LIVE · cybersecurity feed
Live wire
Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsEven with OT network visibility, critical infrastructure operators struggle with legacy equipmentASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-Day
vulnerability

OpenSSH 10.6 enables a post-quantum signature algorithm, so experimental keys need replacing

The OpenSSH project released version 10.6 on October 6, introducing a new hybrid post-quantum signature algorithm and addressing several security vulnerabilities. The maintainers indicated that future releases may occur more frequently to expedite bug fixes, noting a rise in security reports, many identified with the assistance of AI models.

ZeroDay News ·

Source: Help Net Security

The OpenSSH project released version 10.6 on October 6, introducing a new hybrid post-quantum signature algorithm and addressing several security vulnerabilities. The maintainers indicated that future releases may occur more frequently to expedite bug fixes, noting a rise in security reports, many identified with the assistance of AI models.

A significant change in OpenSSH 10.6 is the enablement of the `ssh-mldsa44-ed25519` hybrid post-quantum signature algorithm. Users who previously generated experimental keys using earlier support for this algorithm are advised to regenerate or remove them.

The new release also disables the LZ77 dictionary coder for both the `sshd` server and `ssh` client, making the `Compression` option less effective. This change addresses an attack vector where an adversary controlling input on one channel could potentially recover secrets from another, due to all channels in a session sharing a single compression dictionary. The maintainers recommend using application-level compression, which they state is generally more effective and not susceptible to this particular attack.

To prevent potential shell injection, `ssh` now rejects command-line usernames that contain a dollar sign (`$`) or backslash (`\`). This mitigation aims to prevent untrusted input from being injected into a shell context via features like `ProxyCommand` or `Match exec`. Usernames defined using the `User` directive in configuration files are not affected by this restriction.

Other security enhancements include `sshd` now storing GSSAPI credentials only after successful authentication, preventing the persistence and potential exposure of credentials from failed attempts. The `sftp` client has also been updated to validate server-returned paths more strictly, closing a vulnerability where a malicious server could direct a recursive copy operation outside its intended target directory.

A bug in `ssh-keygen` related to Daylight Saving Time has been fixed, which previously could cause certificate expiry times to be off by up to two hours in certain time zones, such as Antarctica/Troll.

For specific platforms like QNX 6, SCO OpenServer 5, and builds compiled with `disable-fd-passing`, the post-authentication process retains root privileges. Consequently, `GatewayPorts` and `StreamLocalForwarding` are now disabled on these platforms. The project stated that support for these platforms might be removed in the future if a suitable alternative is not found.

vulnerabilitypatchai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Android’s October 2026 Updates Patch 25 Vulnerabilities

Android’s October 2026 security updates have addressed a total of 25 vulnerabilities across the platform. Among these, a critical flaw within Android’s System component has been highlighted, which could potentially allow for privilege escalation on affected devices. The updates are designed to enhance the overall security posture of Android devices by resolving these identified weaknesses.

vulnerabilitycritical

Atlassian Patches Critical Vulnerability Affecting 8 Products

Atlassian has released patches for a critical vulnerability impacting eight of its products. The flaw, if exploited, could allow unauthenticated attackers to gain access to specific files located within the web application's root directory. This type of access could potentially expose sensitive configuration or application data, depending on the contents of the accessible files.

vulnerability

Automation, AI agents or people? Sorting out who handles each security finding

A recent survey of 200 senior security and technology leaders reveals significant concerns about the escalating complexity of software security programs, particularly in the wake of increased AI adoption. Over half of the respondents, primarily from companies with 10,000 or more employees, anticipate struggles in simplifying their security operations if current practices persist.

CVE-2026-93524

Check your X.Org server version because a dozen vulnerabilities have been patched

X.Org has released patches for a dozen security vulnerabilities affecting its X server and Xwayland components, with updates available in versions xorg-server 21.1.25 and xwayland-24.1.14. Nine of these flaws are critical, potentially allowing for arbitrary code execution, while the remaining three could lead to server crashes or information disclosure.

ai

AI Agent Gateway: Open-source tool keeps credentials out of agent configs

Tuskira has released AI Agent Gateway, an open-source tool designed to enhance the security of AI agent deployments by centralizing credential management and access control. The gateway operates as an intermediary between AI agents and the services they interact with, including both tool servers (referred to as MCP tools) for platforms like GitHub and Jira, and various large language model…

nation-state

AI endpoint management: Visibility, compliance, and remediation

Organizations today face a growing challenge in managing their endpoint estates, which are expanding rapidly due to factors like hybrid work models, increased cloud adoption, and the use of contractor devices. This expansion, coupled with a constant stream of new Common Vulnerabilities and Exposures (CVEs) and escalating compliance demands, often overwhelms security teams. Manual tracking and…