Three Snapd Bugs Let Any Local User Own Ubuntu — Patch Now
Canonical patched three snapd CVEs on July 21, including two high-severity privilege escalation flaws that hand a low-privilege account full root on default Ubuntu Desktop installs. »
Gitea 1.27 Patches 45 CVEs and Brings Reusable Workflows to Self-Hosted Git
The self-hosted Git platform's latest release closes 45 security vulnerabilities — the largest patch batch in its history — while delivering reusable workflows and Jupyter Notebook rendering. »
The Linux Foundation Just Created a Last-Resort Security Team for Critical Open Source Software
Akrites — backed by Amazon, Anthropic, Google, Microsoft, NVIDIA, and OpenAI — will step in as maintainer of last resort when a critical open source package has no one left to keep it safe. »
GhostLock and Januscape: Two Ancient Linux Kernel Bugs Disclosed in the Same Week
GhostLock (CVE-2026-43499) gives any logged-in user full root in five seconds and breaks out of containers. Januscape lets a VM escape its host. Both were disclosed in July 2026 — both are over 15 years old. »
Apple Sues OpenAI: The Trade Secret Theft Allegations That Could Reshape the AI Industry
Apple has filed suit against OpenAI, alleging a coordinated campaign to extract hardware trade secrets through 'show and tell' job interviews — a dramatic reversal after the two companies formed a high-profile AI partnership in 2024. »