+ cPanel drops patches for exploited authentication bypass zero-day; 'Copy Fail' Linux privesc bug lay dormant in kernel since 2017; and more
Can't view this message? Click here to view it online.
iTnews

WEEKLY SECURITY WRAP

Tuesday May 5, 2026

Editor's Note


The first five chapters of the 2026 iTnews State of Security report are now live.


Learn how PEXA, Employers Mutual Limited, Estia Health, Cleanaway Waste Management and the University of Queensland are addressing security challenges in domains including IAM, XDR, Zero Trust, endpoint and cyber resilience.


Click here to get free access now!


 

 
  Security  

Defender yanks root certs as Windows updates blocks backups

Rough week for Microsoft customers.

By Juha Saarinen

 

Latest Security News


cPanel drops patches for exploited authentication bypass zero-day
  Security  

cPanel drops patches for exploited authentication bypass zero-day

Detection script released to identify compromised systems.

By Juha Saarinen

 
'Copy Fail' Linux privesc bug lay dormant in kernel since 2017
  Security  

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

Tiny Python script roots every major Linux distribution since nearly nine years ago.

By Juha Saarinen

 
Incomplete fix for Fancy Bear exploit opens zero-click hole in Windows
  Security  

Incomplete fix for Fancy Bear exploit opens zero-click hole in Windows

No interaction needed.

By Juha Saarinen

 
GitHub patches critical 'git push' remote code execution bug
  Security  

GitHub patches critical 'git push' remote code execution bug

Open source code platform dodges bullet with quick response.

By Juha Saarinen

 
 
 
 
Amadeus to buy French biometrics firm Idemia Public Security
  Security  

Amadeus to buy French biometrics firm Idemia Public Security

For 1.2 billion euros.

By Staff Writer

 
University of Queensland aligns resilience approach across operations
  State of Security 2026  

University of Queensland aligns resilience approach across operations

Takes cues from cyber and SOCI.

By Brad Howarth

 
NSW gov downgrades impact of alleged Treasury data breach
  Security  

NSW gov downgrades impact of alleged Treasury data breach

As investigation continues.

By Yoshifumi Takemoto

 
UK cyber security agency warns of AI-driven 'patch wave'
  Security  

UK cyber security agency warns of AI-driven 'patch wave'

Overhaul software update processes or risk being overwhelmed.

By Juha Saarinen

 
Why Backing Up Your Microsoft 365 Data Is Only Half the Job
  Partner Content  

Why Backing Up Your Microsoft 365 Data Is Only Half the Job

Microsoft 365 has evolved into a critical enterprise control plane, but many organisations are still lagging in managing its security and governance demands.

 
 
 
 

Featured whitepaper


 
 

MOST POPULAR


'Copy Fail' Linux privesc bug lay dormant in kernel since 2017
  Security  

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

By Juha Saarinen

Services Australia describes fraud, debt-related machine learning use cases
  Security  

Services Australia describes fraud, debt-related machine learning use cases

By Ry Crozier

Medibank reveals attack vector and cost of 2022 security breach
  Security  

Medibank reveals attack vector and cost of 2022 security breach

By Richard Chirgwin

Attacker embeds Claude Code in mass credential harvesting op
  Security  

Attacker embeds Claude Code in mass credential harvesting op

By Juha Saarinen

Incomplete fix for Fancy Bear exploit opens zero-click hole in Windows
  Security  

Incomplete fix for Fancy Bear exploit opens zero-click hole in Windows

By Juha Saarinen

 
 
unsubscribe