgrade to 1.84.0+
AISecurityDevelopment
LiteLLM, the popular gateway fronting 100+ AI services, has a server-takeover flaw (CVE-2026-42271). Chained with a Starlette bug it enables unauthenticated remote code execution, exposing every stored API key. Patch to 1.83.7 now.
2026.06.0974 views