Arch says it's scrubbed all known malicious commits, but the 1,500‑plus affected AUR packages are a fresh reminder to "trust but verify."
Posts published in “Security”
Arch User Repository hit by a large-scale malware campaign, with maintainers racing to roll back malicious commits and lock out bad actors.
From Copy Fail to Dirty Frag to Fragnesia and ssh-keysign‑pwn: AI‑driven bug hunters are turning the Linux kernel into a shooting gallery.
Two kernel zero‑day fixes, two quick Tails releases, and one Tor‑backed project determined to keep its privacy‑minded users safe — this is open source security hygiene in action.
Use-after-free bug in Exim’s GnuTLS BDAT handling lets remote attackers corrupt memory, with no workaround other than upgrading to version 4.99.3.
A trusted Debian dev turns scary new kernel bugs into a temporary one‑click fix until distros ship permanent patches.
‘Copy Fail’ puts Linux users on alert as kernel patches race out and distros scramble to push them to the update channel.
When models can audit firmware and legacy binaries at scale, hiding vulnerabilities stops working. Open, patchable code becomes a core security requirement.
A deterministic password manager that generates, rather than stores, your logins — and makes versioning old passwords surprisingly handy.










