ZeroHour

Search: “package manager”

4 stories in the last 7d

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages

Debian 13.7 'trixie' point release bundles 92 security advisories and 106 package updates, including kernel, glibc, u-boot and qemu fixes.

Debian shipped version 13.7 of 'trixie', folding in 92 previously published security advisories and corrections to 106 source packages, including six Linux kernel advisories (DSA-6381, DSA-6393, DSA-6405, DSA-6415, DSA-6466, DSA-6477). glibc fixes a buffer overflow (CVE-2026-5928) and buffer underflow (CVE-2026-5450), with 17 packages rebuilt against the updated library; qemu carries 25 CVEs including a secure boot bypass (CVE-2026-16288), imagemagick 24, wolfssl 15 and perl 13. Boot-chain fixes include a u-boot FIT image verification bypass (CVE-2026-46728), a BOOTP/DHCP buffer overread (CVE-2024-42040), and corrected intermediate certificate verification in sbsigntool. The installer was rebuilt with kernel ABI 6.12.107+deb13, and existing systems receive the fixes through normal package mirror updates.

Dell security advisory (AV26-934)

Canadian Cyber Centre relays Dell advisories covering vulnerabilities in Networking OS10, OpenManage Server Administrator, ECS, ObjectScale, DUP, Wyse Management Suite, and Repository Manager.

The Canadian Centre for Cyber Security advisory AV26-934 relays six Dell security advisories (DSA-2026-343, 403, 393, 417, 387, 419) covering vulnerabilities across Dell Networking OS10, OpenManage Server Administrator, Elastic Cloud Storage, ObjectScale, DUP Framework, Wyse Management Suite, and Repository Manager. Affected versions include OS10 prior to 10.6.1.3, ECS and ObjectScale prior to 4.4.0.0, and DUP Framework prior to 26.07.03. Administrators are urged to review Dell's advisories and apply updates; no exploitation is reported.

Canadian Centre for Cyber Security · 18h agoAdvisory

Windows 11 24H2 Home and Pro reach end of support in October

Microsoft ends security updates for Windows 11 24H2 Home and Pro on October 13, 2026, urging users to upgrade to Windows 11 25H2.

Microsoft confirmed that Windows 11 24H2 Home and Pro editions and Windows 10 Enterprise LTSB 2016 reach end of updates on October 13, 2026, after which they stop receiving monthly security and preview updates. Windows 11 24H2 Enterprise and Education editions remain supported until October 2027, and unmanaged Home/Pro devices will automatically upgrade to Windows 11 25H2. Separately, Windows Server 2022 moves from mainstream to extended support on October 13, 2026, running until October 14, 2031.

BleepingComputerupdated · 1h agofirst · 1d agoAdvisory 3 sources1

From guidance to action: Security fundamentals that materially reduce risk

Microsoft expands Secure Now guidance, detailing AI-agent incidents, Storm-2945 CaptiveCrunch DNS hijacks, and Teams IT-support impersonation attack paths.

Microsoft's Security Exposure Management blog outlines three observed attack paths: OpenAI agents reaching production systems via shared Hugging Face infrastructure, Storm-2945 (Midnight Blizzard subcluster) redirecting hospitality network traffic into device-code phishing and fake updates in the CaptiveCrunch campaign, and attackers impersonating IT support over Teams to deploy MSI payloads via PowerShell and pivot through WinRM. Microsoft promotes Secure Now recommendations covering identity governance, agent isolation, phishing-resistant authentication, and Zero Trust controls.

Microsoft Security Blog · 21h agoAdvisory1