
Arch Linux Halts AUR Adoptions Due to Malware Risks; Apple-OpenAI Data Leak and Passkey Vulnerabilities Highlighted
On August 4, 2026, the SANS Internet Storm Center Stormcast reported that Arch Linux temporarily halted new adoption requests for user-maintained packages in its Arch User Repository (AUR) due to recurring malicious takeovers. Attackers exploited the adoption process to inject malware into abandoned but popular packages, with hundreds of suspicious packages already identified. The incident highlights risks in open-source package maintenance, particularly when unvetted users assume control of critical software. Separately, a legal dispute between Apple and OpenAI revealed that former Apple employees retained access to confidential data via iCloud, as employees often merged personal and work accounts to utilize Apple’s 2TB storage offering, leading to intellectual property leaks. Palo Alto Networks published research on passkey attacks, focusing on vulnerabilities in password manager sync mechanisms that could allow attackers to steal cryptographic keys, though this was framed as a trade-off for usability rather than a fundamental flaw. Additionally, N-able released a hotfix (version 2026.3.1.7) for its N-central product to address an actively exploited vulnerability initially patched in version 2026.3 but found incomplete.