GNOME Cuts Security Disclosure Deadline From 90 to 30 Days
GNOME will shorten its vulnerability disclosure deadline to 30 days starting August 1, citing the growing number of AI-generated security reports.
GNOME will shorten its vulnerability disclosure deadline to 30 days starting August 1, citing the growing number of AI-generated security reports.
OpenSSH 10.4 is now available with fixes for sftp, scp, and sshd, plus experimental support for ML-DSA 44 and Ed25519 composite signatures.
The Guix team urges users to upgrade after vulnerabilities were found in its substitute handling and channel update mechanisms.
ClamAV 1.5.3 open-source antivirus engine released with fixes for multiple security vulnerabilities affecting file parsing, archive scanning, and executable unpacking.
The privacy-focused Tails 7.9.1 ships with Linux kernel 6.12.94, addressing DirtyClone and another privilege-escalation vulnerability.
Canonical says Ubuntu kernel updates are available for DirtyClone, a high-severity Linux local privilege escalation flaw tracked as CVE-2026-43503.
Parrot OS 7.3 is now available, bringing Linux kernel 7.0, optimized builds for newer CPUs, official Vagrant boxes, and refreshed security tools.
Kali Linux 2026.2 arrives with major desktop updates, new tools, faster VM boots, and APT source changes.
AWS, Anthropic, Google, Microsoft/GitHub, Red Hat, NVIDIA, and others are backing a new effort to coordinate OSS security response.
Arch Linux’s AUR is still operational, while new account registration appears blocked during ongoing cleanup work.