Topic: software security
-
Notepad++ Updates Channel After Security Breach
Notepad++ has released a critical security update (version 8.9.2) to fix vulnerabilities in its update mechanism that were exploited to deliver malware, and users are urged to update immediately. The attack exploited unsigned update files and a lack of installer verification, allowing hackers to ...
Read More » -
GrapheneOS to Launch on Motorola Foldables Next Year
GrapheneOS will officially support Motorola smartphones starting in 2027, beginning with high-end flagships and later targeting foldable devices like the Razr Ultra. This delayed timeline is necessary because current Motorola hardware lacks mature security features like hardware memory tagging, r...
Read More » -
AI Bug Bounties Surge as Microsoft Pays Record, Apple Closes Door
Microsoft issued its largest bounty payment ever, signaling a shift toward rewarding high-impact AI-discovered flaws over submission volume. Apple capped individual bug submissions to reduce noise and focus on severe issues, prioritizing triage efficiency despite criticism from researchers. Googl...
Read More » -
DLSS 5 Swapper Brings Neural Rendering to Unsupported NVIDIA Games
The release of DLSS 5 Swapper has triggered intense community skepticism and security concerns, with reports identifying the tool as potential malware that was quarantined on Nexus Mods. Users experience significant performance degradation and visual artifacts in supported games, alongside suspic...
Read More » -
Linux Foundation's Akrites Launches in September
The Linux Foundation's Akrites initiative launches in September, accepting AI-powered vulnerability reports for open-source projects as a centralized security channel. The system uses AI to detect and categorize threats, aiming to streamline patching and reduce the burden on maintainers while acc...
Read More » -
UK Unveils Plan to Fortify Online Public Services
The UK government is investing £210 million to launch a Government Cyber Action Plan, establishing a central Government Cyber Unit to set mandatory security standards and coordinate incident response across the public sector. A key component is the creation of a Government Cyber Profession to dev...
Read More » -
Google Patches Actively Exploited Chrome Zero-Day Flaws
Google has urgently patched two actively exploited Chrome vulnerabilities (CVE-2026-3909 & CVE-2026-3910) and advises users to update immediately. The flaws involve an out-of-bounds write in the Skia graphics library and an inappropriate implementation in the V8 JavaScript engine, both posing ser...
Read More » -
cURL Ends Bug Bounties Amid AI-Generated Report Deluge
The cURL project is ending its vulnerability reward program due to an overwhelming volume of low-quality, often AI-generated bug reports, which have strained its small volunteer team and hindered efficient security review. The decision, driven by the need to protect the project's sustainability a...
Read More » -
Trump admin anti-DEI rules block Python security upgrade
The Python Software Foundation withdrew a major NSF grant application because new federal rules would have prohibited any DEI programming, which conflicted with its core mission and principles. This mirrors a similar case with The Carpentries, where a grant was pulled due to DEI-related content, ...
Read More » -
UK Unveils Major Plan to Fortify Public Sector Cybersecurity
The UK government is investing over £210 million in a new cybersecurity initiative, establishing a central Government Cyber Unit and mandating minimum security standards to protect essential public services. The strategy includes a public-private Software Security Ambassador Scheme and follows ne...
Read More » -
Microsoft Plans Major Overhaul: Replacing All C and C++ Code
Microsoft is undertaking a massive initiative to migrate its entire software infrastructure from C/C++ to the memory-safe language Rust by the end of the decade, aiming to enhance security by preventing common vulnerabilities. To achieve this, the company is developing advanced automated tools an...
Read More » -
Rising Cyber Threats Fuel Push for Economic Security Bill
A UK parliamentary committee report warns that the country's economic security is at risk due to vulnerabilities from foreign dependencies and inadequate defenses against threats like economic warfare. Cybersecurity is identified as a major concern, with the report emphasizing the need for strong...
Read More » -
Malware Contains Bugs That Defenders Can Exploit
Static analysis tools applied to 658 leaked malware samples revealed attackers' code is consistently riddled with severe flaws like buffer overflows, memory leaks, and use-after-free vulnerabilities. These embedded weaknesses allow cybersecurity defenders to actively exploit them, for example by ...
Read More » -
Leaked GTA IV Dev Kit Shows Unfinished Zombie Mode
A leaked development kit for a classic open-world game reveals significant cut content, including a fully functional but incomplete zombie survival mode that was ultimately scrapped. The leak also contains a trove of other abandoned assets, such as cut weapons and early cutscenes, showcasing the ...
Read More » -
iOS 26.4 Release Notes: What's New and Fixed
Apple has released the final beta versions of iOS 26.4 and iPadOS 26.4, indicating a public launch is imminent and detailing the update's new features. Apple Music receives major updates, including a beta feature to create playlists from text descriptions, a new Concerts hub, and offline song rec...
Read More » -
CISA Mandates Urgent Patch for Actively Exploited Gogs Flaw
A critical remote code execution flaw (CVE-2025-8110) in Gogs is being actively exploited, allowing attackers to run arbitrary commands by manipulating Git configuration files. CISA has mandated all federal agencies to patch the vulnerability by February 2026, as over 1,400 public Gogs servers ar...
Read More » -
Revive Your Old SD Cards: Smart New Uses
Booting from an SD card provides powerful troubleshooting and flexibility, starting by accessing your system's boot menu using a key like F2 or a model-specific combination. Within the boot menu or BIOS, you can select the SD card to start up, allowing for repairs like reformatting a drive or rol...
Read More »