Menu

Latest articles

Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.
Google fixes super-secret 8th Chrome 0-day
LastPass hammered with £1.2M fine for 2022 breach fiasco
AI vendors move to tackle the hidden cost of inefficient enterprise code
Researcher claims Salt Typhoon spies attended Cisco training scheme
Slash VM provisioning time on Red Hat Openshift Virtualization using Red Hat Ansible Automation Platform
Don’t just automate, validate: How to measure and grow your return on investment
An out-of-bounds read flaw was found in libsndfile’s FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with
10K Docker images spray live cloud creds across the internet
version update security update
1.282 – Sanitize all user-supplied values before inserting into HTTP headers; Fixed CVE-2025-40927.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, same-origin policy bypass or privilege escalation.
Users report chaos as Legal Aid Agency stumbles back online after cyberattack
Microsoft’s Dev Proxy puts APIs to the test
Document databases – understanding your options
Several security issues were fixed in libpng.
Qt could be made to crash or run programs as your login if it opened a specially crafted file.
It’s everyone but Meta in a new AI standards group
Did your npm pipeline break today? Check your ‘classic’ tokens
Smashing Security podcast #447: Grok the stalker, the Louvre heist, and Microsoft 365 mayhem
700+ self-hosted Gits battered in 0-day attacks with no fix imminent
US extradites Ukrainian woman accused of hacking meat processing plant for Russia
Microsoft won’t fix .NET RCE bug affecting slew of enterprise apps, researchers say
The big catch: How whaling attacks target top executives Is your organization’s senior leadership vulnerable to a cyber-harpooning? Learn how to keep them safe.
Ransomware may have extorted over $2.1 billion between 2022-2024, but it’s not all bad news, claims FinCEN report
Protecting value at risk – the role of a risk operations center
* bsc#1251198 * bsc#1251199 Cross-References: * CVE-2025-61984
* bsc#1238879 Cross-References: * CVE-2025-27516
* bsc#1254132 Cross-References: * CVE-2025-9820
Crisis in Icebergen: How NATO crafts stories to sharpen cyber skills
Four years later, Irish health service offers €750 to victims of ransomware attack
Insufficient validation of incoming notifies over TCP in PDNS Recursor, a resolving name server, could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 5.2.7-0+deb13u1. We recommend that you upgrade your pdns-recursor packages.
Why AI agents are so good at coding
PythoC: A new way to generate C code from Python
Is vibe coding the new gateway to technical debt?
Several vulnerabilities were reported in the libpng PNG library, which could lead to information leaks, denial of service or potentially the execution of arbitrary code if a specially crafted image is processed. For the oldstable distribution (bookworm), these problems have been fixed in version 1.6.39-2+deb12u1.
* bsc#1244485 * bsc#1245878 * bsc#1254227 * bsc#1254430 * bsc#1254431
GitHub Action Secrets aren’t secret anymore: exposed PATs now a direct path into cloud environments
Linux Foundation launches Agentic AI Foundation
https://security-tracker.debian.org/tracker/DSA-6075-1
https://security-tracker.debian.org/tracker/DSA-6076-1
https://security-tracker.debian.org/tracker/DSA-6077-1
https://security-tracker.debian.org/tracker/DSA-6078-1
https://security-tracker.debian.org/tracker/DSA-6079-1
Microsoft reports 7.8-rated zero day, plus 56 more in December Patch Tuesday
How to answer the door when the AI agents come knocking
Porsche panic in Russia as pricey status symbols forget how to car
Privacy concerns raised as Grok AI found to be a stalker’s best friend
California man admits role in $263 million cryptocurrency theft that funded lavish lifestyle
The AI Fix #80: DeepSeek’s cheap GPT-5 rival, Antigravity fails, and why being rude to AI makes it smarter