News
LXD hit by 11 flaws including CVE-2026-63294, only 4 affect solo hosts
SecurityLinux
Canonical's LXD picked up 11 CVE entries on August 12, nine rated 9.9. Fixes shipped August 2, seven need multi-tenant setups, and LXD 6.10 does not exist.
2026.08.1332 views
News
FreeRDP 3.29.0 is not enough: update to 3.30.0 (CVE-2026-68579)
SecurityDevelopmentLinux
FreeRDP, the open-source engine behind Remmina and most Linux remote-desktop apps, has fixed 22 security flaws, including two critical bugs that let a malicious or intercepting server bypass encryption and spy on or hijack your session. Update to version 3.29.0. CVE-2026-66402 and more.
2026.08.0133 views
News
Pre-Login Takeover Flaw in Linux Remote Desktop 'xrdp': 10 Flaws Fixed at Once (CVE-2026-41252), Update to 0.10.6.1
SecurityLinux
xrdp, the popular software that accepts Windows Remote Desktop connections to Linux, has a worst-tier flaw exploitable without a password. A malicious relay destination alone can lead to remote takeover, and version 0.10.6.1 fixes 10 flaws at once. Here is who is affected and how to update on each Linux.
2026.07.2138 views
News
Critical flaw in a tool bundled with Ubuntu (CVE-2026-11386): a spoofed server could sneak in malicious software — update now
SecurityLinux
A critical flaw, CVE-2026-11386 (CVSS 9.0), was found in ubuntu-pro-client, a tool bundled with Ubuntu and used on servers worldwide. Loose validation of the contract server's response lets a spoofed server rewrite where software is fetched from and plant malicious packages. All supported LTS releases are affected; a normal security update applies the fix.
2026.07.1621 views
Lab
Claude Desktop Comes to Linux: Cowork Runs a Real VM Inside Your PC
DevelopmentLinuxAI
Claude's desktop app now runs on Linux (Ubuntu/Debian). Cowork boots a VM inside your own PC, but Linux trips over a 'kvm' permission. Here's why, and the fix.
2026.07.03223 views
News
libzypp (openSUSE/SUSE Linux) File-Overwrite Flaw: What It Is and How to Fix It
LinuxSecurityInfrastructure
libzypp, the openSUSE/SUSE Linux package manager, has a path traversal flaw (CVE-2026-25707, CVSS up to 8.8): a malicious repository can overwrite system files. Update to the fixed version now.
2026.06.2933 views
News
Windows BitLocker Bypass Flaw YellowKey: Fix Status and What to Do
LinuxSecurity
A flaw (CVE-2026-45585, 'YellowKey') abuses the Windows recovery environment WinRE to defeat BitLocker disk encryption and the UEFI/BIOS password in minutes with physical access and one USB stick. It breaks the 'encrypted, so safe' premise for lost or stolen PCs. Microsoft fixed it in the June 2026 update — apply it now.
2026.06.2379 views
News
ADSys, Ubuntu's Active Directory Tool: Forged-Certificate Flaw Fixed in 0.16.3
LinuxSecurity
ADSys, the official tool for managing Ubuntu under Windows Active Directory, has a critical flaw (CVSS 9.0, CVE-2026-12249). Because certificate auto-enrollment ran over plain HTTP, an attacker on the network can make endpoints trust forged certificates, enabling interception and impersonation. Fixes are out for each Ubuntu release; update now.
2026.06.2323 views
News
Acer, Toshiba and More: A Secure Boot Hole That Never Gets Revoked
LinuxSecurityInfrastructure
PCs from several makers—Acer, ASUS, GIGABYTE, Toshiba and more—have a weakness that lets attackers slip past Secure Boot, the startup safety check (JVNVU#93024090). If abused, malware that survives an OS reinstall and evades antivirus can be planted deep in the machine. The attack needs admin rights or physical access; fix it with maker firmware updates and DBX updates.
2026.06.1942 views
News
Is SignalRGB Safe? Its Driver Flaws Are Fixed. What to Check Now
SecurityLinux
Two flaws in the kernel driver that SignalRGB installs — CVE-2026-8049, where any local user can reach admin-level hardware operations, and CVE-2026-8050, which can repeatedly crash the PC — were disclosed via JVN and CERT/CC. Both are local but usable for privilege escalation, and because the driver is signed it can be carried onto other machines as a BYOVD tool. WhirlwindFX fixed them in 1.3.6 / 1.3.7.0. Here is how to update and what to check.
2026.06.1856 views
News
A Flaw in Pi-hole Let Someone on Your Network Hijack the Admin Panel Without a Password — Fixed in v6.6.1
LinuxInfrastructureSecurity
A flaw in FTL, the core engine of Pi-hole, the ad blocker widely used in homes and offices (CVE-2026-44693, CVSS 8.8): a third party on the same network can flood it while an admin is active, steal the session ID, and hijack the admin panel without a password — enabling DNS rewrites and browsing-history access. It affects v6.0 to v6.6.0; update to v6.6.1 or later now.
2026.06.1133 views
News
Dracut's Network-Boot Flaw Lets a Rogue DHCP Server Hijack Linux at Boot; Patches Are Out
InfrastructureSecurityLinux
A flaw in Dracut, the tool that handles the boot entry point for much of the Linux world (CVE-2026-6893, CVSS 8.8): a rogue server on the same network can hijack a machine with root privileges the moment it boots, striking the defenseless earliest boot stage. It affects network-boot (PXE, etc.) setups. Apply each distro's update and isolate the network.
2026.06.1138 views