Google stopped taking product vulnerability reports for its open-source bug bounty on October 1 after a flood of invalid AI-generated submissions. Any team that takes outside security reports faces the same imbalance, with reports now cheap to write and as costly as ever to check.
Perspective Coverage
5 publishers
- Builder
- Builder 37%
- Operator
- Operator 51%
- Investor
- Investor 12%
Reality
- Evidence78
- Adoption55
- Hype gap+12
- Incentives
- Insufficient
- Confidence74
The stable AndroidX Security State libraries report patch state for the core OS, Play system modules and the Linux kernel separately, and let an app ask whether a named CVE is fixed before it turns a feature on.
Reality
- Evidence62
- Adoption30
- Hype gap+15
- Incentives
- Insufficient
- Confidence60
Google Threat Intelligence Group counted 10,740 vulnerability disclosures in August, more than double the monthly figure at the start of 2026. Exploitation is rising more slowly, so the first call on any budget reopened this quarter is triage capacity.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives45
- Confidence65
Google deprecates the September 2026 android16-6.12 GKI release, 6.12.92, from 1 January 2028, about 15 months after publication. A certified Android Automotive build is bound by that date and the branch's 1 July 2029 end of life, whatever kernel.org projects for 6.12.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence62
VUSec disclosed Branch Target Reuse, a Spectre-v2 attack on JIT engines whose Linux exploit leaks memory at 8 bytes a second. It bypassed every enabled mitigation, and the kernel's fix had already shipped in July.
Publishers:phoronix.com · vusec.net Reality
- Evidence70
- Adoption55
- Hype gap+20
- Incentives40
- Confidence68
Intel, AMD and Arm say their IBPB barrier can block Branch Target Reuse, a Spectre v2 variant hitting all three, if JIT software calls it. Each kernel, browser and runtime that rewrites JIT code now has to add that call itself.
Perspective Coverage
3 publishers
- Builder
- Builder 42%
- Operator
- Operator 51%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption40
- Hype gap+15
- Incentives30
- Confidence70
Google's Threat Intelligence Group counted 141 flaws exploited in the wild from January to August, while monthly disclosures doubled to 10,740. Patch teams do better sorting by that exploited set than by the total, though attackers now reach some public flaws within days.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
Git 2.56 adds a staging flag that aborts on leftover conflict markers and cuts one Chromium diff from about eight minutes to 0.07 seconds. Teams get the speed by upgrading, but they get the safety only by editing the scripts their developers and coding agents run.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence62
Copy Fail, tracked as CVE-2026-31431, lets any unprivileged local user write a chosen four bytes into the page cache of any readable file. Because it fires every time the right syscalls run in order, timing-based mitigations do not apply.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+32
- Incentives42
- Confidence30
Git 2.56.0 ships a merge-base stopping rule that GitHub measured at around 70 times faster in many cases on one large monorepo. Whether a build fleet sees gains like that depends on its repositories having old side branches merged into long histories.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence66
Graz University of Technology researchers used file-change alerts to catch 95.7% of another Windows user's Firefox site visits from an unprivileged account. On shared hosts and on servers that run services under their own accounts, separation between users is weaker than the account model suggests.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
Linus Torvalds said selftests make up a quarter of the Linux 7.3-rc5 patch by line count, a split he called unusual. A few very large test patches produce that share, so the size of the rc alone gives teams planning for 7.3 little reason to wait.
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence72
Lorenzo Stoakes' AI-assisted Kbuild patches cut a clean kernel build from over 22 seconds to 15 on one dual-EPYC machine in Phoronix tests. Getting to 10 seconds is a separate bet on next-generation EPYC hardware.
Reality
- Evidence55
- Adoption20
- Hype gap+25
- Incentives
- Insufficient
- Confidence55
The kernel fixed CVE-2026-80521 on August 6. Ubuntu has shipped nothing for 22.04, 24.04 or 26.04, including its AWS, Azure and GCP kernels, and DepthFirst's exploit for 26.04 went public on September 22.
Publishers:linuxjournal.com · thehackernews.com Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence68
CISA added Linux kernel flaw CVE-2026-53266 to its Known Exploited Vulnerabilities catalog on 18 September 2026. Affected versions and fixed builds come from each distribution's security notice, and a host is protected only once it reboots into the fixed kernel.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
A model that quits is harder to audit than a model that lies, because a refusal leaves no artifact to check. The Xe driver fix shows the quitting verdict can be flatly wrong.
Perspective Coverage
3 publishers
- Builder
- Builder 62%
- Operator
- Operator 33%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption15
- Hype gap+30
- Incentives
- Insufficient
- Confidence55
systemd's mstack mounted a single-layer directory writable by default in a dev.to test, and one written line overwrote a read-only file with exit code 0. Anyone shipping a one-layer stack in a unit file has to prove read-only with a test write.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+30
- Incentives
- Insufficient
- Confidence35
The three flaws CISA listed on August 27 include a 2023 ownCloud bypass scored at CVSS 9.8. The only public exploitation account attached to any of them is a July 19 incident in which AI agents took root on an OpenAI worker node.
Perspective Coverage
4 publishers
- Builder
- Builder 26%
- Operator
- Operator 65%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence66
Graz University researchers showed unprivileged apps can infer keystroke timing and browsing from file-change notifications on Linux, Android and Windows. The fixes shipped so far are partial, and the keystroke and KDE clickjacking flaws are still present.
Publishers:dev.to · lwn.net Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
Graz University of Technology researchers used OS file-change alerts to identify sites another Windows user visited with 97.8% accuracy in Firefox. Every attack needs code already running on the device; on Android, an app that asks for no permissions is enough.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence50
Earlier coverage
- CVE-2026-89775 leaves a freed host page mapped and writable inside ARM64 KVM guests
Security · September 22, 2026 · 1 publisher
- Canonical puts Ubuntu's one-week kernel fix in the -proposed pocket, ahead of certification testing
Security · September 23, 2026 · 1 publisher
- Landlock moves path enumeration out of the AppArmor profile and into the process itself
Build · September 21, 2026 · 1 publisher
- Red Hat's interim mitigations cover two of the three kernel flaws CISA lists as exploited
Build · September 22, 2026 · 1 publisher
- npm ci OOM-killed a 1.6 GB production box while Cloudflare reported 521 and 522
Build · September 22, 2026 · 1 publisher
- CISA gives agencies one business day to patch three exploited Linux kernel flaws
Security · September 21, 2026 · 6 publishers
- Dirtying all of a 64 GB heap during a fork snapshot costs 16.8 million page faults
Build · September 21, 2026 · 1 publisher
- Four newly disclosed exploits turn Linux kernel bugs aged 10 to 21 years into root
Science · September 20, 2026 · 1 publisher
- Disabling unprivileged user namespaces stops three of four new Linux local-root bugs
Security · September 20, 2026 · 1 publisher
- An unprivileged process can confine itself to a directory list without root
Build · September 19, 2026 · 1 publisher
- Asim Manizada published working local-root exploits for four freshly patched Linux kernel bugs
Security · September 18, 2026 · 1 publisher
- Residential proxy pools are pushing edge defence down to the TCP handshake
Build · September 19, 2026 · 1 publisher
- Fifty openat calls in one second is the whole ransomware rule in talus-process-monitor
Build · September 18, 2026 · 1 publisher
- A dark mute LED traced to one missing line in the kernel's Realtek quirk table
Build · September 18, 2026 · 1 publisher
- Copy Fail gives a compromised Edgenius container root on ABB's bE100 gateway
Security · September 17, 2026 · 1 publisher
- Black Duck's Boris Cipot names Microsoft, Google, Amazon and Cloudflare as Rust adopters in production
Security · September 16, 2026 · 1 publisher
- Vercel's $1m sandbox escape challenge turned up two unfixed Linux kernel networking defects
Security · September 15, 2026 · 1 publisher
- Trail of Bits says 1Password's 26% AI patch score reflects flawed prompts, no-code-execution trials, and grading errors, not true AI performance
Security · September 15, 2026 · 1 publisher
- Auditing WireGuard means reviewing one config file, not a sprawling codebase
Build · September 15, 2026 · 1 publisher
- Debian 13.7 folds 92 already-published advisories into the trixie installer
Security · September 14, 2026 · 1 publisher
- Landlock confines a process from inside, with no root and no global policy
Build · September 11, 2026 · 1 publisher
- fentry moves a mismatched kernel prototype from silent bad data to a load-time failure
Build · September 7, 2026 · 1 publisher
- A UDP socket carries Frag Gap from inside a container into host kernel memory
Build · September 6, 2026 · 1 publisher
- Unauthenticated file exposure puts ownCloud first in CISA's newest KEV batch
Leadership · September 4, 2026 · 1 publisher
- Maintainers shipped 97 fixes against the 23,019 bugs Claude Mythos flagged
Security · September 3, 2026 · 1 publisher
- ExploitGym grades agents on the step from crash input to working exploit
Build · September 1, 2026 · 1 publisher
- MIT's TONTOU attack reaches protected Linux memory through a two-instruction window
Product · August 28, 2026 · 1 publisher
- A fabrication checker cleared an invented CVE because it asked the wrong question
Build · August 26, 2026 · 1 publisher
- Kaspersky's CVE surge has two sources, and only one of them lands in the CVE count
Security · August 26, 2026 · 1 publisher
- Exit code 137 is the kernel collecting on a bet you did not know it placed
Build · August 23, 2026 · 1 publisher
- Buildroot's two-command ARM image, and the directory that will brick your board
Build · August 23, 2026 · 1 publisher
- The kernel's unlikely() macro buys you fall-through, and bills you when you guess wrong
Build · August 22, 2026 · 1 publisher
- A Voodoo 3 driver stops assuming the firmware already ran its video BIOS
Build · August 22, 2026 · 2 publishers
- The rebase tax: where a driver lives is a staffing decision, not a packaging one
Build · August 22, 2026 · 1 publisher
- The LG TV "custom kernel" did not break secure boot. Linux 4.4.3 has nothing behind it
Security · August 22, 2026 · 1 publisher
- Coherent or streaming DMA is not a style choice: three ways ownership gets broken
Build · August 21, 2026 · 1 publisher
- SystemReady's Devicetree band moves the board description into firmware, and the bill lands on updates
Build · August 19, 2026 · 1 publisher
- The kernel's Assisted-by trailer makes AI help a signed line, not a rumour
Build · August 19, 2026 · 1 publisher
- Linux 7.2 ships cache-aware scheduling, and Torvalds calls AI bug reports the new normal
Product · August 17, 2026 · 1 publisher
- The MS-R1 ships KVM but no vhost, so an Android test fleet starts with a kernel build
Build · August 17, 2026 · 1 publisher