🦅 The changelog says "bug fixes."
The diff says "security patch."
We track CVE-less fixes so defenders don't fly blind.
New drop every Thursday.
@78_lab
7-Zip 26.01's changelog lists exactly ONE security fix.
We diffed the source, 26.00 -> 26.01. It silently shipped 14 MORE.
"Some bugs were fixed" was doing a lot of heavy lifting. 🧵
Takeaway: treat 26.01 as a security release, not a point fix. Upgrade from 26.00 even if you think the NTFS CVE doesn't touch you, because 14 more code paths got safer and the changelog won't say so.
🦅 PatchHawk
#7zip#infosec
Linux mainline quietly shipped a fix for a remote kernel heap overflow in the iSCSI target. It fires during login, before the CHAP password is ever checked.
No CVE. The commit just says "validate CHAP_R length before base64 decode."
Only watch CVE feeds? You missed it. 🧵
These are mainline -rc fixes: Cc: stable, no CVE yet by design. CVEs land later, on backport.
We read the merge graph so you see them now, not after the feed catches up.
🦅 PatchHawk
#LinuxKernel#infosec
🦅 Silent Patch Watch
Vendors often ship real security fixes as "minor bug fixes" — no CVE, no advisory.
Every Thursday we diff a release and show the one that actually mattered, so you can update before attackers notice.
Follow + 🔖 for the first issue this week.