Related Threat Clusters
-
Critical RCE Vulnerability in Rails Active Storage Disclosed
On July 29, 2026, the Ruby on Rails security team published CVE-2026-66066, a critical arbitrary file read and remote code execution (RCE) vulnerability in Active Storage. Discovered by the Ethiack research team, this…
16 articles · Updated July 30, 2026 -
Critical NGINX Vulnerability CVE-2026-42945 Exposes Millions to RCE and DoS Attacks
A critical vulnerability, CVE-2026-42945, has been discovered in the NGINX web server's ngx_http_rewrite_module, allowing unauthenticated attackers to execute remote code or crash servers. This heap-based buffer…
51 articles · Updated May 13, 2026 -
Supply Chain Attack Compromises DAEMON Tools with Malicious Backdoor
A supply chain attack has compromised the DAEMON Tools software installers, which began on April 8, 2026. Kaspersky identified that these trojanized installers, signed with legitimate digital certificates, have affected…
26 articles · Updated May 5, 2026 -
Critical OpenSSL Vulnerabilities Affect Multiple Ubuntu Versions
Recent updates to OpenSSL have revealed multiple vulnerabilities affecting various Ubuntu LTS versions. CVE-2026-2673, discovered by Viktor Dukhovni, involves incorrect negotiation of key exchange groups in TLS 1.3…
2 articles · Updated April 9, 2026 -
Critical GnuTLS Vulnerabilities Affecting Ubuntu Systems
Multiple vulnerabilities in GnuTLS have been identified, primarily affecting Ubuntu 18.04 LTS and 20.04 LTS. A timing side-channel vulnerability (CVE-2024-0553) could allow remote attackers to recover sensitive…
6 articles · Updated July 6, 2026 -
Critical Authlib Vulnerabilities Discovered in Ubuntu Affecting JWT and CSRF
Multiple vulnerabilities were identified in the Authlib library used in Ubuntu systems, specifically affecting versions 24.04 LTS and 26.04 LTS. Discovered by researchers Jay Neiva, Mauro Carrillo, and Johnny Deuss,…
2 articles · Updated July 16, 2026 -
Critical Python Vulnerabilities Affect Multiple Versions
Recent security updates for Python 3.10, 3.12, and 3.15 address critical vulnerabilities impacting various systems. Key vulnerabilities include CVE-2026-1502, which allows HTTP header injection, and CVE-2026-6100, which…
11 articles · Updated April 20, 2026 -
Critical ldns Vulnerability in Ubuntu Allows Spoofed DNS Responses
A vulnerability in the ldns library affects Ubuntu systems, allowing remote attackers to inject arbitrary DNS responses due to improper validation of DNS responses when used as a stub resolver over UDP. Discovered by…
2 articles · Updated June 18, 2026 -
Multiple rlottie Vulnerabilities Lead to Denial of Service Risks
On July 20, 2026, Ubuntu released USN-8559-1 addressing multiple vulnerabilities in the rlottie library, which is used for rendering vector-based animations. The vulnerabilities, identified as CVE-2026-10305,…
2 articles · Updated July 20, 2026 -
Critical Januscape Vulnerability in Linux KVM Exposes Cloud Servers to Attacks
A critical vulnerability in Linux KVM, named Januscape (CVE-2026-53359), has been discovered after lying dormant for 16 years. This flaw allows attackers with root access in a guest virtual machine to escape to the host…
31 articles · Updated July 7, 2026
Recent Intelligence Reports
- Ubuntu 26.04 LTS OpenZFS Key Admin Access Bypass 8705-1 CVE-2026 — Linuxsecurity · August 31, 2026
- Ubuntu 26.04 LTS MySQL Important Security Issues USN-8700 — Linuxsecurity · August 31, 2026
- Ubuntu WebKitGTK Important XSS and DoS Vulnerabilities USN-8703 — Linuxsecurity · August 31, 2026
- Ubuntu FreeRDP Vulnerabilities and Security Concerns USN-8698 — Linuxsecurity · August 31, 2026
- Ubuntu 26.04 GNU Core Utilities Critical DoS Issues USN-8697 — Linuxsecurity · August 31, 2026
- USN-8702-1: util — Ubuntu · August 31, 2026
- USN-8700-1: MySQL vulnerabilities — Ubuntu · August 31, 2026
- USN-8698-1: FreeRDP vulnerabilities — Ubuntu · August 31, 2026