Canonical is replacing Ubuntu's separate four-week Stable Release Update and two-week security-update schedules with overlapping two-week kernel release cycles, delivering a new kernel release each week. Each cycle spends its first week on package preparation, builds, smoke testing, and publication to the -proposed archive; certification, integration, and regression testing occur during the second week before general availability.
The change responds to a growing volume of Linux kernel CVEs, including vulnerabilities identified through AI-assisted bug discovery and expanded upstream CVE assignment. Organizations that need patches sooner can deploy weekly -proposed release candidates, but must accept that Canonical certification is incomplete and assume more regression-testing responsibility. Canonical also plans to publish safe workarounds within 24–48 hours of public disclosure when fixes are unavailable, or provide hardening guidance where no workaround exists.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Canonical announced it is replacing separate four-week regular and two-week security Ubuntu kernel SRU schedules with overlapping two-week cycles, resulting in weekly kernel releases. The process publishes release candidates to the -proposed pocket after first-week preparation and testing, followed by certification, integration, and regression testing before standard release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.