-

CISA contractor leaked AWS GovCloud keys to public GitHub for six months
Patch Tuesday broke records again, a CISA contractor left AWS GovCloud keys public for six months, and lobste.rs quietly ditched MariaDB for SQLite.
-

GhostApproval: AI coding assistants approve malicious actions without showing users what they approved
etcd 3.7 lands with streaming ranges, Cloudflare bets on global consensus, and a disgruntled OpenMandriva contributor reminded everyone why least-privilege still matters.
-

XWayland 24.1.13 fixes two more X.Org security issues
Kernel 7.2-rc2 is out, trusted publishing is getting pushback, and sqlite-utils finally hit 4.0 – solid engineering day.
-

Four vulnerabilities in Guix: remote privilege escalation via substitute download
Seven stable kernels out, Guix has remote privilege escalation, and Claude Opus 4.8 is inventing tool-call fields. Odd weekend.
-

GitLab 19.1 ships; malware stuffs CBRN keywords to blind AI scanners
A 753B open-weights model dropped under MIT, GitLab shipped secret-scan GA, and malware authors are now stuffing CBRN keywords into comments specifically to blind the AI tools scanning for them.