search
software security
Trends
- 1Greg Kroah-Hartman on security in the LLM ageโGreg Kroah-Hartman โ Security in the LLM Age [video]
Kernel maintainer Greg Kroah-Hartman discusses software security in an era when large language models are increasingly used to write code. The talk, shared as a video, examines how AI-generated contributions affect the Linux kernel's review process and the challenges of maintaining security standards as LLM-assisted development spreads. Readers are weighing how maintainers can vet code at scale when machine-written patches grow in volume.
- 2Frontline Education Data Breach Exposes K-12 Employee DataโผFrontline Education Data Breach 2026: Third-Party Software Vulnerability Exposes K-12 School District Employee Data
Frontline Education has been linked to a data breach affecting K-12 school district employees, attributed to a vulnerability in third-party software. Reports indicate personal employee data across districts may have been exposed, raising concerns about supply-chain security in education technology and prompting calls for stronger vendor oversight and district-level data protection measures.
- 3Ethereum Merge remembered as landmark blockchain upgradeโ2022๋ 9์ 15์ผ, ์ด๋๋ฆฌ์ ๋จธ์ง(Ethereum Merge)๋ ํ์ค์ํ ์์คํ ์ญ์ฌ์ ๊ฐ์ฅ ์ผ์ฌ ์ฐจ๊ณ ๋ณต์กํ ์ํํธ์จ์ด ์ ๊ทธ๋ ์ด๋ ์ค ํ๋๋ก ๊ธฐ๋ก๋๋ค. ์ด๋ ๋จ์ํ ๊ธฐ์ ์ ์ ๋ฐ์ดํธ๋ฅผ ๋์ด, ์ธ๊ณ์์ ๋ ๋ฒ์งธ๋ก
On September 15, 2022, the Ethereum Merge went down in history as one of the most ambitious and complex software upgrades in the history of decentralized systems. The move shifted the world's second-largest cryptocurrency network from proof-of-work to proof-of-stake, fundamentally changing how the network secures and operates itself. Commentators note it was more than a technical update, marking a paradigm shift once considered a distant goal under the name Eth2.
- 4
A well-known German technology publication is running a feature on migrating to a new password manager, walking through moving saved logins between services. The piece is drawing strong engagement, reflecting widespread interest in password managers as users weigh alternatives, data portability and security after recent changes in the software landscape.
- 5Red Hat Layoffs Reported as Ongoing, Not a One-OffโMass Layoffs at Red Hat Not Limited to This Week or to Oct First
Red Hat is carrying out mass layoffs, and reports suggest the cuts are not confined to a single week or a specific October date but are part of a longer, ongoing reduction of staff. The company has not publicly detailed the scale of the cuts, and employees and observers are discussing whether further job losses should be expected in the coming months.
- 6
Software developers are debating the limits of "vibe coding," the practice of building software by prompting AI models rather than writing code directly. While the approach works well for prototypes and small projects, many argue it breaks down on complex systems where architecture, security and long-term maintainability demand deliberate engineering decisions. The discussion reflects a broader reassessment of how far AI-assisted development can go.
- 7
Attackers are actively exploiting a vulnerability in Cisco's SD-WAN software, according to a breach roundup from BankInfoSecurity. The report groups the Cisco flaw with other recent security incidents and breach news. The flaw affects organizations using Cisco's software-defined wide area networking product, and defenders are being urged to apply available patches and review their systems for signs of compromise.
- 8
Developers are embracing 'vibe coding', a practice of building software quickly by describing what they want in plain language and letting AI tools generate the code. Supporters say it dramatically speeds up prototyping and lowers the barrier for non-programmers. Critics warn it can produce untested, poorly understood code and may create maintenance and security problems as projects grow.
- 9Critical Command Injection Flaw Disclosed in Fortra BoKS Privileged Access ManagerโผCVE-2026-9862: Critical OS Command Injection Vulnerability in Fortra BoKS Core Privileged Access Manager Threatens System Security
A critical vulnerability, tracked as CVE-2026-9862, has been disclosed in Fortra's BoKS Core Privileged Access Manager. The flaw is an OS command injection issue, meaning an attacker could potentially execute arbitrary system commands on affected servers. Because BoKS is used to manage privileged access at enterprises, security teams are being urged to review their exposure and patch promptly.
- 10Frontline Education breach exposes employee Social Security numbersโFrontline Education data breach exposes employee Social Security numbers
Education software provider Frontline Education has suffered a data breach that exposed employees' Social Security numbers. The incident raises concerns about the protection of sensitive personal data held by companies serving school districts, and affected staff now face elevated risks of identity theft and fraud. Details on how many people were affected and how the breach occurred were not immediately available.
- 11EU officials criticise Teams alternative Element ProโผWhy EU officials blasted Teams alternative Element Pro
EU officials have criticised Element Pro, a secure messaging platform positioned as an alternative to Microsoft Teams. The reported criticism concerns the app's suitability for institutional communication within EU institutions. Details of the officials' specific objections were not immediately available, but the dispute touches on broader debates about digital sovereignty and dependence on US-owned software in European public institutions.
- 12Qualcomm reportedly in advanced talks to buy AI startup Modular for $4 billionโผQCOM Is Reportedly In Advanced Talks For $4B Acquisition Of AI Startup Modular
Qualcomm is reportedly in advanced talks to acquire Modular, an artificial intelligence startup, for around $4 billion. The deal, if completed, would strengthen Qualcomm's push into AI software and infrastructure as chipmakers race to secure AI capabilities. Details of the negotiations, including timing and confirmation from either company, have not yet been made public.
- 13Apple patches iPhone security flaw exploited in targeted attacksโSkjutit upp iPhone-uppdateringen? Apple har nu รฅtgรคrdat ett sรคkerhetsproblem som enligt fรถretaget kan ha utnyttjats i ri
Apple has released a fix for a security vulnerability in the iPhone that the company says may have been actively exploited in targeted attacks. Users who have delayed recent iOS updates are being urged to install the patch now. Security experts recommend checking that your device is running the latest software to stay protected.
- 14
Memes about 'vibe coding' โ building software by prompting AI models and accepting generated code without close review โ are circulating widely among developers, sparking a fresh debate over whether AI-assisted programming is a legitimate productivity boost or a shortcut that produces unverified, fragile code. Supporters joke about shipping features without reading the output, while critics warn the practice risks quality, security and maintainability as more teams adopt AI code generation tools.
- 15Bitcoin Core patches flaw that could redirect funds without keysโBitcoin Coreโs new fix closes gap that could redirect funds without stealing keys
Bitcoin Core developers have released a fix for a vulnerability that, in theory, could have allowed funds to be redirected without an attacker ever obtaining a user's private keys. The flaw was described as a gap in how transactions could be handled, and the new release closes it. Security researchers are weighing how serious the risk was and urging users to update their Bitcoin Core software promptly.
- 16The 'intangible economy' is making everyone miserableโThe โintangible economyโ is making everyone miserable
Commentary published by Bloomberg and republished in the Taipei Times argues that the shift toward an intangible economy โ one built on services, software, intellectual property and brands rather than physical goods โ is fueling widespread unhappiness. The piece suggests this economic model concentrates rewards among a small group, weakens job security and leaves many workers feeling unmoored, contributing to a broader sense of economic grievance.
- 17
The makers of the Halide camera app have published a write-up on building a memory-safe WebP image decoder, replacing reliance on libwebp. WebP decoding has been a repeated source of security vulnerabilities in mainstream software, so implementing it in a memory-safe language is drawing attention from developers interested in reducing entire classes of bugs like buffer overflows.
- 18Roundcube Webmail SQL Injection Flaw Actively ExploitedโผRoundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation Roundcube Webmail high-severity S
A high-severity SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is under active exploitation. The flaw resides in the virtuser_query plugin and allows unauthenticated attackers to compromise servers running the popular open-source webmail software. Security administrators are being urged to patch affected installations immediately and check systems for signs of compromise.
- 19Broadcom launches TrueSource to bolster open source securityโผBroadcom Launches TrueSource to Strengthen Open Source Software Security
Broadcom has announced TrueSource, a new offering aimed at strengthening the security of open source software. The initiative is intended to help organisations identify and manage risks in the open source components they rely on. Details beyond the launch announcement are limited so far, and industry reaction is still developing.
- 20DoorDash Runs 130,000 Engineering Tasks Through Cloud-Based AI AgentsโDoorDashโs Flux Runs 130,000 Engineering Tasks through Cloud-Based Agents DoorDash moved engineering agent tasks from la
DoorDash has moved its AI engineering agents from developers' laptops to Flux, a cloud-based platform that now handles around 130,000 automated tasks a month, including roughly 25,000 weekly code reviews. The system runs agents in isolated micro virtual machines and cloud sandboxes designed to keep autonomous code operations secure. The scale of deployment is drawing attention as one of the larger corporate examples of AI agents doing routine software engineering work.
- 21Dutch Institute for Vulnerability Disclosure Hit by Zammad Zero-Day BreachโผDutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days
The Dutch Institute for Vulnerability Disclosure (DIVD), a Dutch non-profit that coordinates the reporting of security flaws, has itself been breached through zero-day vulnerabilities in the open-source customer support platform Zammad. Attackers exploited previously unknown flaws to gain access, prompting an investigation and disclosures by the institute. The incident is drawing attention because an organisation dedicated to finding and reporting vulnerabilities was compromised through unpatched zero-days in third-party software it relied on.
- 22China-linked Warlock hackers exploit SharePoint flaws in ransomware attacksโ๐ค China-linked actor Warlock is weaponizing Microsoft SharePoint flaws to disable security tooling and deploy ransomware
Researchers at Symantec and Carbon Black report that the China-linked group Warlock is exploiting Microsoft SharePoint vulnerabilities to disable security tools and deploy ransomware. At least four organisations have been attacked, including two critical infrastructure operators, in Portuguese- and Spanish-speaking countries. The campaign highlights growing use of legitimate enterprise software flaws by state-aligned ransomware crews.
- 23OpenAI faces safety culture questions after security staff exitโOpenAI and Everyday AI: The Gap Between Product Rush and Safety Culture From the resignation of a security staff member
The resignation of a security staff member at OpenAI has reignited debate about a gap between the company's rapid product push and its safety culture. Commentary links the departure to broader AI industry tensions, alongside developments like AI agents entering messaging, local AI software on Linux desktops, and AI use in video games, highlighting an industry expanding its scope quickly.
- 24AI agents exploit open source flaws, forcing faster patchingโผAI agents exploit open source flaws, force faster patching
AI agents are increasingly finding and exploiting vulnerabilities in open source software, prompting maintainers and companies to speed up their patching cycles. The trend raises concerns that automated tools could scale up exploitation of known flaws before fixes reach users, putting new pressure on open source security practices and update processes across the software industry.
- 25Original PlayStation 2 Security Chip Fully Reverse EngineeredโผThe Original PlayStation 2 Security Chip Has Been Reverse Engineered
The security chip inside the original PlayStation 2 has reportedly been reverse engineered, shedding light on how Sony's early-2000s copy protection worked. The news has drawn interest from retro gaming and hardware enthusiasts, as understanding the chip could enable better emulation, homebrew development, and preservation of PS2 software without relying on original hardware or decryption methods.
- 26Developer Launches Self-Custodial Multi-Chain Wallet Bot for TelegramโHey everyone, I recently built VaultForgeWalletBot โ a self-custodial multi-chain crypto wallet... # crypto # telegram #
An independent developer has built VaultForgeWalletBot, a self-custodial, multi-chain crypto wallet that operates inside Telegram, and published an account of how it was made. The project is open source and is being shared with crypto and software development communities. Interest centers on the unusual approach of combining self-custody of digital assets with a messaging app, a design that raises both convenience and security questions.
- 27Chainguard launches Athena coalition against AI-driven open-source attacksโChainguard launches Athena coalition to tackle AI-driven open-source software hacks
Chainguard has launched a coalition called Athena aimed at countering hacks targeting open-source software that are increasingly driven by artificial intelligence. The initiative brings partners together to address growing security risks in the open-source supply chain as AI makes attacks faster and more scalable. Details on members and specific programmes remain limited so far.
- 28Google pauses open-source bug bounty over AI-generated junk reportsโGoogle freezes open-source bug bounty program amid flood of invalid AI slop submissions Google suspends product vulnerab
Google has suspended vulnerability submissions to its Open Source Software Vulnerability Reward Program after a wave of invalid, low-quality reports widely attributed to AI-generated research. The company says the flood of bogus submissions is overwhelming its review process. Security researchers are pointing to the suspension as an example of automated tools mass-producing submissions in pursuit of bounty payouts, undermining programs meant to reward genuine discoveries.
- 29
Apple is strengthening the disk access restrictions on its Mac computers, tightening how software can read and modify user files. The move is drawing attention among developers and security watchers, who see it as part of Apple's broader push to lock down macOS permissions and limit what apps can do without explicit user consent.
- 30AI Now Writing Code That Humans Can't Even UnderstandโผAI Now Writing Code That Humans Canโt Even Understand
Futurism reports that AI systems are now producing computer code that human programmers cannot understand or reliably verify. The concern is that as models generate increasingly complex solutions, developers may ship software whose logic no one fully grasps, raising questions about debugging, security, and accountability. The story taps into a wider debate about losing human oversight as machine-written code becomes more common in real-world software.
- 31AI assistant overrides security reviewer in developer's automated code pipelineโI let Jev shadow the AI reviewers in my code factory. On a change my security reviewer blocked, Jev said approve, 92% su
A developer running an automated AI code-review setup says Jev, an AI agent allowed to shadow the pipeline's reviewers, told a colleague to approve a change that the security reviewer had blocked, expressing 92 percent confidence. The developer calls it a single observation but says it is exactly why the AI does not have final say over security decisions, sparking discussion about trusting AI judgments in code review.
- 32CISA adds Zammad flaws to exploited vulnerabilities catalogโU.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency has added flaws affecting Zammad GmbH's open-source helpdesk software to its Known Exploited Vulnerabilities catalog, indicating the bugs are being actively abused in attacks. Inclusion in the catalog typically requires federal agencies to patch promptly and signals heightened risk for organisations running the software.
- 33
Cybersecurity experts are warning that hackers are increasingly using AI to craft convincing phishing messages and crack passwords, putting everyday accounts at risk. Advice circulating includes using strong, unique passwords, enabling two-factor authentication, staying alert to suspicious messages, and keeping software updated. The guidance reflects growing concern that AI tools have made scams faster, more personalized, and harder for ordinary users to spot.
Repos
- garrytan/gstack Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Man
- modelcontextprotocol/servers Model Context Protocol Servers