Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
GNOME is officially shortening its standard vulnerability disclosure window from 90 days to 30 days, a change that impacts upstream maintainers, downstream Linux distributions, and system administrators in how they handle software vulnerabilities. The policy shift, announced by long-time security coordinator Michael Catanzaro , addresses modern software patching realities and a growing influx of automated submissions. . Because GNOME is the default desktop environment on several major Linux distributions, changes to its security process can affect downstream maintainers and organizations that deploy GNOME-based workstations. The shorter disclosure window could reduce the time available for downstream distributions and organizations to prepare updates before vulnerability details become public. What Actually Changes on August 1? The new policy introduces strict operational guidelines for how incoming security issues are handled across GNOME projects: Effective Date: The 30-day disclosure window only applies to vulnerabilities reported on or after August 1, 2026. Automatic Public Disclosure: According to the policy of GNOME, if a vulnerability is not fixed after 30 days the report will not be confidential anymore. Existing Reports Unaffected: Any security reports filed before August 1 will still follow the old 90 day embargo timeline to avoid disruption of active investigations. Handling AI-Ban Projects: For upstream projects that do not explicitly accept contributions of AI-generated content, the GNOME security team will locally close incoming reports, instead of forwarding automated noise to developer issue trackers. Why GNOME Changed Its Security Policy To understand the timeline shift, it helps to know why disclosure embargoes exist in the first place. Coordinated disclosure policies aim to give developers and downstream maintainers a protected window of time to investigate flaws, write patches, and coordinate repository updates before technicalexploit details become public knowledge. Under the previous 90-day framework, however, that window no longer matched actual project behavior. In practice, GNOME maintainers typically resolve valid security issues within one to three weeks, or they leave them unaddressed entirely. Keeping unpatched reports confidential for a full 90 days created administrative delays without providing practical benefits for patch development. Moreover, the rise of automated tools had a dramatic impact on submission patterns. There are fewer reports that are written by humans, and more reports that are generated by AI. A large proportion of these automated submissions are of low quality, which significantly increases the triage burden on maintainers. Some open-source projects opted for immediate full disclosure for AI-generated reports, but GNOME opted for a more balanced 30-day window to ensure maintainers still have a reasonable window to fix legitimate issues. How the New Timeline Affects Linux Distributions When GNOME fixes a security issue, distribution maintainers package those changes, publish updates, and release security advisories. A shorter disclosure window gives each step in that process less time before vulnerability details may become public. Downstream maintainers across Fedora Workstation , Ubuntu Desktop , and Debian face tighter turnaround times to build and test patches. If an issue remains unresolved when the 30-day clock runs out, technical details enter the public domain, leaving downstream maintainers with less time to validate and distribute updates before technical details become public. What Linux Administrators Should Expect System administrators and enterprise IT teams managing GNOME-heavy environments should adjust their operational expectations to align with the new timeline. Rather than tracking upstream GNOME announcements directly, security teams should monitor security notices issued by their specific Linux distribution. Organizations must be prepared for technicalvulnerability details to become public sooner if upstream maintainers cannot reach a resolution within the 30-day window, meaning internal staging and QA windows for desktop updates may need to be streamlined. GNOME Begins Search for a New Security Coordinator Supporting this policy transition is an upcoming leadership change within the project. Catanzaro, who has managed GNOME security tracking largely alone since November 2020 with backing from Red Hat, announced plans to step down from coordinating security reports later this year. Catanzaro will stop tracking newly reported issues on November 1, 2026, aiming to clear the remaining pipeline by December. The departure initiates a search for an experienced community successor to manage incoming reports, oversee disclosure deadlines, and coordinate CVE assignments under the new 30-day framework. . As GNOME shortens its vulnerability disclosure window, organizations must adapt to the new 30-day policy to protect systems effectively.. GNOME Security Changes, Vulnerability Disclosure, Linux Distribution Guidance. . MaK Ulac
Microsoft's Security Update Guide, which chronicles Microsoft's patch releases each month, is getting two relatively new additions. . First off, the Security Update Guide will soon list common vulnerabilities and exposures (CVEs) for Microsoft''s CBL-Mariner Linux distribution, per a Friday announcement. CBL-Mariner is Microsoft''s Linux-based operating system that''s widely used with various Azure services. Specifically, CBL-Mariner is getting added to the "Security Update Guide (SUG) Common Vulnerability Reporting Framework." Publication will happen "beginning January 11, 2023." The coming CBL-Mariner vulnerability disclosures are expected to bulk up the amount of CVEs published by Microsoft, although the CVEs actually derive from various open source software projects. . The forthcoming update from Microsoft's Security Update Guide will elaborate on CBL-Mariner exposure findings, thereby improving the efficiency of patch management.. CBL-Mariner Linux, Microsoft Security Updates, Vulnerability Disclosure. . LinuxSecurity.com Team
Dennis Fisher talks with Dan Kaminsky about the VENOM bug, the value of virtual machine escapes, why everyone wants to make every bug the worst one of all time or just a bunch of hype and what the Avengers have to do with vulnerability disclosure.. . Dennis Fisher talks with Dan Kaminsky about the newly revealed VENOM vulnerability, examining its impact on virtual machine security and the hype around it.. VENOM Bug, Virtual Machine Escape, Cybersecurity Trends. . Alex
It's no secret that the National Security Agency is full of secrets. But, in a rare move, the White House disclosed Monday a bit more about how the NSA works.. In a blog post, White House cybersecurity coordinator Michael Daniel detailed when the NSA keeps security vulnerabilities under wraps and when it lets the public know they exist. The link for this article located at CNET is no longer available. . In a blog post, White House cybersecurity coordinator Michael Daniel detailed when the NSA keeps sec. secret, national, security, agency, secrets, white. . Dave Wreski
A team of academics asked a federal court Wednesday for permission to publicly reveal how they cracked an anti-piracy technology backed by the music industry. Princeton University researchers headed by professor Edward Felten filed the challenge in order to present their . . . . A team of academics asked a federal court Wednesday for permission to publicly reveal how they cracked an anti-piracy technology backed by the music industry. Princeton University researchers headed by professor Edward Felten filed the challenge in order to present their findings at a computer security conference in August. Felten had originally planned to present a paper disclosing how his team defeated a digital-music antipiracy measure at another conference in April, but bowed out after the recording industry threatened a lawsuit. The link for this article located at Reuters is no longer available. . Legal proceedings uncover efforts by researchers to share results regarding breakthroughs in bypassing digital rights management in music.. Anti-Piracy Technology, Digital Security, Academic Research, Legal Challenges. . LinuxSecurity.com Team
Microsoft has told Security Focus, the US security company that manages the Bugtraq moderated security email list, that it can no longer publish the software giant's security alerts. The issue centres round Microsoft's recently redesigned security email alerts, which it distributes . . . . Microsoft has told Security Focus, the US security company that manages the Bugtraq moderated security email list, that it can no longer publish the software giant's security alerts. The issue centres round Microsoft's recently redesigned security email alerts, which it distributes to registered subscribers and third party security mailing lists. The redesigned bulletins give only the barest details about new vulnerabilities and instead directs users to a page on Microsoft's website for the full text. Under the original email format, which included full text, Bugtraq was able to redistribute the alerts because Microsoft had sent them to Bugtraq. But in response to a Microsoft vulnerability email alert issued in the new format earlier this week, Bugtraq's moderator, Elias Levy, republished the full text which he downloaded from Microsoft's website. The link for this article located at VNUnet is no longer available. . Apple advises Tech Alert to halt disclosing advisories because novel messaging styles impact threat notifications.. Microsoft Security,Bugtraq Management,Security Alerts,Vulnerability Disclosure. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.