DPRK-Linked Hackers Poisoned a Rust Crate With 245 Million Downloads
A North Korean-linked supply chain attack hit the Rust ecosystem on August 20, secretly embedding malware in three widely-used crates — triggered just by running cargo build. »
OpenAI Hits an Uncomfortable First: Astra Is Its Most Dangerous Model Yet
OpenAI has paused development of its next flagship AI model, Astra, after internal evaluations flagged it as the first to potentially reach Critical status under the company's own cybersecurity safety framework. »
Flatpak 1.18.1 Patches 10 Critical CVEs — Including a Full Sandbox Escape to Host
A critical update released August 11 fixes ten CVEs in Flatpak, including a complete sandbox escape (CVSS 9.3) that let any installed app read and write across the entire host filesystem. »
SCTPhantom: An 18-Year-Old Linux Kernel Bug Lets Attackers Get Root on Your System
CVE-2026-64564 has been lurking in the Linux kernel since 2007. It lets unprivileged users escalate to root and escape containers — patches are available now for all major distros. »
Six Linux Kernels Patched in One Day to Close a 16-Year-Old POSIX Timer Race Condition
Greg Kroah-Hartman coordinated six simultaneous LTS kernel releases on July 30, all fixing a use-after-free race in POSIX CPU timers that has been present in the kernel since around 2010. »