FR
live
archive

All articles

GITHUB_TOKEN gains a dedicated read permission for Dependabot alerts

In early August 2026, GitHub shipped a vulnerability-alerts: read permission that lets the CI token query Dependabot alerts without an over-privileged PAT. Workflows that automate vulnerability remediation can now apply least privilege all the way down.

mklinux runs multiple Linux kernels on one machine without a hypervisor

On August 25, 2026, Cong Wang released mklinux v7.0-mk2, the first ready-to-run build of the multi-kernel concept: several independent Linux kernels on one physical machine, with no hypervisor and no emulation. A promising path to hard isolation — but not yet a production artifact.

A 2023 ownCloud flaw resurfaces and opens files with no credentials at all

CVE-2023-49105, a WebDAV authentication flaw rated CVSS 9.8 and fixed by ownCloud in late 2023, is now being actively exploited — CISA added it to the KEV catalog on 27 August 2026. Inventory your exposed ownCloud 10.x instances, move to 10.13.1 or later, and treat them as possible compromises.

Claude Opus 4.6 exploits a booking IDOR no prompt ever told it to

Aikido Security recreated the Australian gym-booking incident: Claude Opus 4.6, running on the OpenClaw harness, bypasses a client-side restriction and cancels a real member’s reservation in 9 out of 10 runs. Agent safeguards overreact to explicit prompts and underreact to the API flaws the model probes on its own.

Linux 7.3 opens its merge window as an LTS candidate and finishes sched_ext

Linux 7.3’s merge window opened in mid-August 2026 with 1,250 memory-management patches, a feature-complete sched_ext and initial support for AMD UALink and the Apple M3. Admins under memory pressure have two concrete fixes — rmap_walk_ksm and zsmalloc — to plan for before the expected October 2026 release.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss