Malwarebytes 5.7.2.358 / 5.27.1.4191 released

Published by Thokk Veen Rahl 0

Malwarebytes has released version 5.7.2.358 of its software, along with an update to version 5.27.1.4191. This comprehensive antivirus solution is designed to shield users from various threats, including malware, ransomware, exploits, and harmful websites and applications. The software is accessible to users of all levels, featuring a user-friendly interface that allows even novices to easily perform scans and remove detected threats.

Linux Security Roundup: 44 Red Hat Advisories and 62 Firefox Fixes

Published by Xaren Lysander Valtor 0

The latest Linux security updates include a significant number of advisories, with Red Hat issuing 44 advisories marking its largest batch for 2026, primarily addressing important vulnerabilities. SUSE followed closely behind with a massive security sweep, fixing around 206 vulnerabilities, including 62 related to Firefox, while Ubuntu focused on kernel updates that tackle privilege escalation flaws. Debian also released notable fixes, particularly for roundcube and Rails, which addressed serious webmail and application vulnerabilities. Administrators across various distributions are advised to prioritize kernel, browser, and SSH patches based on their severity ratings to mitigate risks effectively

X.Org Patches Twelve CVEs in X Server and Xwayland Security Update

Published by Xaren Lysander Valtor 0

X.Org has released twelve security patches addressing vulnerabilities in xorg-server 21.1.25, the standalone 26.1.0 release candidate 26.0.99.903, and xwayland 24.1.14. The vulnerabilities include serious issues such as double frees, use-after-frees, and heap overflows, which can be exploited by compromised local applications to take control of the session or access sensitive information. Users on various operating systems, including Debian, Ubuntu, and Windows, are advised to update their systems promptly, particularly those operating multi-user hardware. The release highlights ongoing security improvements in the X server, reinforcing the need for regular updates to mitigate potential risks

Fort Firewall 3.20.1 Released: New Filter Simulator, Command-Line Control, and Driver Fixes

Published by Xaren Lysander Valtor 0

Fort Firewall has released version 3.20.1, introducing a new Filter Simulator that clarifies the decision-making process for allowed or blocked connections, which can be accessed directly from the Connections window. This patch also enhances command-line control with new verbs and fixes a bug that preserved wildcard program paths when a regular entry was removed. The update focuses on improving automation and usability, with changes such as splitting the Statistics window into Traffic and Connections, and allowing installation or removal of the Windows Service from a non-elevated UI. Despite being a donation-funded, one-person project, Fort Firewall competes well against other firewalls with its unique features and commitment to regular updates

Linux Security Roundup: Firefox ESR (62 CVEs), Chromium (32 CVEs), Debian, Fedora, RHEL and openSUSE Fixes

Published by Xaren Lysander Valtor 0

This week's Linux security updates include significant patches from major distributions like Debian, Fedora, RHEL, and openSUSE, with notable attention on Firefox ESR and Chromium, which report 62 and 32 CVEs respectively. Debian addressed a critical zero-day vulnerability in FreeCAD that could allow arbitrary code execution, while also updating the Linux kernel and PHP with various fixes. Fedora's updates include security patches for Chromium and Python, alongside a more extensive list of vulnerabilities across other packages. Red Hat focused on RHEL 8 with important updates for sudo and the kernel, while openSUSE highlighted the need for Firefox ESR updates due to a backlog of vulnerabilities

Linux Security Roundup: Ubuntu's 101-CVE Kernel and a Critical freerdp Fix

Published by Xaren Lysander Valtor 0

Ubuntu recently released a significant kernel update containing 101 CVEs for its Google Container Engine image, impacting 38 subsystems, which appears to address a backlog rather than an immediate crisis. Red Hat and Rocky Linux both flagged a Critical freerdp fix, while Debian issued a large 62-CVE patch for Firefox ESR, along with advisories for redis and webkit2gtk. Fedora and SUSE also provided updates, including important fixes for WordPress and OpenSSL vulnerabilities, while AlmaLinux and Rocky Linux focused on essential patches. Users are advised to prioritize Critical and high-severity fixes before moving on to Important and Moderate updates during their maintenance windows

OWASP CRS v4.30.0 and v4.25.2 LTS Ship Three Critical WAF Bypass Fixes

Published by Xaren Lysander Valtor 0

The OWASP Core Rule Set (CRS) released versions v4.30.0 and v4.25.2 (LTS) on October 2, 2026, which included three critical fixes for web application firewall (WAF) bypass vulnerabilities. These updates addressed issues related to path-based command injection in RCE rules, a case-sensitivity bug in charset allow-lists, and a multipart charset shadowing trick that could allow attackers to bypass encoding checks. In addition to the security fixes, v4.30.0 introduced new detection capabilities for various tools and command usages, while also repairing a response-skipping flag that previously affected rule evaluations. Users of affected versions are advised to upgrade promptly or apply specific workarounds outlined in the advisories to mitigate the identified vulnerabilities

Linux Security Roundup: WebKit and Chromium Flood with Hundreds of CVEs Across 8 Distro Updates

Published by Xaren Lysander Valtor 0

Today's Linux security updates have resulted in a significant number of CVEs, particularly affecting browser engines like WebKit and Chromium, with Debian reporting 232 CVEs in one advisory and SUSE claiming 302 in a kernel update, which largely pertains to build headers. Major distros have pushed updates addressing vulnerabilities in Chromium, Thunderbird, and Firefox, emphasizing the importance of applying these fixes promptly to avoid potential exploitation via malicious webpages or emails. Critical updates include SUSE's Tomcat/libtcnative patch, Red Hat's Satellite 6.19.5, and Oracle's FreeIPA roll, while many CVEs listed are inflated due to upstream releases being backported. Users are advised to prioritize patching WebKit and Chromium vulnerabilities first and to schedule maintenance for the remaining important items in their systems

Linux Security Roundup: Thunderbird, Firefox-ESR, and Python Fixes

Published by Xaren Lysander Valtor 0

A significant wave of Linux security patches has been released across multiple distributions, including Debian, Fedora, Ubuntu, Red Hat, Rocky, Slackware, and SUSE, with a focus on Mozilla's Thunderbird and Firefox-ESR, which account for a large number of the reported vulnerabilities. Debian alone has issued updates for 62 CVEs in Firefox-ESR and 44 in Thunderbird, while security fixes for Python's query string parser could potentially break systems relying on semicolons for separation. Other notable updates include critical patches for OpenSSL and various kernel vulnerabilities, particularly affecting server-side applications that utilize PHP or handle email through Thunderbird. Administrators are advised to prioritize these updates, especially those related to OpenSSL and the major Mozilla updates, while also ensuring proper management of any potential application breakage due to the changes in the Python parser

GridinSoft Anti-Malware 5.0.30 released

Published by Xaren Lysander Valtor 0

GridinSoft Anti-Malware has recently released its version 5.0.30, enhancing its capability to tackle PC threats such as adware, malware, and potentially unwanted programs (PUPs). This software allows users to effectively remove these threats, ensuring their systems are safeguarded against various virus and malware attacks.

Linux Security Roundup: CVEs in Debian and Ubuntu Kernels, RHEL Sends 27 Errata

Published by Xaren Lysander Valtor 0

The latest Linux security updates encompass a range of distributions, with significant vulnerabilities identified in Debian, Ubuntu, and Red Hat systems. Debian's kernel update introduces hundreds of CVEs, while Ubuntu addresses critical flaws in its Oracle kernel alongside numerous other vulnerabilities. Red Hat issued 27 errata, including a critical kernel update for NVIDIA, and critical vulnerabilities were also reported for FreeIPA and PostgreSQL in Rocky Linux. Users are urged to prioritize applying the most critical patches, especially for FreeIPA updates on AlmaLinux and Rocky Linux 10, and to ensure their systems are up-to-date with kernel updates across various distributions

OpenSSL 4.0.3 Releases 14 Security Fixes Across QUIC, DTLS and SM2

Published by Xaren Lysander Valtor 0

OpenSSL 4.0.3 has been released, addressing 14 vulnerabilities related to QUIC, DTLS, X.509 certificate handling, and the SM2 cryptographic suite, with the most severe flaw rated as High. Notable issues include an AES-SIV authentication error that could misreport tampered data and a base64 encoding bug that may lead to truncated output. The release highlights significant themes, particularly the prevalence of QUIC vulnerabilities and recurring timing side-channel issues in cryptographic operations. OpenSSL is rapidly evolving, with a final release of version 4.1 expected soon, which will include DTLS 1.3 support and a commitment to regular major updates every two years

Linux Security Roundup: SUSE Kernel, rsync, and Exim CVEs

Published by Xaren Lysander Valtor 0

The latest Linux security roundup highlights significant updates, with SUSE releasing a kernel patch addressing 133 CVEs, while Debian and Ubuntu also rolled out important updates for rsync, dovecot, and Exim, among others. Notably, vulnerabilities in Slackware's groff and pcre2 libraries remind us of long-standing security issues, some dating back decades, while AlmaLinux and Oracle Linux also issued multiple security advisories for essential packages. Users of Fedora and Rocky Linux should prioritize updates for Chromium and Ruby, respectively, due to their critical vulnerabilities. Administrators are advised to carefully assess the advisory tables and apply the necessary patches, keeping in mind that some updates may require system reboots

Linux Security Roundup: Red Hat Flags 3 Critical CVEs, Ubuntu PyJWT Fix Ships

Published by Xaren Lysander Valtor 0

Linux distributions, including Red Hat, Ubuntu, Debian, Fedora, Rocky Linux, and SUSE, have recently released security updates addressing various vulnerabilities, with Red Hat highlighting three critical advisories, particularly for the unbound DNS resolver and Red Hat Identity Management. Ubuntu's PyJWT update fixes five CVEs, including a significant signature-bypass vulnerability that could allow token forgery. Debian's updates cover multiple packages, with a focus on libheif, which has several CVEs related to untrusted file processing. Users are advised to prioritize patching critical vulnerabilities, particularly those related to DNS resolution and token forgery, before addressing the rest of the updates

Linux Security Roundup: Unbound Criticals and a Chromium Flood Across Six Distros

Published by Xaren Lysander Valtor 0

Six Linux distributions have released important security updates, primarily addressing critical vulnerabilities in the DNS resolver Unbound and various web browsers. Unbound has received critical ratings due to remote code execution and DNSSEC flaws, while browsers including Firefox, Thunderbird, and Chromium have been updated to fix numerous vulnerabilities related to use-after-free and privilege escalation bugs. The security updates across AlmaLinux, Debian, Fedora, RHEL, Rocky Linux, and SUSE include a significant focus on patching these critical issues, with recommendations to prioritize updating DNS resolvers and browsers first. Additional advisories cover various packages, including fixes for other software vulnerabilities and maintenance issues, emphasizing the need for administrators to apply these updates promptly to secure their systems

Linux Security Roundup: Unbound, Chromium, and WebkitGTK Lead the List

Published by Xaren Lysander Valtor 0

A recent wave of security advisories has highlighted critical vulnerabilities across various Linux distributions, particularly focusing on the unbound DNS resolver, which poses a severe remote code execution risk. Fedora's webkitgtk upgrade also addresses numerous CVEs, including hundreds from ANGLE and Skia, emphasizing the importance of patching these components first if they are in use. Other distributions like AlmaLinux, RHEL, and SUSE have also reported similar vulnerabilities, urging users to prioritize updates for critical packages. Overall, system administrators are advised to apply these patches promptly, especially for the unbound and Chromium-related updates, to mitigate potential security threats

Avira Phantom VPN 2.47.1 released

Published by Kalyx Tib Veenor 0

Avira Phantom VPN version 2.47.1 has been released, offering users a straightforward solution for concealing their internet traffic and enhancing online privacy. This VPN service is particularly beneficial when connecting to unsecured Wi-Fi hotspots in public spaces, ensuring that users' data remains secure.

Linux Security Roundup: 58-CVE Chromium, Critical unbound DNS, and Ubuntu apology

Published by Xaren Lysander Valtor 0

The latest Linux security roundup highlights significant updates across eight distributions, particularly noting Fedora's release of a Chromium update addressing 58 CVEs and critical fixes for the unbound DNS resolver in Red Hat and Rocky Linux. Other notable updates include critical patches for the Ansible Automation Platform and a rare apology from Ubuntu for a regression in its earlier XDG Desktop Portal fix. The roundup also mentions various updates for Firefox, PostgreSQL, and the container toolchain, with varying patch efforts across the distributions. Overall, the updates reflect a mix of critical vulnerabilities and routine maintenance patches, emphasizing the importance of timely updates to maintain security across Linux systems

Wireshark 4.6.9 and 4.4.19 Release Patches 35 Vulnerabilities Across Stable and Old Stable Lines

Published by Xaren Lysander Valtor 0

Wireshark has released two security updates, versions 4.6.9 and 4.4.19, which address at least 35 vulnerabilities across its current and older stable lines. The updates primarily fix local crashes triggered by opening crafted capture files, but some vulnerabilities can be exploited remotely and may lead to remote code execution (RCE). The fixes include common parser errors such as integer overflows and out-of-bounds reads, with notable contributions from several security researchers. Users are advised to update both installations while ensuring the integrity of the signed packages prior to installation

Linux Security Roundup: Browsers and SSH Bugs Dominate

Published by Xaren Lysander Valtor 0

The latest Linux security updates are heavily focused on browser-related vulnerabilities, with significant fixes for Chromium and Firefox, which have introduced 58 and 73 CVEs respectively. OpenSSH, curl, and sudo advisories are also prevalent across various distributions, necessitating patching efforts for those who manage multiple systems. Other notable updates include kernel patches for RHEL and Ubuntu, which require reboots after installation due to ABI changes that impact third-party modules. Overall, users are advised to prioritize browser and OpenSSH updates, followed by curl, sudo, and PostgreSQL fixes, while ensuring they follow the specific update protocols for their respective Linux distributions