Topic: system administration

  • SystemRescue 13 Upgrades to Linux 6.18 LTS, Adds Recovery Tools

    SystemRescue 13 Upgrades to Linux 6.18 LTS, Adds Recovery Tools

    SystemRescue 13, a major bootable Linux recovery environment, has launched with a core architecture upgrade and an expanded toolset for data rescue and system repair. A key update is the shift to the modern, stable Linux 6.18 LTS kernel, improving hardware support, security, and performance for r...

    Read More »
  • Exploit Code Released for Critical BIND 9 DNS Vulnerability

    Exploit Code Released for Critical BIND 9 DNS Vulnerability

    A critical security flaw (CVE-2025-40778) in BIND 9 DNS resolvers allows remote cache poisoning, enabling attackers to redirect users to malicious sites or spread malware without authentication. The vulnerability affects recursive DNS servers and authoritative servers with recursion enabled, with...

    Read More »
  • Microsoft Patches Critical Zero-Day Exploits

    Microsoft Patches Critical Zero-Day Exploits

    Microsoft's latest security update patches 79 vulnerabilities, including two publicly disclosed zero-day exploits, requiring urgent attention from IT teams. One critical zero-day (CVE-2026-21262) is a high-severity privilege escalation flaw in SQL Server, posing a risk to exposed instances, while...

    Read More »
  • Ubuntu Kernel CVE Fixes Shift to Weekly Release Schedule

    Ubuntu Kernel CVE Fixes Shift to Weekly Release Schedule

    Ubuntu is shifting to a weekly kernel release schedule by merging standard updates and critical security patches into a staggered, continuous cycle. This structural change allows system administrators to receive new packages every seven days for faster vulnerability remediation. The accelerated t...

    Read More »
  • Bastion: Open-Source Access Control for Complex Infrastructure

    Bastion: Open-Source Access Control for Complex Infrastructure

    The Bastion is an open-source project that centralizes and secures SSH access to infrastructure by acting as a hardened entry point, simplifying credential management and enabling controlled, auditable workflows. It enhances security with strong authentication methods like TOTP and Yubico PIV key...

    Read More »
  • Synology Reverses Drive Limits on New NAS Models

    Synology Reverses Drive Limits on New NAS Models

    Synology has reversed its restrictive drive compatibility policy on several new NAS models, moving away from a strategy that pushed users toward its more expensive branded drives and allowing for greater hardware flexibility and cost savings. Previously, using non-verified drives triggered system...

    Read More »
  • Sudo on Windows 11: More Useful Than You Think

    Sudo on Windows 11: More Useful Than You Think

    Windows 11 now includes a native `sudo` command, allowing users to run terminal commands with administrative privileges directly from their current window, streamlining workflows for developers and power users. The feature is enabled in Settings and offers configuration modes, including an inline...

    Read More »
  • Urgent CISA Alert: Active Attacks Exploit Critical CentOS Bug

    Urgent CISA Alert: Active Attacks Exploit Critical CentOS Bug

    A critical security flaw (CVE-2025-48703) in CentOS Web Panel allows unauthenticated attackers to execute arbitrary commands, prompting CISA to issue an urgent patch-or-discontinue directive by November 25. The vulnerability stems from improper handling of the 'changePerm' endpoint and unsanitize...

    Read More »
  • Urgent CISA Alert: Active Attacks Exploit Critical Linux Sudo Flaw

    Urgent CISA Alert: Active Attacks Exploit Critical Linux Sudo Flaw

    A critical vulnerability (CVE-2025-32463) in Linux sudo versions 1.9.14 to 1.9.17 allows local attackers to escalate privileges to root using the -R option, even without sudoers file authorization. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known E...

    Read More »
  • Cisco warns of critical Unified CM flaw with exploit code

    Cisco warns of critical Unified CM flaw with exploit code

    Cisco has released patches for a critical vulnerability (CVE-2026-20230) in its Unified Communications Manager (Unified CM) that allows unauthenticated attackers to achieve root privileges via low-complexity SSRF attacks, with public proof-of-concept exploit code available. The flaw is only explo...

    Read More »