Cybersecurity

Python Backdoor DEEP#DOOR Exploits Tunneling Service to Exfiltrate Browser and Cloud Credentials

New Python backdoor DEEP#DOOR uses a legitimate tunneling service to steal browser and cloud credentials, evading traditional defenses.

Cybersecurity

Massive Cyber Security Alert: SMS Blasting, Medical Data Flaws, and Roblox Accounts Under Attack – Over 25 Threats Revealed

Breaking: Fake cell towers spread SMS scams, critical OpenEMR flaws expose patient data, and 600K Roblox accounts hacked. Experts urge immediate action.

Cybersecurity

Critical Supply Chain Attack Compromises PyTorch Lightning and Intercom-client Packages for Credential Theft

Two major Python packages, PyTorch Lightning and Intercom-client, were hit in a supply chain attack that published malicious versions to steal credentials. Security firms urge immediate action.

Digital Marketing

Supply Chain Attack Uses Poisoned Ruby Gems and Go Modules to Steal Credentials via CI Pipelines

Attackers use poisoned Ruby gems and Go modules to steal credentials via CI pipelines, attributed to BufferZoneCorp GitHub account.

Cybersecurity

Cracking Down on Cyber Complicity: Two IT Security Advisors Sentenced to 4 Years for BlackCat Ransomware Role

Two cybersecurity professionals sentenced to 4 years for deploying BlackCat ransomware in 2023 attacks.

Cybersecurity

MSPs Miss Cybersecurity Revenue Windfall as Sales Strategy Lags Behind Booming Market

MSPs lose revenue due to five sales challenges despite cybersecurity market doubling to $69B by 2030. Experts urge strategy shift.

Cybersecurity

Urgent: New China-Aligned Cyber Espionage Campaign Hits Asian Governments, NATO State, and Journalists

China-linked SHADOW-EARTH-053 campaign targets Asian governments, a NATO state, and journalists. Trend Micro reports sophisticated espionage with custom malware.

Cybersecurity

New Cybercrime Syndicates Unleash Fast-Paced Vishing and SSO Attacks Against SaaS Platforms

Two cybercrime groups, Cordial Spider and Snarky Spider, are using vishing and SSO abuse for rapid SaaS extortion attacks, leaving minimal traces.

Cybersecurity

Massive Facebook Account Heist: Over 30,000 Compromised in New Google AppSheet Phishing Scheme

A Vietnamese-linked group stole over 30k Facebook accounts via Google AppSheet phishing, selling them on an illicit storefront.

Cybersecurity

Trellix Source Code Breach: Unauthorized Repository Access Confirmed, Forensic Investigation Underway

Trellix confirms unauthorized access to its source code repository. Forensic experts and law enforcement involved. Implications for customers and security industry.

Programming

Python’s Packaging Community Establishes Formal Governance Council

Python's Packaging Council, approved via PEP 772, brings formal governance to packaging standards and tools. Five elected members will oversee decisions, with first election in June 2026.

Cybersecurity

Critical Linux Kernel Bug Allows Arbitrary Page Cache Writes via AEAD Sockets

Xint discovered a Linux kernel bug (since 2017) enabling arbitrary 4-byte writes to page cache via AEAD sockets and splice. Fixed in mainline.

Linux & DevOps

Highlights from the LWN.net Weekly Edition: April 30, 2026

Explore the latest LWN.net Weekly Edition covering Famfs filesystem, Python Packaging Council, Zig concurrency, Linux pages/folios, Strawberry music manager, 7.1 kernel merge window, and briefs.

Linux & DevOps

Critical Security Patches Issued Across Major Linux Distributions This Thursday

Thursday's security updates from AlmaLinux, Debian, Fedora, Red Hat, SUSE, and Ubuntu address vulnerabilities in numerous packages including browsers, containers, and system tools.

Cybersecurity

Latest Linux Stable Kernels Address Critical AEAD Socket Vulnerability

Greg Kroah-Hartman released seven new stable kernels. Two specialize in Xen fixes; five address the critical AEAD socket vulnerability. All users of affected series must upgrade.

Web Development

GCC 16.1 Brings C++20 Default, Experimental C++26 Features, and a New Algol68 Frontend

GCC 16.1 is released with C++20 as default, experimental C++26 features (reflection, contracts, expansion statements, std::simd), a new experimental Algol68 frontend, and HTML diagnostic output.

Programming

When Specs Aren't Enough: The Clash Between Linux Kernel's Restartable Sequences and Google's TCMalloc

Linux kernel's restartable sequences optimization in 6.19 breaks Google's TCMalloc due to undocumented dependencies, illustrating Hyrum's Law. The no-regressions rule forces a compromise, highlighting API design lessons.

Open Source

How Version-Controlled Databases Leverage Prolly Trees for Efficient Data Management

Explore how Prolly trees, a variant of B-trees, enable efficient version control in databases, focusing on Dolt's implementation for branching, merging, and historical queries.

Open Source

The NHS’s Open Source Crackdown: A Misguided Response to AI Security Threats?

The UK's NHS plans to close most open source repositories due to AI security scanning tools, but critics argue it's unnecessary and contradicts open government principles.

Technology

10 Crucial Dates for Ubuntu 26.10 Stonking Stingray: Plan Your Upgrade

Ubuntu 26.10 Stonking Stingray releases Oct 15, 2026. Key dates: feature freeze Aug 10, beta Oct 3, RC Oct 10. Plan your upgrade with this 10-point guide.

Explore More

Comprehensive Guide to This Week's Critical Security Patches Across Major Linux DistributionsWhy Session Timeouts Create Hidden Accessibility Hurdles for Web UsersLululemon Faces Crisis as New CEO Pick Triggers Stock Plunge and Founder BacklashTrump Picks New Surgeon General Nominee, Abandons RFK Ally Casey MeansCloud Cost Optimization Principles Endure as AI Workloads Reshape Spending Strategies