-

xAI’s Grok CLI uploaded users’ entire home directories – SSH keys, password managers, all of it
The big story today is xAI’s Grok CLI uploading entire home directories to Google Cloud – SSH keys, password databases, everything. That’ll wake you up.
-

CISA’s AWS GovCloud Keys Sat Public on GitHub for Six Months
CISA credentials sat in a public GitHub repo for six months. Netflix mapped 10k+ services in real time. Debian bookworm moves to LTS. A busy day for postmortems.
-

GhostApproval: AI coding assistants approve malicious actions without showing users what they approved
etcd 3.7 lands with streaming ranges, Cloudflare bets on global consensus, and a disgruntled OpenMandriva contributor reminded everyone why least-privilege still matters.
-

XWayland 24.1.13 fixes two more X.Org security issues
Kernel 7.2-rc2 is out, trusted publishing is getting pushback, and sqlite-utils finally hit 4.0 – solid engineering day.
-

Four vulnerabilities in Guix: remote privilege escalation via substitute download
Seven stable kernels out, Guix has remote privilege escalation, and Claude Opus 4.8 is inventing tool-call fields. Odd weekend.
-

FBI seizes NetNut proxy platform tied to 2M-device Popa botnet
Quiet holiday week, but the kernel mailing list and the FBI both had eventful Wednesdays.
-

Weak RSA keys with sparse bit patterns found in real-world Certificate Transparency logs
Git 2.55, Linux 7.2-rc1, and a real RSA key vulnerability in the wild — a quieter news day with a few sharp edges worth your attention.
-

LWN: Kernel 7.2 gets allocation tokens and boot-time structure-layout randomization
MinIO archived, kernel hardening incoming, Podman 6 out — a solid infrastructure day under all the AI noise.
-

Cisco SD-WAN zero-day hits production; supply chain ransom reaches Grafana Labs
A supply chain ransom hit Grafana’s CI runners, a Cisco SD-WAN zero-day is being used for lateral movement in production right now, and both Fedora and Red Hat published pieces about what happens when humans stop owning the security decisions in their own pipelines.
-

AUR supply-chain attack: orphaned packages pushed malware for days
Quiet weekend, but systemd v261 and the AUR supply-chain saga both deserve your attention before Monday standup.