Blog

Security insights, vulnerability roundups, and updates from the Agent Breach team.

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

nginx HTTP/2 Cookie Handling Flaw Patched After Regression

Ubuntu released USN-8398-3 to address CVE-2026-49975, a denial-of-service vulnerability in nginx's HTTP/2 cookie processing that was incompletely fixed in earlier updates. The final patch resolves resource exhaustion risks without introducing the regressions that plagued previous attempts.

Read more

.NET Security Patches Address File Tampering and DoS Vulnerabilities

Ubuntu has released critical security updates for .NET addressing two significant vulnerabilities: improper link resolution enabling unauthorized file writes and a denial-of-service flaw in MessagePack array handling. Development teams should prioritize patching to prevent local exploitation and resource exhaustion attacks.

Read more