UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern" logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory (ex: $HOME/.bash_history). They suffer of multiple problems:

A recent report highlighted the limitations of traditional shell history logging mechanisms in UNIX-like systems, specifically focusing on the challenges they present for forensic analysis. While these operating systems are generally robust in logging various activities across different locations, the logging of shell commands themselves often falls short of modern forensic requirements.
The core issue identified is the prevalent use of flat files, such as $HOME/.bash_history, for storing command history. These files, while functional for user convenience, suffer from several inherent problems when viewed from a forensic perspective. The simplicity of their structure and storage can make it difficult to ascertain the full context of commands executed.
One significant limitation of these flat-file histories is their susceptibility to manipulation or deletion. An attacker or malicious insider could easily modify or clear these files to cover their tracks, making it challenging for investigators to reconstruct a timeline of events. Furthermore, these files often lack crucial metadata, such as timestamps for individual commands, the user who executed them, or the working directory at the time of execution.
The absence of detailed metadata severely hampers forensic investigations. Without precise timestamps, it's difficult to correlate shell activity with other system logs or network events. The lack of user context can be problematic in multi-user environments, and the absence of working directory information can obscure the true impact or intent of certain commands, especially those involving file system operations.
Products designed to enhance shell history, such as Atuin, aim to address these shortcomings by providing more robust and forensically sound logging capabilities. These tools typically offer features like encrypted history, synchronization across devices, and richer metadata capture, including timestamps and potentially other contextual information.
For organizations, mitigating the risks associated with inadequate shell logging often involves implementing centralized logging solutions that can ingest and correlate shell history with other security events. This might include deploying enhanced shell history tools, configuring auditd or similar system auditing frameworks, and ensuring that logs are immutable and stored securely off-host. Regular log review and the use of Security Information and Event Management (SIEM) systems are also critical.
The ongoing evolution of threat landscapes necessitates a corresponding advancement in forensic capabilities. The focus on improving shell history logging reflects a broader industry trend towards enhancing visibility into user activity, particularly at the command-line level, which remains a primary interface for system interaction and, consequently, a common vector for malicious operations.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed