AUTO-UPDATED

This Week in Security: What’s in a name, the AI Bugpocalypse Hits Everyone, OpenWRT flaws, and Duress Passwords

Google has introduced new threat actor naming conventions as the cybersecurity industry grapples with a surge in vulnerabilities and evolving patch management strategies across major software platforms.

Key Points

  • Google launched "RELIC," "CASTLE," and "COMET" naming schemes to classify threat groups, joining existing systems from CrowdStrike and Microsoft.
  • OpenWRT released critical security patches for the odhcpd server and uhttpd, though many legacy MIPS-based devices will remain permanently vulnerable.
  • Cisco is shifting to a twice-monthly patch cycle and will stop assigning CVEs to bugs unless they require specific compensating controls.
  • Oracle addressed 1,499 security issues across 334 products in its July 2026 update, while the Linux kernel patched 323 vulnerabilities in three days.
  • FreeBSD issued a security update to fix a cryptographic validation flaw in its WireGuard VPN implementation that allowed for potential packet injection.

Why it Matters

The rapid increase in AI-generated vulnerability reports is overwhelming traditional security workflows, forcing major vendors to reconsider how they track and patch software flaws. This shift risks creating a "patch fatigue" cycle where organizations struggle to balance the need for rapid updates against the stability and testing requirements of enterprise environments.
Hackaday Published by Mike Kershaw
Read original