Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Unified%20Communications%20Manager%20Server-Side%20Request%20Forgery%20Vulnerability%26vs_k=1
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.
Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.
Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
Security Impact Rating: Critical
CVE: CVE-2026-20230
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Unified%20Communications%20Manager%20Server-Side%20Request%20Forgery%20Vulnerability%26vs_k=1
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.
Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.
Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
Security Impact Rating: Critical
CVE: CVE-2026-20230
Apple Needs a Next-Gen Siri at WWDC to Power Its Future Devices
https://www.cnet.com/tech/services-and-software/apple-wwdc-2026-siri-update-gemini-ai-wearables/
Commentary: Glasses, camera-enabled AirPods, a pendant and perhaps major Apple Watch updates all need a Gemini-powered AI revamp that isn't here yet. WWDC should be where that journey begins.
https://www.cnet.com/tech/services-and-software/apple-wwdc-2026-siri-update-gemini-ai-wearables/
Commentary: Glasses, camera-enabled AirPods, a pendant and perhaps major Apple Watch updates all need a Gemini-powered AI revamp that isn't here yet. WWDC should be where that journey begins.
Cisco Finesse Remote File Inclusion Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-rfi-gwpkdc89?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Finesse%20Remote%20File%20Inclusion%20Vulnerability%26vs_k=1
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks.
This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link that contains the affected device address. A successful exploit could allow the attacker to conduct browser-based attacks and execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-rfi-gwpkdc89
Security Impact Rating: Medium
CVE: CVE-2026-20175
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-rfi-gwpkdc89?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Finesse%20Remote%20File%20Inclusion%20Vulnerability%26vs_k=1
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks.
This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link that contains the affected device address. A successful exploit could allow the attacker to conduct browser-based attacks and execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-rfi-gwpkdc89
Security Impact Rating: Medium
CVE: CVE-2026-20175
Google Is Testing an Option for Websites to Opt Out of AI Search
https://www.cnet.com/tech/services-and-software/google-now-testing-option-website-owners-opt-out-ai/
The search giant also plans to give publishers more information about the ways their content shows up in AI Overviews and AI Mode.
https://www.cnet.com/tech/services-and-software/google-now-testing-option-website-owners-opt-out-ai/
The search giant also plans to give publishers more information about the ways their content shows up in AI Overviews and AI Mode.
Xfinity Is Giving 2026 World Cup Fans an Interactive, Bilingual Experience
https://www.cnet.com/tech/services-and-software/xfinity-is-giving-2026-world-cup-fans-an-interactive-experience/
You can tap into several new features while watching the tournament.
https://www.cnet.com/tech/services-and-software/xfinity-is-giving-2026-world-cup-fans-an-interactive-experience/
You can tap into several new features while watching the tournament.
Hisense's Colorful RGB TV, the UR8, Hits Shelves From $1,300
https://www.cnet.com/tech/home-entertainment/hisense-shrinks-30000-tech-into-smaller-tvs-for-2026/
Hisense has released the RGB Mini-LED UR8, which promises brighter colors than before.
https://www.cnet.com/tech/home-entertainment/hisense-shrinks-30000-tech-into-smaller-tvs-for-2026/
Hisense has released the RGB Mini-LED UR8, which promises brighter colors than before.
Cisco Live US 2026 Day 2: From Agentic Vision to Enterprise Reality
https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m06/cisco-live-us-2026-day-2-from-agentic-vision-to-enterprise-reality.html?source=rss
https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m06/cisco-live-us-2026-day-2-from-agentic-vision-to-enterprise-reality.html?source=rss
The agentic era isn't coming - it's here. And today is where it gets real. Join Liz Centoni, Cisco EVP and Chief Customer Officer, and Jeetu Patel, President and Chief Product Officer, for a keynote that brings agentic transformation to life
More RSS Feeds: https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html (https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html?source=rss)
More RSS Feeds: https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html (https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html?source=rss)
I Checked Out the $699 Dell XPS 13, and It's the MacBook Neo's Biggest Threat video
https://www.cnet.com/videos/dell-xps-13-computex/
Watch out, MacBook Neo: we checked out the affordable Dell XPS 13 in person and came away impressed. Its all-metal build, touchscreen, and other features feel like a more expensive laptop.
https://www.cnet.com/videos/dell-xps-13-computex/
Watch out, MacBook Neo: we checked out the affordable Dell XPS 13 in person and came away impressed. Its all-metal build, touchscreen, and other features feel like a more expensive laptop.
Microsoft's New AI Image Tool Beats Nano Banana on This Key Task
https://www.cnet.com/tech/services-and-software/microsoft-new-ai-image-model-build-nano-banana-news/
Microsoft's new MAI-Image-2.5 model bested Google's Nano Banana 2 on an important benchmark. But does that make it the right choice for you?
https://www.cnet.com/tech/services-and-software/microsoft-new-ai-image-model-build-nano-banana-news/
Microsoft's new MAI-Image-2.5 model bested Google's Nano Banana 2 on an important benchmark. But does that make it the right choice for you?
Strava Members: Run a 5K Wednesday, Get a Runna Subscription Free
https://www.cnet.com/health/fitness/strava-members-free-runna-subscription-run-5k-june-3/
Strava is adding an incentive to get you moving -- but don't wait, it's only for one day, June 3.
https://www.cnet.com/health/fitness/strava-members-free-runna-subscription-run-5k-june-3/
Strava is adding an incentive to get you moving -- but don't wait, it's only for one day, June 3.
Motorola's Razr Fold Makes a Strong Debut -- With a Few Catches video
https://www.cnet.com/videos/motorolas-razr-fold-makes-a-strong-debut-with-a-few-catches/
Motorola's first book-style foldable makes a strong debut, with long battery life, impressive cameras and a sleek build. But there are some caveats, including the hefty $1,900 price.
https://www.cnet.com/videos/motorolas-razr-fold-makes-a-strong-debut-with-a-few-catches/
Motorola's first book-style foldable makes a strong debut, with long battery life, impressive cameras and a sleek build. But there are some caveats, including the hefty $1,900 price.
Intel's Computex Keynote in 12 Minutes video
https://www.cnet.com/videos/intels-computex-keynote-in-12-minutes/
Intel's CEO, Lip-Bu Tan, and industry partners present the company's transition to its 18A process technology across consumer PCs, handheld gaming devices, and data centers built to handle multi-agent AI workloads.
https://www.cnet.com/videos/intels-computex-keynote-in-12-minutes/
Intel's CEO, Lip-Bu Tan, and industry partners present the company's transition to its 18A process technology across consumer PCs, handheld gaming devices, and data centers built to handle multi-agent AI workloads.
The Future of Windows Is Every Device You Own video
https://www.cnet.com/videos/the-future-of-windows-is-every-device-you-own/
From Project Solara hardware to "agent-first" operating systems, Microsoft is betting that your future computing experience isn't tied to one device. Instead, it's powered by an army of autonomous assistants.
https://www.cnet.com/videos/the-future-of-windows-is-every-device-you-own/
From Project Solara hardware to "agent-first" operating systems, Microsoft is betting that your future computing experience isn't tied to one device. Instead, it's powered by an army of autonomous assistants.
Today's NYT Strands Hints, Answers and Help for June 4 #823
https://www.cnet.com/tech/gaming/todays-nyt-strands-hints-answers-and-help-for-june-4-823/
Here are hints and answers for the NYT Strands puzzle for June 4, No. 823.
https://www.cnet.com/tech/gaming/todays-nyt-strands-hints-answers-and-help-for-june-4-823/
Here are hints and answers for the NYT Strands puzzle for June 4, No. 823.
Today's NYT Connections Hints, Answers and Help for June 4, #1089
https://www.cnet.com/tech/gaming/todays-nyt-connections-hints-answers-and-help-for-june-4-1089/
Here are some hints and the answers for the NYT Connections puzzle for June 4, No. 1,089.
https://www.cnet.com/tech/gaming/todays-nyt-connections-hints-answers-and-help-for-june-4-1089/
Here are some hints and the answers for the NYT Connections puzzle for June 4, No. 1,089.
Qubes Canary 047
https://www.qubes-os.org/news/2026/06/03/canary-047/
We have published Qubes Canary 047 (https://github.com/QubesOS/qubes-secpack/blob/5e7150d2731e1fb3979520e3e72e4d76d1e22c07/canaries/canary-047-2026.txt). The text of this canary and its accompanying cryptographic signatures are reproduced below. For an explanation of this announcement and instructions for authenticating this canary, please see the end of this announcement.
Qubes Canary 047
---===[ Qubes Canary 047 ]===---
Statements
-----------
The Qubes security team members who have digitally signed this file [1]
state the following:
1. The date of issue of this canary is June 03, 2026.
2. There have been 114 Qubes security bulletins published so far.
3. The Qubes Master Signing Key fingerprint is:
427F 11FD 0FAA 4B08 0123 F01C DDFA 1A3E 3687 9494
4. No warrants have ever been served to us with regard to the Qubes OS
Project (e.g. to hand out the private signing keys or to introduce
backdoors).
5. We plan to publish the next of these canary statements in the first
fourteen days of September 2026. Special note should be taken if no new
canary is published by that time or if the list of statements changes
without plausible explanation.
Special announcements
----------------------
None.
Disclaimers and notes
----------------------
We would like to remind you that Qubes OS has been designed under the
assumption that all relevant infrastructure is permanently compromised.
This means that we assume NO trust in any of the servers or services
which host or provide any Qubes-related data, in particular, software
updates, source code repositories, and Qubes ISO downloads.
This canary scheme is not infallible. Although signing the declaration
makes it very difficult for a third party to produce arbitrary
declarations, it does not prevent them from using force or other means,
like blackmail or compromising the signers' laptops, to coerce us to
produce false declarations.
The proof of freshness provided below serves to demonstrate that this
canary could not have been created prior to the date stated. It shows
that a series of canaries was not created in advance.
This declaration is merely a best effort and is provided without any
guarantee or warranty. It is not legally binding in any way to anybody.
None of the signers should be ever held legally responsible for any of
the statements made here.
Proof of freshness
-------------------
Wed, 03 Jun 2026 02:51:46 +0000
Source: DER SPIEGEL - International (https://www.spiegel.de/international/index.rss)
NSDAP archive: How DER SPIEGEL processed the data from the Nazi card file
Interactive Research Tool: What Your Family Did Under Hitler – Find Out Here
Human Rights in the US: Meet the Transgender Americans Forced to Flee GOP Persecution
An Interview with Maduro's Son: "We Should Have Done More to Protect My Father"
Forced Mercenaries: How Russia Dupes Kenyans into Fighting in Ukraine
Source: NYT > World News (https://rss.nytimes.com/services/xml/rss/nyt/World.xml)
Iran War Live Updates: Iran Targets Neighbors as U.S. Condemns ‘Aggressive’ Strikes
Russia Launches Deadly Strikes on Kyiv After Threatening Ukraine for a Week
U.S. Ebola Unit Plans in Kenya, Subject of Protests, Suffers New Setback From Court Ruling
The New Zealand Parakeet Pair That Are Saving Their Species
U.S. Was Asked to Blacklist Colombian Cartel Gold. It Was Also Buying It.
Source: BBC News (https://feeds.bbci.co.uk/news/world/rss.xml)
Israel strikes southern Lebanon but partial truce with Hezbollah appears to hold
US and Iran launch new strikes as ceasefire negotiations stall
Putin remains uncompromising on Ukraine, but is public discourse on war changing in Russia?
'They'll fix the building, but not our souls': Sleepy Kyiv neighbourhood hit in Russian strike
British couple lose Iran jail sentence appeal, family says
Source: Blockchain.info
https://www.qubes-os.org/news/2026/06/03/canary-047/
We have published Qubes Canary 047 (https://github.com/QubesOS/qubes-secpack/blob/5e7150d2731e1fb3979520e3e72e4d76d1e22c07/canaries/canary-047-2026.txt). The text of this canary and its accompanying cryptographic signatures are reproduced below. For an explanation of this announcement and instructions for authenticating this canary, please see the end of this announcement.
Qubes Canary 047
---===[ Qubes Canary 047 ]===---
Statements
-----------
The Qubes security team members who have digitally signed this file [1]
state the following:
1. The date of issue of this canary is June 03, 2026.
2. There have been 114 Qubes security bulletins published so far.
3. The Qubes Master Signing Key fingerprint is:
427F 11FD 0FAA 4B08 0123 F01C DDFA 1A3E 3687 9494
4. No warrants have ever been served to us with regard to the Qubes OS
Project (e.g. to hand out the private signing keys or to introduce
backdoors).
5. We plan to publish the next of these canary statements in the first
fourteen days of September 2026. Special note should be taken if no new
canary is published by that time or if the list of statements changes
without plausible explanation.
Special announcements
----------------------
None.
Disclaimers and notes
----------------------
We would like to remind you that Qubes OS has been designed under the
assumption that all relevant infrastructure is permanently compromised.
This means that we assume NO trust in any of the servers or services
which host or provide any Qubes-related data, in particular, software
updates, source code repositories, and Qubes ISO downloads.
This canary scheme is not infallible. Although signing the declaration
makes it very difficult for a third party to produce arbitrary
declarations, it does not prevent them from using force or other means,
like blackmail or compromising the signers' laptops, to coerce us to
produce false declarations.
The proof of freshness provided below serves to demonstrate that this
canary could not have been created prior to the date stated. It shows
that a series of canaries was not created in advance.
This declaration is merely a best effort and is provided without any
guarantee or warranty. It is not legally binding in any way to anybody.
None of the signers should be ever held legally responsible for any of
the statements made here.
Proof of freshness
-------------------
Wed, 03 Jun 2026 02:51:46 +0000
Source: DER SPIEGEL - International (https://www.spiegel.de/international/index.rss)
NSDAP archive: How DER SPIEGEL processed the data from the Nazi card file
Interactive Research Tool: What Your Family Did Under Hitler – Find Out Here
Human Rights in the US: Meet the Transgender Americans Forced to Flee GOP Persecution
An Interview with Maduro's Son: "We Should Have Done More to Protect My Father"
Forced Mercenaries: How Russia Dupes Kenyans into Fighting in Ukraine
Source: NYT > World News (https://rss.nytimes.com/services/xml/rss/nyt/World.xml)
Iran War Live Updates: Iran Targets Neighbors as U.S. Condemns ‘Aggressive’ Strikes
Russia Launches Deadly Strikes on Kyiv After Threatening Ukraine for a Week
U.S. Ebola Unit Plans in Kenya, Subject of Protests, Suffers New Setback From Court Ruling
The New Zealand Parakeet Pair That Are Saving Their Species
U.S. Was Asked to Blacklist Colombian Cartel Gold. It Was Also Buying It.
Source: BBC News (https://feeds.bbci.co.uk/news/world/rss.xml)
Israel strikes southern Lebanon but partial truce with Hezbollah appears to hold
US and Iran launch new strikes as ceasefire negotiations stall
Putin remains uncompromising on Ukraine, but is public discourse on war changing in Russia?
'They'll fix the building, but not our souls': Sleepy Kyiv neighbourhood hit in Russian strike
British couple lose Iran jail sentence appeal, family says
Source: Blockchain.info
00000000000000000001c7c4fb4f5b739e74f18ca4b3b6add30011982c0735d7
Footnotes
----------
[1] This file should be signed in two ways: (1) via detached PGP
signatures by each of the signers, distributed together with this canary
in the qubes-secpack.git repo, and (2) via digital signatures on the
corresponding qubes-secpack.git repo tags. [2]
[2] Don't just trust the contents of this file blindly! Verify the
digital signatures! Instructions for doing so are documented here:
https://doc.qubes-os.org/en/latest/project-security/security-pack.html
--
The Qubes Security Team
https://www.qubes-os.org/security/
Source: canary-047-2026.txt (https://github.com/QubesOS/qubes-secpack/blob/5e7150d2731e1fb3979520e3e72e4d76d1e22c07/canaries/canary-047-2026.txt)
Marek Marczykowski-Górecki (https://www.qubes-os.org/team/#marek-marczykowski-g%C3%B3recki)’s PGP signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmogGGoACgkQ1lWk8hgw
4GqoLxAAgGBg5spc/nfW5c04S0nP7WhAgrBsjsLJEG2COhYhc2rK5IiLVYd1JroF
QJiqw4OLmBoCCka+QFUmhsnPK2iQ+IVdm9uSPcyBkhBHk6C1RYEbyJFMqVhWzaCf
v846YoAeQuKTZAQHb+BsdL/4uQNRI8bhmdIs6mqE3cxdGoqzalitfQ8Un0dv67Ma
LqZM48GpiBZipuwpzMHNQ49IRNvjO+wArLrlNaoPtJD9VJAQcjp5772xXI2mWCj7
2BCwoZQ2vvcQA5qg/QL9WWFt9AYcp5kxZXkaGbjzX60wPwSYFz8xPHHsAP2sSbap
a6npFo49QX+V8ho8a3q811dw0q6FCiurip4D2MTTSqDQBzxb8boRl43mZcaZhc6I
GzKeY/VuH30YLuP6QoItTj1cW1APVgDh6KVSWhE2pZgjfRxsimMJti7dY3FX91oF
twIZog8Z7CmlKumhH459YABTKoLR0YQLdVqlyGXROOvX3C5kZw2FBbfiTtkjmg9O
aNb+GJ2ihBjUYkW3k+WHKJdA5rnd9VzYd+9w0wEnr02U/Ghh8o6BmEQQbdrMemso
TuuupdLkylN19oPltjhmtBl7qe5XA1cshkCngcLhom99WgeQIfayUUEUwsPQMbCC
HzYqOb8YCvntllFGcAHyyhxGizJUgIa9e6xogwP9DRT5DOCXevE=
=v00t
-----END PGP SIGNATURE-----
Source: canary-047-2026.txt.sig.marmarek (https://github.com/QubesOS/qubes-secpack/blob/5e7150d2731e1fb3979520e3e72e4d76d1e22c07/canaries/canary-047-2026.txt.sig.marmarek)
Simon Gaiser (aka HW42) (https://www.qubes-os.org/team/#simon-gaiser-aka-hw42)’s PGP signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmogYMsACgkQSsGN4REu
FJCGMQ/7BfF8If6ooYaRvVxR/I/dqGBnE5vqmlKti89OfAHynZw4XpXbAsDXqZKV
mPTRBMzfy5L9Ujo0xtmqg0+fMmhjzLqqUSlSRyZgGRUvkYkEV3tfG9qr0LWZmJLA
dREye5fH5QYggcGUqZjRwcmSavdc/HfnTx6xW/yKzqH+43Gn3iAuHzr47J+vpvv3
Abr6aK1YKQGy5IvJ+CV5/9U4x+cDtYnuXqWoIZq0R8uHj1p4+wUnzWH1CIs1OKGQ
nVUx0g6SH7ktqjGubhLIVGkPX6j/dKFN1OB1Qn2ooHQbqaHa4wDUM8TqdDna4gBP
Batcgo6Kp7e+kec+OtEOHIjyFySNrNRtMpEI6cfVKmrGcBNDeWyfdV+5lpJtg4GP
0MyvgLovwYONkb8fWR25tAWj3O54Fjkydts9uM5cLWQBlQqUIbQBVRcXtHRmKgZS
vrPf7ORjdBXf86CS35FTrwjKV9CcecZYgtQMthLOaYcsP4H5NKfnDr+4tyilaFjD
dkl8rR6EbC+YV4OBNc+6OFBK9x7rV+uOrNqq00QHmsFw+jDEnQMKotWu49oZcszH
2vETkeXmJz0Mgs2H9KaY6xURj8bGHOGUfVSbZa1d55h+9R15j+94Hni/UyekgpEq
AJ65/grY6xJ9iumeCFZhNYywvOzkeAQ2viDKzv9VfWcG31msmno=
=ViwC
-----END PGP SIGNATURE-----
Source: canary-047-2026.txt.sig.simon (https://github.com/QubesOS/qubes-secpack/blob/5e7150d2731e1fb3979520e3e72e4d76d1e22c07/canaries/canary-047-2026.txt.sig.simon)
What is the purpose of this announcement?
The purpose of this announcement is to inform the Qubes community that a new Qubes canary has been published.
What is a Qubes canary?
A Qubes canary (https://www.qubes-os.org/security/canary/) is a security announcement periodically issued by the Qubes security team (https://doc.qubes-os.org/en/latest/project-security/security.html#qubes-security-team) consisting of several statements to the effect that the signers of the canary have not been compromised. The idea is that, as long as signed canaries including such statements continue to be published, all is well. However, if the canaries should suddenly cease, if one or more signers begin declining to sign them, or if the included statements change significantly without plausible explanation, then this may indicate that something has gone wrong.
Footnotes
----------
[1] This file should be signed in two ways: (1) via detached PGP
signatures by each of the signers, distributed together with this canary
in the qubes-secpack.git repo, and (2) via digital signatures on the
corresponding qubes-secpack.git repo tags. [2]
[2] Don't just trust the contents of this file blindly! Verify the
digital signatures! Instructions for doing so are documented here:
https://doc.qubes-os.org/en/latest/project-security/security-pack.html
--
The Qubes Security Team
https://www.qubes-os.org/security/
Source: canary-047-2026.txt (https://github.com/QubesOS/qubes-secpack/blob/5e7150d2731e1fb3979520e3e72e4d76d1e22c07/canaries/canary-047-2026.txt)
Marek Marczykowski-Górecki (https://www.qubes-os.org/team/#marek-marczykowski-g%C3%B3recki)’s PGP signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmogGGoACgkQ1lWk8hgw
4GqoLxAAgGBg5spc/nfW5c04S0nP7WhAgrBsjsLJEG2COhYhc2rK5IiLVYd1JroF
QJiqw4OLmBoCCka+QFUmhsnPK2iQ+IVdm9uSPcyBkhBHk6C1RYEbyJFMqVhWzaCf
v846YoAeQuKTZAQHb+BsdL/4uQNRI8bhmdIs6mqE3cxdGoqzalitfQ8Un0dv67Ma
LqZM48GpiBZipuwpzMHNQ49IRNvjO+wArLrlNaoPtJD9VJAQcjp5772xXI2mWCj7
2BCwoZQ2vvcQA5qg/QL9WWFt9AYcp5kxZXkaGbjzX60wPwSYFz8xPHHsAP2sSbap
a6npFo49QX+V8ho8a3q811dw0q6FCiurip4D2MTTSqDQBzxb8boRl43mZcaZhc6I
GzKeY/VuH30YLuP6QoItTj1cW1APVgDh6KVSWhE2pZgjfRxsimMJti7dY3FX91oF
twIZog8Z7CmlKumhH459YABTKoLR0YQLdVqlyGXROOvX3C5kZw2FBbfiTtkjmg9O
aNb+GJ2ihBjUYkW3k+WHKJdA5rnd9VzYd+9w0wEnr02U/Ghh8o6BmEQQbdrMemso
TuuupdLkylN19oPltjhmtBl7qe5XA1cshkCngcLhom99WgeQIfayUUEUwsPQMbCC
HzYqOb8YCvntllFGcAHyyhxGizJUgIa9e6xogwP9DRT5DOCXevE=
=v00t
-----END PGP SIGNATURE-----
Source: canary-047-2026.txt.sig.marmarek (https://github.com/QubesOS/qubes-secpack/blob/5e7150d2731e1fb3979520e3e72e4d76d1e22c07/canaries/canary-047-2026.txt.sig.marmarek)
Simon Gaiser (aka HW42) (https://www.qubes-os.org/team/#simon-gaiser-aka-hw42)’s PGP signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmogYMsACgkQSsGN4REu
FJCGMQ/7BfF8If6ooYaRvVxR/I/dqGBnE5vqmlKti89OfAHynZw4XpXbAsDXqZKV
mPTRBMzfy5L9Ujo0xtmqg0+fMmhjzLqqUSlSRyZgGRUvkYkEV3tfG9qr0LWZmJLA
dREye5fH5QYggcGUqZjRwcmSavdc/HfnTx6xW/yKzqH+43Gn3iAuHzr47J+vpvv3
Abr6aK1YKQGy5IvJ+CV5/9U4x+cDtYnuXqWoIZq0R8uHj1p4+wUnzWH1CIs1OKGQ
nVUx0g6SH7ktqjGubhLIVGkPX6j/dKFN1OB1Qn2ooHQbqaHa4wDUM8TqdDna4gBP
Batcgo6Kp7e+kec+OtEOHIjyFySNrNRtMpEI6cfVKmrGcBNDeWyfdV+5lpJtg4GP
0MyvgLovwYONkb8fWR25tAWj3O54Fjkydts9uM5cLWQBlQqUIbQBVRcXtHRmKgZS
vrPf7ORjdBXf86CS35FTrwjKV9CcecZYgtQMthLOaYcsP4H5NKfnDr+4tyilaFjD
dkl8rR6EbC+YV4OBNc+6OFBK9x7rV+uOrNqq00QHmsFw+jDEnQMKotWu49oZcszH
2vETkeXmJz0Mgs2H9KaY6xURj8bGHOGUfVSbZa1d55h+9R15j+94Hni/UyekgpEq
AJ65/grY6xJ9iumeCFZhNYywvOzkeAQ2viDKzv9VfWcG31msmno=
=ViwC
-----END PGP SIGNATURE-----
Source: canary-047-2026.txt.sig.simon (https://github.com/QubesOS/qubes-secpack/blob/5e7150d2731e1fb3979520e3e72e4d76d1e22c07/canaries/canary-047-2026.txt.sig.simon)
What is the purpose of this announcement?
The purpose of this announcement is to inform the Qubes community that a new Qubes canary has been published.
What is a Qubes canary?
A Qubes canary (https://www.qubes-os.org/security/canary/) is a security announcement periodically issued by the Qubes security team (https://doc.qubes-os.org/en/latest/project-security/security.html#qubes-security-team) consisting of several statements to the effect that the signers of the canary have not been compromised. The idea is that, as long as signed canaries including such statements continue to be published, all is well. However, if the canaries should suddenly cease, if one or more signers begin declining to sign them, or if the included statements change significantly without plausible explanation, then this may indicate that something has gone wrong.
What are some signs of an unhealthy canary?
Here is a non-exhaustive list of examples:
Dead canary. In each canary, we state a window of time during which you should expect the next canary to be published. If no canary is published within that window of time and no good explanation is provided for missing the deadline, then the canary has died.
Missing statement(s). Canaries include a set of numbered statements at the top. These statements are generally the same across canaries, except for specific numbers and dates that have changed since the previous canary. If an important statement was present in older canaries but suddenly goes missing from new canaries with no correction or explanation, then this may be an indication that the signers can no longer truthfully make that statement.
Missing signature(s). Qubes canaries are signed by the members of the Qubes security team (https://doc.qubes-os.org/en/latest/project-security/security.html#qubes-security-team) (see below). If one of them has been signing all canaries but suddenly and permanently stops signing new canaries without any explanation, then this may indicate that this person is under duress or can no longer truthfully sign the statements contained in the canary.
Does every unexpected or unusual occurrence related to a canary indicate something bad?
No, there are many canary-related possibilities that should not worry you. Here is a non-exhaustive list of examples:
Unusual reposts. The only canaries that matter are the ones that are validly signed in the Qubes security pack (qubes-secpack) (https://doc.qubes-os.org/en/latest/project-security/security-pack.html). Reposts of canaries (like the one in this announcement) do not have any authority (except insofar as they reproduce validly-signed text from the qubes-secpack). If the actual canary in the qubes-secpack is healthy, but reposts are late, absent, or modified on the website, mailing lists, forum, or social media platforms, you should not be concerned about the canary.
Last-minute signature(s). If the canary is signed at the last minute but before the deadline, that’s okay. (People get busy and procrastinate sometimes.)
Signatures at different times. If one signature is earlier or later than the other, but both are present within a reasonable period of time, that’s okay. (For example, sometimes one signer is out of town, but we try to plan the deadlines around this.)
Permitted changes. If something about a canary changes without violating any of the statements in prior canaries, that’s okay. (For example, canaries are usually scheduled for the first fourteen days of a given month, but there’s no rule that says they have to be.)
Unusual but planned changes. If something unusual happens, but it was announced in advance, and the appropriate statements are signed, that’s okay (e.g., when Joanna left the security team and Simon joined it).
In general, it would not be realistic for an organization to exist that never changed, had zero turnover, and never made mistakes. Therefore, it would be reasonable to expect such events to occur periodically, and it would be unreasonable to regard every unusual or unexpected canary-related event as a sign of compromise. For example, if something usual happens with a canary, and we say it was a mistake and correct it (with valid signatures), you will have to decide for yourself whether it’s more likely that it really was just a mistake or that something is wrong and that this is how we chose to send you a subtle signal about it. This will require you to think carefully about which among many possible scenarios is most likely given the evidence available to you. Since this is fundamentally a matter of judgment, canaries are ultimately a social scheme, not a technical one.
What are the PGP signatures that accompany canaries?
Here is a non-exhaustive list of examples:
Dead canary. In each canary, we state a window of time during which you should expect the next canary to be published. If no canary is published within that window of time and no good explanation is provided for missing the deadline, then the canary has died.
Missing statement(s). Canaries include a set of numbered statements at the top. These statements are generally the same across canaries, except for specific numbers and dates that have changed since the previous canary. If an important statement was present in older canaries but suddenly goes missing from new canaries with no correction or explanation, then this may be an indication that the signers can no longer truthfully make that statement.
Missing signature(s). Qubes canaries are signed by the members of the Qubes security team (https://doc.qubes-os.org/en/latest/project-security/security.html#qubes-security-team) (see below). If one of them has been signing all canaries but suddenly and permanently stops signing new canaries without any explanation, then this may indicate that this person is under duress or can no longer truthfully sign the statements contained in the canary.
Does every unexpected or unusual occurrence related to a canary indicate something bad?
No, there are many canary-related possibilities that should not worry you. Here is a non-exhaustive list of examples:
Unusual reposts. The only canaries that matter are the ones that are validly signed in the Qubes security pack (qubes-secpack) (https://doc.qubes-os.org/en/latest/project-security/security-pack.html). Reposts of canaries (like the one in this announcement) do not have any authority (except insofar as they reproduce validly-signed text from the qubes-secpack). If the actual canary in the qubes-secpack is healthy, but reposts are late, absent, or modified on the website, mailing lists, forum, or social media platforms, you should not be concerned about the canary.
Last-minute signature(s). If the canary is signed at the last minute but before the deadline, that’s okay. (People get busy and procrastinate sometimes.)
Signatures at different times. If one signature is earlier or later than the other, but both are present within a reasonable period of time, that’s okay. (For example, sometimes one signer is out of town, but we try to plan the deadlines around this.)
Permitted changes. If something about a canary changes without violating any of the statements in prior canaries, that’s okay. (For example, canaries are usually scheduled for the first fourteen days of a given month, but there’s no rule that says they have to be.)
Unusual but planned changes. If something unusual happens, but it was announced in advance, and the appropriate statements are signed, that’s okay (e.g., when Joanna left the security team and Simon joined it).
In general, it would not be realistic for an organization to exist that never changed, had zero turnover, and never made mistakes. Therefore, it would be reasonable to expect such events to occur periodically, and it would be unreasonable to regard every unusual or unexpected canary-related event as a sign of compromise. For example, if something usual happens with a canary, and we say it was a mistake and correct it (with valid signatures), you will have to decide for yourself whether it’s more likely that it really was just a mistake or that something is wrong and that this is how we chose to send you a subtle signal about it. This will require you to think carefully about which among many possible scenarios is most likely given the evidence available to you. Since this is fundamentally a matter of judgment, canaries are ultimately a social scheme, not a technical one.
What are the PGP signatures that accompany canaries?
A PGP (https://en.wikipedia.org/wiki/Pretty_Good_Privacy) signature is a cryptographic digital signature (https://en.wikipedia.org/wiki/Digital_signature) made in accordance with the OpenPGP (https://en.wikipedia.org/wiki/Pretty_Good_Privacy#OpenPGP) standard. PGP signatures can be cryptographically verified with programs like GNU Privacy Guard (GPG) (https://en.wikipedia.org/wiki/GNU_Privacy_Guard). The Qubes security team cryptographically signs all canaries so that Qubes users have a reliable way to check whether canaries are genuine. The only way to be certain that a canary is authentic is by verifying its PGP signatures.
Why should I care whether a canary is authentic?
If you fail to notice that a canary is unhealthy or has died, you may continue to trust the Qubes security team even after they have signaled via the canary (or lack thereof) that they been compromised or coerced.
Alternatively, an adversary could fabricate a canary in an attempt to deceive the public. Such a canary would not be validly signed, but users who neglect to check the signatures on the fake canary would not be aware of this, so they may mistakenly believe it to be genuine, especially if it closely mimics the language of authentic canaries. Such falsified canaries could include manipulated text designed to sow fear, uncertainty, and doubt about the security of Qubes OS or the status of the Qubes OS Project.
How do I verify the PGP signatures on a canary?
The following command-line instructions assume a Linux system with git and gpg installed. (For Windows and Mac options, see OpenPGP software (https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#openpgp-software).)
Obtain the Qubes Master Signing Key (QMSK), e.g.:
$ gpg --fetch-keys https://keys.qubes-os.org/keys/qubes-master-signing-key.asc
gpg: directory '/home/user/.gnupg' created
gpg: keybox '/home/user/.gnupg/pubring.kbx' created
gpg: requesting key from 'https://keys.qubes-os.org/keys/qubes-master-signing-key.asc'
gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
gpg: key DDFA1A3E36879494: public key "Qubes Master Signing Key" imported
gpg: Total number processed: 1
gpg: imported: 1
(For more ways to obtain the QMSK, see How to import and authenticate the Qubes Master Signing Key (https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#how-to-import-and-authenticate-the-qubes-master-signing-key).)
View the fingerprint of the PGP key you just imported. (Note: gpg> indicates a prompt inside of the GnuPG program. Type what appears after it when prompted.)
$ gpg --edit-key 0x427F11FD0FAA4B080123F01CDDFA1A3E36879494
gpg (GnuPG) 2.2.27; Copyright (C) 2021 Free Software Foundation, Inc.
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
pub rsa4096/DDFA1A3E36879494
created: 2010-04-01 expires: never usage: SC
trust: unknown validity: unknown
[ unknown] (1). Qubes Master Signing Key
gpg> fpr
pub rsa4096/DDFA1A3E36879494 2010-04-01 Qubes Master Signing Key
Primary key fingerprint: 427F 11FD 0FAA 4B08 0123 F01C DDFA 1A3E 3687 9494
Important: At this point, you still don’t know whether the key you just imported is the genuine QMSK or a forgery. In order for this entire procedure to provide meaningful security benefits, you must authenticate the QMSK out-of-band. Do not skip this step! The standard method is to obtain the QMSK fingerprint from multiple independent sources in several different ways and check to see whether they match the key you just imported. For more information, see How to import and authenticate the Qubes Master Signing Key (https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#how-to-import-and-authenticate-the-qubes-master-signing-key).
Why should I care whether a canary is authentic?
If you fail to notice that a canary is unhealthy or has died, you may continue to trust the Qubes security team even after they have signaled via the canary (or lack thereof) that they been compromised or coerced.
Alternatively, an adversary could fabricate a canary in an attempt to deceive the public. Such a canary would not be validly signed, but users who neglect to check the signatures on the fake canary would not be aware of this, so they may mistakenly believe it to be genuine, especially if it closely mimics the language of authentic canaries. Such falsified canaries could include manipulated text designed to sow fear, uncertainty, and doubt about the security of Qubes OS or the status of the Qubes OS Project.
How do I verify the PGP signatures on a canary?
The following command-line instructions assume a Linux system with git and gpg installed. (For Windows and Mac options, see OpenPGP software (https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#openpgp-software).)
Obtain the Qubes Master Signing Key (QMSK), e.g.:
$ gpg --fetch-keys https://keys.qubes-os.org/keys/qubes-master-signing-key.asc
gpg: directory '/home/user/.gnupg' created
gpg: keybox '/home/user/.gnupg/pubring.kbx' created
gpg: requesting key from 'https://keys.qubes-os.org/keys/qubes-master-signing-key.asc'
gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
gpg: key DDFA1A3E36879494: public key "Qubes Master Signing Key" imported
gpg: Total number processed: 1
gpg: imported: 1
(For more ways to obtain the QMSK, see How to import and authenticate the Qubes Master Signing Key (https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#how-to-import-and-authenticate-the-qubes-master-signing-key).)
View the fingerprint of the PGP key you just imported. (Note: gpg> indicates a prompt inside of the GnuPG program. Type what appears after it when prompted.)
$ gpg --edit-key 0x427F11FD0FAA4B080123F01CDDFA1A3E36879494
gpg (GnuPG) 2.2.27; Copyright (C) 2021 Free Software Foundation, Inc.
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
pub rsa4096/DDFA1A3E36879494
created: 2010-04-01 expires: never usage: SC
trust: unknown validity: unknown
[ unknown] (1). Qubes Master Signing Key
gpg> fpr
pub rsa4096/DDFA1A3E36879494 2010-04-01 Qubes Master Signing Key
Primary key fingerprint: 427F 11FD 0FAA 4B08 0123 F01C DDFA 1A3E 3687 9494
Important: At this point, you still don’t know whether the key you just imported is the genuine QMSK or a forgery. In order for this entire procedure to provide meaningful security benefits, you must authenticate the QMSK out-of-band. Do not skip this step! The standard method is to obtain the QMSK fingerprint from multiple independent sources in several different ways and check to see whether they match the key you just imported. For more information, see How to import and authenticate the Qubes Master Signing Key (https://doc.qubes-os.org/en/latest/project-security/verifying-signatures.html#how-to-import-and-authenticate-the-qubes-master-signing-key).