Gemini Breached Three Outside Systems, and Claude-Using Researchers Breached OpenAI
“Software security researchers used Anthropic’s Claude AI platform to hack OpenAI’s ChatGPT tool,” reports CBS News.
Using Claude, “On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts,” write researchers at security platform Hacktron AI. “With these ac … ⌘ Read more
Rust Issues Warning Over Key Developers Being Targeted For Compromise
The Rust security response working group and Crates.io team have issued a warning that a targeted attack is underway against key Rust programming language developers… ⌘ Read more
AMD Preparing Linux For Enhanced SMT Protection “ESMTP” For EPYC VMs
AMD engineers today sent out patches on the Linux kernel mailing list for beginning to enable Enhanced SMT Protection “ESMTP” for better security with virtual machines running atop EPYC server processors with SEV-SNP… ⌘ Read more
Rustls 0.23.45 Released To Fix Two Year Old Security Issue
While the Rustls modern TLS library is written in the Rust programming language with a focus on memory safety, as we’ve seen out of other Rust project re-implementations in the past, the new implementations can lead to other security bugs of their own. Out today is Rustls 0.23.45 to fix a security issue introduced back in 2024 with Rustls while the likes of OpenSSL, BoringSSL, and others are unaffected… ⌘ Read more
Should US Open-Weight AI Labs ‘Distill’ Frontier Models Too?
Silicon Valley giants and national security experts “are calling for action against Chinese companies engaged in model distillation,” reports CNBC. But “I would do nothing,” says Y Combinator CEO Garry Tan. “We could argue that there should be an American distillation regime.”
Distillation is the process of using the outputs of a more capable AI model to t … ⌘ Read more
California’s Gig Drivers Just Secured Collective Bargaining Power with Newly Certified Union
A union representing Uber and Lyft drivers was just certified by California’s Public Employment Relations Board, officially recognizing them as the drivers’ bargaining organization.
The Sacramento Bee reports that this new bargaining structure :
The move will allow the California Gig Workers … ⌘ Read more
Anthropic CEO Dario Amodei Calls For AI Slowdown
An anonymous reader quotes a report from The New York Times: The chief executive of Anthropic called for a global slowdown of artificial intelligence development in a 3,800-word essay on Saturday, just days after one of the company’s employees quit over concerns about the safety of the technology. Dario Amodei, who co-founded Anthropic to focus on securely and carefully building A.I … ⌘ Read more
Debian 13.7 Released With Many Bug Fixes
For those wanting the freshest Debian 13 “Trixie” install media, Debian 13.7 is out today in bundling up all the latest bug and security fixes… ⌘ Read more
Altman Considers Slowing Down AI Development
Bloomberg reports (paywalled) that Sam Altman told OpenAI employees the company is open to slowing the pace of AI development alongside other leading labs as concerns grow over increasingly capable systems and recent incidents in which models escaped human control. OpenAI has already paused development once this year for security work and is now pushing for mandatory U.S. AI safety requirem … ⌘ Read more
Android Rolling Out Passkey Transfers Between Password Managers
Android is rolling out a system-level way to securely transfer passwords and passkeys between credential managers, eliminating the need to export passwords as unencrypted text files or manually recreate passkeys. The feature initially supports Google Password Manager, 1Password, Bitwarden, and Dashlane, with other providers able to integrate through … ⌘ Read more
Microsoft Breaks Another Patch Tuesday Record
Microsoft’s September 2026 Patch Tuesday is its largest ever, fixing a record 966 vulnerabilities, including 105 rated critical and two zero-days already being exploited in attacks. BleepingComputer reports: This Patch Tuesday addresses 105 “Critical” vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security fea … ⌘ Read more
FreeBSD 14.5 Released With Hardware Support Improvements, Many Bug & Security Fixes
For those that haven’t yet made the move to FreeBSD 15 with still relying on FreeBSD 14 in production, out today is FreeBSD 14.5-RELEASE… ⌘ Read more
Linux Preps For New AMD Zen 6 BTB CTX Isolation Security Feature
A recently posted Linux kernel patch has revealed a new security improvement with Zen 6 processors… ⌘ Read more
Rustls 0.23.44 Released With ML-DSA Certificates Enabled By Default
Rustls as the modern TLS library implementation written in the Rust programming language is out with a new feature release. This morning’s Rustls 0.23.44 release enables post-quantum secure ML-DSA certificates by default… ⌘ Read more
OpenAI Agents Hijacked a German Wiki to Discuss Ways to Escape Their Sandbox
Citing researchers published Friday, Ars Technica writes that AI agents “posted 18,000 messages to a public wiki that discussed ways for other agents to bypass security sandbox restrictions.”
Reuters attributes the discussion to “a swarm of rogue OpenAI agents” that “hijacked a German website this spring and transformed it into … ⌘ Read more
Linux 7.3 Now Disabling RandStruct Security Feature By Default If Rust Support Present
While Rust programming language use may help with memory safety and other security advantages, the default Linux kernel configuration is now losing randomization of sensitive kernel structures if Rust support is present… ⌘ Read more
NVIDIA-Started Open Secure AI Alliance Moves To The Linux Foundation
Earlier this year NVIDIA led an effort with more than two dozen other companies to launch the Open Secure AI Alliance with a focus on keeping open-source AI models secure. The Open Secure AI Alliance today is transitioning from being stewarded by NVIDIA to becoming a Linux Foundation project… ⌘ Read more
Broadcom Pledges to Lock Down Open Source Python, Java Libraries
Broadcom is launching “TrueSource,” an effort to curate and secure open-source components used with its Tanzu platform, including Spring, RabbitMQ, and libraries across Java, Python, and Node.js. “The idea is to provide a set of solutions focused on providing clean and secure artefacts,” Purnima Padmanabhan, vice president of Broadcom’s Tanzu Divisi … ⌘ Read more
Citrix Adds a Linux-Powered Escape Hatch For Compromised Windows PCs
Citrix’s Desktop as a Service (DaaS) product includes a lightweight, hardened second operating system called UniconOS (once called “eLux”) to offer Windows customers a write-protected file system Citrix says is secure against computer viruses and other malware. Nerds.xyz reports:
According to the company, the environment remains isolated f … ⌘ Read more
FreeBSD 14.5-RC1 Released With Several Security Fixes
Ahead of FreeBSD 14.5-RELEASE hopefully debuting on 8 September, FreeBSD 14.5-RC1 is out today as the final scheduled development release… ⌘ Read more
AppArmor In Linux 7.3 Adds Support For User-Space Compressed Policies
The AppArmor improvements have been merged for Linux 7.3 for this kernel security module providing per-program Linux application security controls around system resources. Most notable this cycle is being able to load user-space compressed policies… ⌘ Read more
New AF_ALG Restrictions With Linux 7.3 Due To The Security & Maintenance Nightmare
The past few Linux kernel cycles have chipped away at AF_ALG functionality for that interface for user-space programs to access the kernel’s internal cryptography API. Linux has been dropping AF_ALG features like zero-copy support and offloading. AF_ALG was quickly deprecated in Linux 7.2 while now for Linux 7.3 it’s being further restricted… ⌘ Read more
Iran-linked Cyberattackers Shut Down a UK Power Plant for Four Days
“Iran shut down a British power plant for four days in an unprecedented cyber attack,” reports the Telegraph.
More details from the BBC:
The government said that at no point was there a risk to the UK’s energy system, but the Department for Energy Security and Net Zero (DESNZ) has contacted power companies to advise them about the risk of … ⌘ Read more
Slovakia Finds Russian Backdoor In Traffic Speed Cameras
Slovakia acquired speed cameras to modernize its traffic control– but there was a surprise. Tom’s Hardware cites this story from the Risky Bulletin Newsletter:
Unfortunately, the country’s national security service, the NBU, has discovered that the cameras have multiple security issues. Firstly, they have SMS-activated Russian backdoors. Secondly, live camera f … ⌘ Read more
Linux 7.3 Input Subsystem Updates Merged With Security Fixes, Other Improvements
The big set of input subsystem updates were merged earlier this week for the Linux 7.3 cycle. It’s a random assortment of different improvements as well as bug/security fixes driven in part by the flow of AI/LLM generated discoveries… ⌘ Read more
Specially Crafted NTFS File-System Image Allows Root Access On Linux With NTFS3 Driver
A reported security vulnerability for the NTFS3 driver has gone unaddressed since being reported earlier this summer. The vulnerability allows a pre-crafted NTFS image on a USB flash drive or similar to allow the user to gain root access to the running Linux system… ⌘ Read more
China Joins Europe In Scrapping Windows For Linux
An anonymous reader quotes a report from ZDNet: According to a Bloomberg report, attributed to China’s Ministry of State Security, the country has ordered some government agencies to drop Windows 10 China Government Edition for Chinese-made Linux distributions. Why not Windows 11? Because China, like many other non-US governments, no longer trusts American companies with the … ⌘ Read more
Linux 7.3 Cleans Up Stack Randomization, Ensures It Happen As Early As Possible
Merged this week for the Linux 7.3 kernel was a big clean-up to the stack randomization code for better security on Linux systems and helping unify some of the architecture-specific code… ⌘ Read more
Voxel game creation platform Luanti (formerly Minetest) gets basic gamepad support, security fixes
Luanti (formerly Minetest) is a popular free and open source voxel game creation platform, with the latest release 5.17.0 out now and it’s an important one.
Read the full article on [GamingOnLinux](https://www.gamingonlinux.com/2026/08/voxel-gam … ⌘ Read more
Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
Security researcher Jeremiah Fowler found that people-search service ClarityCheck left more than 9 million image files accessible in an unsecured Amazon S3 bucket, despite advertising its reverse-image search as “private and secure.” A separate misconfiguration also exposed email addresses, phone numbers, and other personal information. Wired … ⌘ Read more
AMD GAIA 0.23 Delivers Ability To Install/Run AI Agents From The Terminal
AMD’s GAIA open-source AI software built atop Lemonade for serving as an AI companion for emails, a Bash coding agent, and other AI agent skills is out with a new version today with more features while also improving security and making other improvements… ⌘ Read more
KDE, Techpaladin & Kubuntu Focus Announce The Bullet-Proof KDE Software Initiative
KDE e.V. along with Linux PC vendor Kubuntu Focus and KDE-aligned consulting firm Techpaladin Software have announced a collaboration of the “bullet-proof KDE Software initiative” for providing at least three years of bug fixes and security updates to KDE Plasma 6.6 LTS and related software… ⌘ Read more
Make sure your Flatpak is up to date due to security issues
Version 1.18.1 and 1.19.0 pre-release rolled out for Flatpak, due to some security issues that were found so it’s an essential update for all Linux systems.
Read the full article on GamingOnLinux. ⌘ Read more
Microsoft’s Azure Linux 3.0.20260809 Ships With 233+ CVE Fixes
While Microsoft continues working on Azure Linux 4.0 as its overhauled Linux distribution built atop Fedora, Azure Linux 3.0 remains the current stable production series. Released overnight was Azure Linux 3.0.20260809 and it comes with more than 233 security patches for recent CVEs in the AI era… ⌘ Read more
Rsync 3.5 Released As “Extraordinary” Update To Fix 33 Security Issues
Rsync as the widely-used, open-source remote sync software for synchronizing files and directories across networks is out today with a very important update… ⌘ Read more
DEF CON Crowd Suspected In Fake-Hotspot Attack On Delta Flight
An anonymous reader quotes a report from Ars Technica: On Monday, passengers aboard Delta flight 591 going from Las Vegas to Atlanta allegedly spoofed the onboard Wi-Fi, raising the attention of federal law enforcement. The incident came one day after the DEF CON security conference concluded in Las Vegas, and was first described on social media acc … ⌘ Read more
Intel CPU Microcode 20260811 Release Fixes Eight Security Issues
Intel today published their 20260811 CPU microcode updates to fix a variety of issues for exciting processors, including shipping the first new microcode images for Bartlett Lake and Wildcat Lake. The new microcode updates stretch back to Intel Core Gen10 processors… ⌘ Read more
Flatpak 1.19 Released With Nine Security Fixes
Flatpak 1.19 was released today as a new development release along with the Flatpak 1.18.1 stable point release. Both of these releases ship a number of newly-discovered security issues with this app sandboxing and distribution tech… ⌘ Read more
The Roboguard Revolution Is Short-Circuiting
alternative_right shares a report from 404 Media: Robotics companies promise that video-camera-toting security robots can deter and detect crime. But many companies are rethinking the approach after a trail of canceled contracts and questions about whether the artificial intelligence-powered bots are meeting the needs of businesses and local governments. Proof News found evidence … ⌘ Read more
Cyber Vulnerability Sweep Picks Up Royal Navy Drones Sending Data To China
A routine security assessment found that cameras aboard Royal Navy Kraken unmanned surface vessels were sending “heartbeat” signals to an IP address in China. “A thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally,” said a Ministry of Defense spokesperson. “Our … ⌘ Read more
Old SGI Drivers Being Removed In Linux 7.3 Over Security Concerns
On top of various other Linux drivers for old hardware being removed due to noise generated by AI/LLM coding agents, there are more examples coming with Linux 7.3 as some old Silicon Graphics (SGI) drivers are being removed from the mainline Linux kernel over security concerns… ⌘ Read more
OpenAI Announces It’s Enhancing Security Controls, Pausing Some Work for New AI Model Astra
OpenAI announced Friday it’s pausing work on its Astra AI model because of security concerns. The Guardian reports:
The company had evaluated the agent, Astra, and found “significant advancements in agentic coding and cybersecurity”, which had moved to a “critical” threshold… OpenAI stated that … ⌘ Read more
FreeBSD 14.5 Beta 1 Released With Various Backports, Security Fixes
For those still on the FreeBSD 14 N-1 stable series rather than the latest FreeBSD 15 series, FreeBSD 14.5 is working toward release to deliver various security fixes and backports… ⌘ Read more
‘Asimov Was Right’ About Rules For Robots, Says Ex-US Cyber Director
Former U.S. National Cyber Director Chris Inglis says the biggest AI risk isn’t sentience but autonomy. “What I’m worried about is that they get to choose what and where they do something, and under what rules they do it,” he said, citing recent cases of AI agents from OpenAI, Anthropic, and Meta escaping security sandboxes. He argues develope … ⌘ Read more
Meta AI Hacked External Systems During Cybersecurity Testing
wiredmikey shares a report from SecurityWeek: Meta is the latest major AI developer to admit that its models broke loose during cybersecurity testing and hacked external systems. The tech giant said in a statement to the media on Wednesday that the incident occurred during independent evaluations conducted by Israeli AI security startup Irregular. The test … ⌘ Read more
Linux Accidentally Left Legacy I/O & Memory Handlers Open In Kernel Lockdown Mode
For nearly the past decade has been the kernel lockdown mode for tightening up kernel access from user-space such as when UEFI Secure Boot is enabled. The kernel lockdown mode restricts PCI BAR access, no writing to /dev/mem, and other restrictions so user-space can’t can’t modify the running kernel or access sensitive kernel memory. An oversight has allowed legacy I/O and memory interfaces via sysfs to remain open in lockdown m … ⌘ Read more
Linux Wireless Maintainer Takes Firm Stance Against AI/LLM Generated Slop Patches
In addition to the Linux kernel staging area now rejecting AI/LLM-generated patches except for real security fixes, the Linux wireless networking code is also seeing some shifts around how it will deal with AI/LLM generated patches… ⌘ Read more
Rust Coreutils 0.10 Released With More Security Hardening, Increased GNU Compatibility
Rust Coreutils 0.10 is out today from the uutils project for this alternative to GNU Coreutils. Rust Coreutils 0.10 development focused on additional security hardening plus also increasing the GNU test suite compatibility and robustness… ⌘ Read more
Anthropic’s AI Used Fake Identities, Malware In Rogue Attack On GitHub Project
An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents – the most serious case arising when Anthropic’s Mythos 5 model attempted to insert malicious code into an open source software application and created fake identitie … ⌘ Read more
Apple’s ‘Private Relay’ Is Exposing Users’ Real IP Addresses
Security researchers found that Apple’s iCloud Private Relay can expose users’ real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. “In short: any website that supports, or pretends to support, passkeys can see the user’s real IP address despite having iCloud Private Relay on,” security … ⌘ Read more