Aggregator
KDE gets over €1 million investment to strengthen security and core infrastructure
European governments and public institutions have been shifting away from proprietary software for years, and the financial infrastructure supporting open-source alternatives is growing to match. Germany’s Sovereign Tech Fund announced today that it is investing more than €1 million in KDE, the open-source project behind the Plasma desktop environment and a broad range of Linux software. The investment will go toward strengthening KDE’s testing infrastructure, security architecture, and the frameworks underpinning its communication services. KDE … More →
The post KDE gets over €1 million investment to strengthen security and core infrastructure appeared first on Help Net Security.
May 2026 Patch Tuesday: no zero-days but plenty to fix
Global Cyber Agencies Issue New SBOMs for AI Guidance to Tackle AI Supply Chain Risks
CVE-2016-8201 | Brocade Virtual Traffic Manager up to 11.0 cross-site request forgery (BID-95930)
CVE-2016-8204 | Brocade Network Advisor up to 14.0.2 FileReceiveServlet path traversal (BID-95695 / ID 800326)
CVE-2016-8205 | Brocade Network Advisor up to 14.0.2 DashboardFileReceiveServlet path traversal (BID-95694 / ID 800326)
CVE-2016-8206 | Brocade Network Advisor up to 14.0.2 SoftwareImageUpload path traversal (BID-95692 / ID 800326)
CVE-2016-8207 | Brocade Network Advisor up to 14.0.2 CliMonitorReportServlet path traversal (BID-95691 / ID 800326)
CVE-2017-2584 | Linux Kernel up to 4.9.3 arch/x86/kvm/emulate.c use after free (Nessus ID 97274 / ID 169712)
CVE-2017-5487 | WordPress 4.7.0 REST API class-wp-rest-users-controller.php information disclosure (EDB-41497 / Nessus ID 96606)
CVE-2017-5488 | WordPress up to 4.7.0 wp-admin/update-core.php name/version cross site scripting (EDB-40968 / Nessus ID 96606)
CVE-2017-5489 | WordPress 4.7.0 Flash File Upload cross-site request forgery (Nessus ID 96606 / ID 175955)
CVE-2017-5490 | WordPress up to 4.7.0 class-wp-theme.php cross site scripting (EDB-40968 / Nessus ID 96606)
CVE-2017-5491 | WordPress up to 4.7.0 wp-mail.php 7pk security (EDB-40968 / Nessus ID 96606)
Microsoft’s agentic security system found four critical Windows RCE flaws
Microsoft responded to growing competition in AI security by announcing that its new agentic security system helped researchers discover 16 new vulnerabilities in the Windows networking and authentication stack, including four critical remote code execution (RCE) vulnerabilities. MDASH architecture diagram (Source: Microsoft) Two of the four flaws — CVE-2026-40361 and CVE-2026-40364 — were deemed by Microsoft to be more likely to be exploited. The multi-model agentic scanning harness, codenamed MDASH, was built by Microsoft’s Autonomous … More →
The post Microsoft’s agentic security system found four critical Windows RCE flaws appeared first on Help Net Security.