Discovered in 2022 and rated high priority, it still hasn't been fixed
Facepalm: The open-source Chromium project provides the foundation for Google Chrome and many other popular web browsers like Microsoft Edge, Opera, and Brave. When a serious security flaw is discovered in the shared codebase, it can quickly become a widespread threat affecting millions of devices across multiple computing platforms.
Discord just flipped on end-to-end encryption for every voice and video call across DMs, group chats, voice channels and streams. It's one of the platform's biggest privacy upgrades yet.
Another massive support headache for the Linux world
Facepalm: The open-source community is once again facing a major security incident tied to an "unprecedented" vulnerability. The new flaw could give attackers a reliable way to escalate user privileges, and no patch is available yet. Fortunately, the mitigation process is relatively straightforward. Still, kernel developers are already growing frustrated with the seemingly endless stream of critical bugs.
Affects virtually every Linux distro released in the past nine years, and working exploits were on GitHub within 24 hours
Facepalm: Security researchers recently unveiled "Copy Fail," a bug that could potentially bring the entire Linux ecosystem to a screeching halt. The flaw can be reliably exploited across all Linux-based systems, both on local machines and in cloud environments. Vendors are now scrambling to patch the issue.
The takeaway: The PC piracy scene appears to have reached a milestone many once thought unlikely: Denuvo, long regarded as one of the most formidable DRM and anti-tamper systems in gaming, has effectively been defeated. With hypervisor bypasses emerging as the latest breakthrough, there is now no known PC game protected by Denuvo that cannot be obtained for free through either a crack or a functional bypass.
Editor's take: Google is once again trying to simplify something that was already fairly easy and convenient. Mountain View's latest target is email-based authentication, which is now dropping the email-checking step altogether thanks to a new Android API update.