Daily feed
Today in security.
The last seven days from every source RedPatch watches — vendors, government CERTs and the security press. Refreshed every morning and evening; if a source is down you see its last good copy, never a blank.
Everything · 120 items
- perl-GD-SecurityImage-1.75-22.fc43Fedora security updates (Bodhi) · Oct 11
- perl-GD-SecurityImage-1.75-23.fc44Fedora security updates (Bodhi) · Oct 11
- perl-GD-SecurityImage-1.75-24.fc45Fedora security updates (Bodhi) · Oct 11
- Internal files add to evidence of an ExxonMobil climate deception campaignHacker News · Oct 11
- Nippon Columbia malware incident exposes 8.6 million karaoke fan recordsBleepingComputer · Oct 11
- Open-Source Microsoft Office Excel, PowerPoint, and Word ReplicationsHacker News · Oct 11
- Terence Tao: Math 2.0 [pdf]Hacker News · Oct 11
- perl-Net-Whois-Raw-2.99.044-1.fc45Fedora security updates (Bodhi) · Oct 11
- perl-Net-Whois-Raw-2.99.044-1.fc43Fedora security updates (Bodhi) · Oct 11
- perl-Net-Whois-Raw-2.99.044-1.fc44Fedora security updates (Bodhi) · Oct 11
- mkvtoolnix-96.0-2.fc43Fedora security updates (Bodhi) · Oct 11
- libebml-1.4.7-1.fc44 libmatroska-1.7.2-1.fc44 mkvtoolnix-102.0-1.fc44Fedora security updates (Bodhi) · Oct 11
- The tilde in your PATH may not be your HOMEHacker News · Oct 11
- Valen's Memory Safety: A New Kind of Borrow CheckingHacker News · Oct 11
- Show HN: BetterWispr – Free, open-source dictation for MacHacker News · Oct 11
- Weave (YC W25) is hiring ML, AI, product, & design engineersHacker News · Oct 11
- perl-Net-IDN-Encode-2.502-1.fc45Fedora security updates (Bodhi) · Oct 11
- perl-Net-IDN-Encode-2.502-1.fc44Fedora security updates (Bodhi) · Oct 11
- perl-Net-IDN-Encode-2.502-1.fc43Fedora security updates (Bodhi) · Oct 11
- I paid people to try and follow my READMEHacker News · Oct 11
- rclone-1.75.2-2.el9Fedora security updates (Bodhi) · Oct 11
- Nitter: Update Oct 10th seeking funding and legal helpHacker News · Oct 11
- IRCv3Hacker News · Oct 11
- rclone-1.75.2-1.fc45Fedora security updates (Bodhi) · Oct 11
- xapian-bindings-1.4.32-1.fc46 xapian-core-1.4.32-1.fc46Fedora security updates (Bodhi) · Oct 11
- 3rd Yandex Cloud Data Center Was HitHacker News · Oct 11
- LineageOS 24.0Hacker News · Oct 11
- ImageMagick-7.1.2.33-1.fc44Fedora security updates (Bodhi) · Oct 11
- ImageMagick-7.1.2.33-1.fc45Fedora security updates (Bodhi) · Oct 11
- ImageMagick-7.1.2.33-1.fc43Fedora security updates (Bodhi) · Oct 11
- ImageMagick-7.1.2.33-1.fc46Fedora security updates (Bodhi) · Oct 11
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote CommandsThe Hacker News · Oct 11
- PSPi 6 – Raspberry Pi in a PSPHacker News · Oct 10
- Build your own decision modelHacker News · Oct 10
- libheif-1.23.6-1.fc43Fedora security updates (Bodhi) · Oct 10
- libheif-1.23.6-1.el10_4Fedora security updates (Bodhi) · Oct 10
- A city-building game in which the city would prefer you didn'tHacker News · Oct 10
- Knuth reward checkHacker News · Oct 10
- Cyber exec arrested in case allegedly tied to ShinyHunters hackersBleepingComputer · Oct 10
- ARTEX AI, Claude agents used in cyberattacks on South Korean banksBleepingComputer · Oct 10
- Criminal IP Introduces AITEM as the Next Evolution of Attack Surface ManagementBleepingComputer · Oct 10
- AI Is Getting Really Good at Messing With CybercriminalsWIRED Security · Oct 10
- The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn'tThe Hacker News · Oct 10
- Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in PrisonSecurityWeek · Oct 10
- Talorys – A self-hosted personal AI agent on Cloudflare's free tierHacker News · Oct 10
- When Ldaxr Doesn't Work: Exclusive Accesses and Cacheability on AArch64Hacker News · Oct 10
- Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsThe Hacker News · Oct 10
- Why TLP should not replace your internal information classification, (Sat, Oct 10th)SANS Internet Storm Center · Oct 10
- GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API CredentialsGBHackers · Oct 10
- Iranian VPN-over-DNS Activity Generates 40 Billion DNS Observations During Military ConflictGBHackers · Oct 10
- DarkBlinders Hackers Use Fake Meeting App to Deploy Backdoor and Steal Government DataGBHackers · Oct 10
- Two AhsayCBS Zero-Day Vulnerabilities Actively Exploited to Take Over Backup ServersGBHackers · Oct 10
- Hackers Use AI Agents and GodPotato Exploit to Gain Windows SYSTEM PrivilegesGBHackers · Oct 10
- Rat's Register AllocatorHacker News · Oct 10
- AWS Bedrock AgentCore Flaw Allowed Attackers to Hijack AI Agents Using a Single PromptGBHackers · Oct 10
- The Lightbulb ComputerHacker News · Oct 10
- The RAM shortage is bringing back DDR4Hacker News · Oct 9
- FBI Arrests Executive at Ransomware Negotiation FirmKrebs on Security · Oct 9
- DSA-6550-1 ghostscript - security updateDebian Security Advisories (DSA) · Oct 9
- OpenAI Fires 3 Safety Researchers in Dispute Over AI RisksSecurityWeek · Oct 9
- Microsoft 365 incident readiness for Microsoft Engage CenterWindows Release Health · Oct 9
- ASOS Breach Reveals the Risks in Customer-Facing SaaSDark Reading · Oct 9
- Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksBleepingComputer · Oct 9
- Friday Squid Blogging: I Caught a SquidSchneier on Security · Oct 9
- AI Scramble Drives Cybersecurity M&A BoomDark Reading · Oct 9
- Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of RepositoriesThe Hacker News · Oct 9
- Japan confirms arrest of Russian Qilin operative, extradition to GermanyThe Record · Oct 9
- Rolling the Root KeyHacker News · Oct 9
- FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal HackThe Hacker News · Oct 9
- Windows 11, version 26H1 known issues and notificationsWindows Release Health · Oct 9
- Windows 11, version 23H2 known issues and notificationsWindows Release Health · Oct 9
- What We Missed: FBI Strikes Back at ShinyHuntersDark Reading · Oct 9
- Unpatched AhsayCBS flaws exploited to deploy webshells, mine cryptoBleepingComputer · Oct 9
- FBI arrests another suspected ShinyHunters hacker after agency breachBleepingComputer · Oct 9
- Security Threats Don't Stop at the Office: Why Executives' Families Need Training, TooDark Reading · Oct 9
- Hundreds of thousands impacted by data breach at biosensor firm iRhythmThe Record · Oct 9
- Leader of vast money mule operation that laundered cybercriminal proceeds pleads guiltyThe Record · Oct 9
- FBI touts another ShinyHunters arrest in response to data breachThe Record · Oct 9
- Germany arrests alleged core Qilin ransomware member after extraditionBleepingComputer · Oct 9
- Five months treating bugs like patients and coding agents like a medical teamHacker News · Oct 9
- Wikimedia Says Rogue AI Agents Abused its PlatformsInfosecurity Magazine · Oct 9
- Belarusian hacktivists admit to 2023 breach of Russian state healthcare networkThe Record · Oct 9
- RHSA-2026:79786: Important: kernel security updateRed Hat Security Advisories (RHSA) · Oct 9
- How to keep AI agents within their permissionsBleepingComputer · Oct 9
- CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-68875 Windows NTFS Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-68878 Windows Fast FAT Driver Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69281 Windows License Manager Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69337 Windows Registry Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69451 Windows Management Instrumentation Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69582 Windows Volume Manager Extension Driver Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69693 Windows Device Association Broker Service Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69732 Windows Link Layer Topology Discovery Protocol Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-72979 Windows DHCP Server Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-72982 Windows Netlogon Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-68880 Windows Win32k Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69277 Microsoft Local Security Authority (LSA) Server Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69301 Windows Win32k Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69322 Microsoft Windows Search Component Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69324 Windows Performance Monitor Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69340 Windows NTFS Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69385 Windows TCP/IP Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69433 Windows Error Reporting Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69571 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69566 Windows NTFS Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69688 Windows Encrypting File System (EFS) Elevation of Privilege VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-72987 Windows DNS Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-73006 DirectWrite Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9
- CVE-2026-69598 Windows iSCSI Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9
- TP-Link Sued by Four More U.S. States Over Router Security and China TiesThe Hacker News · Oct 9
- Social Engineering AI Agents: The New BEC for 2026Dark Reading · Oct 9
- Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root AccessThe Hacker News · Oct 9
- Anthropic Launches Free AI Vulnerability Scanner for Open-Source ProjectsThe Hacker News · Oct 9
- Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft EdgeThe Hacker News · Oct 9
- Max severity SonicWall SMA1000 flaw now exploited in attacksBleepingComputer · Oct 9
- React Server Components Vulnerability Lets Attackers Freeze Next.js Servers With a Single RequestGBHackers · Oct 9
- Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal AgenciesThe Hacker News · Oct 9
- In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 YearsSecurityWeek · Oct 9
- Q3 2026 Sets New Record for Ransomware AttacksInfosecurity Magazine · Oct 9
- USN-8911-1: Linux kernel (OEM) vulnerabilitiesUbuntu Security Notices (USN) · Oct 9