-

CISA contractor leaked AWS GovCloud keys to public GitHub for six months
Patch Tuesday broke records again, a CISA contractor left AWS GovCloud keys public for six months, and lobste.rs quietly ditched MariaDB for SQLite.
-

GhostApproval: AI coding assistants approve malicious actions without showing users what they approved
etcd 3.7 lands with streaming ranges, Cloudflare bets on global consensus, and a disgruntled OpenMandriva contributor reminded everyone why least-privilege still matters.
-

XWayland 24.1.13 fixes two more X.Org security issues
Kernel 7.2-rc2 is out, trusted publishing is getting pushback, and sqlite-utils finally hit 4.0 – solid engineering day.
-

Four vulnerabilities in Guix: remote privilege escalation via substitute download
Seven stable kernels out, Guix has remote privilege escalation, and Claude Opus 4.8 is inventing tool-call fields. Odd weekend.
-

Linux 7.2 targets August; an 18-year-old GPU bug surfaces; PQC lands in pip
An 18-year-old bug surfaces via GPU fleet telemetry, AI tooling is making engineers work more hours not fewer, and post-quantum crypto just became a single pip install — all in the same news cycle.
-

GitLab 19.1 ships; malware stuffs CBRN keywords to blind AI scanners
A 753B open-weights model dropped under MIT, GitLab shipped secret-scan GA, and malware authors are now stuffing CBRN keywords into comments specifically to blind the AI tools scanning for them.