🚨 nginx has a critical vuln hiding in it for 18 years.
We patched it across AlmaLinux 8, 9, 10 & Kitten—including EOL streams—before upstream did.
Details on our blog. 👇 https://t.co/VYOqD5SumV
Copy-Fail? More like Copy-Fixed. 🛑
At @DECIX , our customers depend on our availability and integrity. So when the Linux "Copy-Fail" vulnerability popped up, we took it super seriously and patched things up immediately.
But our engineers don't just patch; they innovate. 🧠
During the mitigation process, one of our brilliant system engineers identified a completely alternative way to block the vulnerability using ftrace. Because it’s been supported in the kernel since 2013, it’s an incredibly accessible solution for the broader community.
We love a clever fix. Check out the GitHub repo below, try it yourself, and hit us with your feedback!
👉 https://t.co/8uwOuCFbUd
Patches for Copy Fail (CVE-2026-31431) are not yet available from Red Hat, so our core team has built patched kernels.
These kernels are available in the testing repository today. Learn more on our blog ⤵️ https://t.co/DN5GxavFT9
Copy Fail (CVE-2026-31431) is severe enough that we wanted to create a patch ASAP.
If you run AlmaLinux on a multi-tenant host, container build farm, CI runner, or any system where untrusted users can get a shell, please read this blog post!
https://t.co/DN5GxavFT9
‼️Copy Fail (CVE-2026-31431) is a Linux privilege escalation bug that lets any local user get root using a 732-byte Python script, and itworks on basically every major Linux distro shipped since 2017.
Website: https://t.co/f5G6KnEv35
Write-up: https://t.co/W86Pz2PC6C
GitHub: https://t.co/zAMTC6nTRk
It's a logic flaw in the kernel's crypto code (authencesn via AF_ALG and splice()) that allows a small write into the page cache, which can be used to tamper with a setuid binary like /usr/bin/su.
Think how bad this is going to be for shared environments like Kubernetes, CI runners, and cloud sandboxes, where it enables container escape and tenant-to-host compromise.
Found by Theori's Xint Code scanner, patched in the mainline kernel, and publicly disclosed on April 29, 2026; if you can't patch right away, the recommended workaround is to disable the algif_aead module.
‼️🇮🇩 A threat actor has allegedly leaked 53,993 records from SIMOJANG (Sistem Informasi Monitoring Jabar Caang), an Indonesian provincial government monitoring system.
The data reportedly includes monitoring statuses, names, NIK numbers, addresses, property ownership details, GPS coordinates, photos, electrical status, and other residential infrastructure data.
The data is being distributed for free.
‼️CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Severity: Critical
CVSS: 9.8
Zero Day: Yes
CVE Published: January 27th, 2026
Advisory: https://t.co/q2wUQnp3vl
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Patah hati terbesar kami ketika mendengar cerita Pak Reje (kepala desa) di Aceh Tengah yang akses desanya tertutup akibat jembatan putus dan jalan longsor.
Inilah yang menyebabkan kami fokus perbaikan akses. Tanpa akses, ekonomi tidak berputar. Masyarakat tidak bisa jual beli.