Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
Microsoft
WSL containers are generally available on Windows

Microsoft made WSL containers generally available and shipped the feature with controls that let administrators switch it off or limit where it pulls images from. WSL …

surveillance
Other users can watch your browsing and time your keystrokes through OS file notifications

Researchers at Graz University of Technology have used the file-notification systems in Windows, Linux, and macOS to spy on activity in other accounts. On Windows, a standard …

Gnome
GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection

GNOME 50.5, which the GNOME Release Team shipped on September 24, patches a CVE in the gvfs file system layer, a JavaScript injection flaw in the Epiphany web browser and a …

Ubuntu
Ubuntu kernel CVE fixes are moving to a weekly release schedule

Ubuntu kernels will ship every week under a new release schedule from Canonical, which is merging its four-week cycle for regular Stable Release Updates (SRUs) and its …

Gopass
Gopass: Open-source command-line password manager for teams

Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement …

Gnome
GNOME 51 adds passkey logins, offline maps and drawn PDF signatures

GNOME 51, the new version of the Linux desktop, came out on September 16 under the codename A Coruña. The release adds offline maps and live transit information to Maps, new …

Acronis
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)

A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by …

Debian
Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages

The Debian project shipped Debian 13.7 codenamed “trixie.” The project folded in 92 security advisories it had already published separately, added corrections to …

Ubuntu
Ubuntu 24.04.5 LTS release patches security bugs across ten flavors

Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release. Anyone …

Debian
Debian developers rejected an LLM ban and left disclosure voluntary

A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and …

OpenSSH
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5

Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether …

botnet
Tengu botnet reboots Linux devices to survive removal

A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools