Menu

Monthly Archives: February 2025

TrapC proposal to fix C/C++ memory safety
Rust 1.85 arrives with long-awaited async closures

https://security-tracker.debian.org/tracker/DSA-5871-1

Ransomware criminals love CISA’s KEV list – and that’s a bug, not a feature
Google’s AlloyDB is looking more and more like PostgreSQL

* bsc#1237093 Cross-References: * CVE-2025-1094

* bsc#1237431 Cross-References: * CVE-2025-26597

* bsc#1237431 Cross-References: * CVE-2025-26597

Do more with Python’s new built-in async programming library
The rising threat of shadow AI
Microsoft names alleged credential-snatching ‘Azure Abuse Enterprise’ operators
Feds: Army soldier suspected of AT&T heist Googled ‘can hacking be treason,’ ‘defecting to Russia’
What is retrieval-augmented generation? More accurate and reliable LLMs
FBI officially fingers North Korea for $1.5B Bybit crypto-burglary

https://security-tracker.debian.org/tracker/DSA-5870-1

Microsoft’s Phi-4-multimodal AI model handles speech, text, and video
Warning issued as hackers offer firms fake cybersecurity audits to break into their systems
DeepSeek offers steep discounts, escalating AI price war
Understanding thread synchronization in C#
What’s next for Microsoft’s Semantic Kernel?

Several security issues were fixed in PHP.

Does terrible code drive you mad? Wait until you see what it does to OpenAI’s GPT-4o

Multiple vulnerabilities were discovered in GNU Emacs, the extensible, customisable, self-documenting, real-time display editor. CVE-2023-28617

Libxmltok could be made to crash if it opened a specially crafted file.

Merge branch ‘f42’ into f41 Merge branch ‘rawhide’ into f41 Fix merge conflict

Microsoft’s .NET 10 arrives in first preview
Wallbleed vulnerability unearths secrets of China’s Great Firewall 125 bytes at a time
Smashing Security podcast #406: History’s biggest heist just happened, and online abuse
With millions upon millions of victims, scale of unstoppable info-stealer malware laid bare
Bybit declares war on North Korea’s Lazarus crime-ring to regain $1.5B stolen from wallet

A heap-based buffer overflow flaw in the decoding functions of openh264, a codec library which supports H.264 encoding and decoding, may allow a remote attacker to cause a denial of service or the execution of arbitrary code if a specially crafted video is processed.

New emacs packages are available for Slackware 15.0 and -current to fix security issues.

Qualcomm pledges 8 years of security updates for Android kit using its chips (YMMV)
Essential Updates for X.Org and XWayland Address Eight New Security Flaws
Signal will withdraw from Sweden if encryption-busting laws take effect

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Get started with async in Python
Plug-and-play web development with Astro
11 rules for writing better code
Red Hat OpenShift improves virtualization support

Cross-References: * CVE-2020-13936 CVSS scores:

200-plus impressively convincing GitHub repos are serving up malware

Upstream kernel version 6.6.79 fixes bugs and vulnerabilities. The kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.

Vanilla upstream kernel version 6.6.79 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=34024

Incoming deputy boss of Homeland Security says America’s top cyber-agency needs to be reined in
Cot framework aims to ease Rust web development
Drug-screening biz DISA took a year to disclose security breach affecting millions
Xi know what you did last summer: China was all up in Republicans’ email, says book
MITRE Caldera security suite scores perfect 10 for insecurity
IBM acquires DataStax to boost watsonx’s generative AI capabilities
Harassment allegations against DEF CON veteran detailed in court filing
The AI Fix #39: AIs value their lives over yours, and flattery gets you nowhere

Several security issues were fixed in the Linux kernel.

* bsc#1237058 * bsc#1237062 Cross-References: * CVE-2025-24031

* bsc#1227320 * bsc#1227371 * bsc#1228585 * bsc#1236783

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Google rolls out free version of Gemini Code Assist for individuals
Review: Gemini Code Assist is good at coding
What the private sector can teach government about cloud computing
Flaw found in stalkerware apps, exposing millions of people. Here’s how to find out if your phone is being spied upon
MongoDB acquires Voyage AI to reduce hallucinations in AI applications
Microsoft gives Azure AI users a place to experiment with latest technologies
Shifting the cybersecurity odds
The software UK techies need to protect themselves now Apple’s ADP won’t

* bsc#1233296 * bsc#1236278 * bsc#1236470 Cross-References:

* bsc#1233296 * bsc#1236278 * bsc#1236470 Cross-References:

* bsc#1236783 Cross-References: * CVE-2024-53104

* bsc#1227320 * bsc#1227371 * bsc#1228585 * bsc#1236783

10 machine learning mistakes and how to avoid them
A smarter approach to training AI models
AI coding assistants are on a downward spiral
Rather than add a backdoor, Apple decides to kill iCloud E2EE for UK peeps

Nearly every aspect of life is connected to the internet, so protecting your devices, identity, and privacy has never been more critical. Cyber threats are no longer just the occasional virus or suspicious email. Phishing scams, ransomware attacks, data breaches, and identity theft are part of a growing list of online dangers that are a […]

Cyber threats. Identity theft. Online profiling. Financial fraud. Social media misuse. The list just gets longer. As more aspects of our lives move online and digital devices proliferate, staying safe from threats has become more important than ever. Consider all the connected devices you use for daily tasks—browsing, shopping, banking, gaming, and more. Then think […]

OpenText recently surveyed 255 MSPs to uncover key trends shaping the future of Managed Detection and Response (MDR). One technology area it explored was security orchestration, automation, and response (SOAR)—the workhorse behind automating security workflows. The survey revealed several key benefits of SOAR in MDR, highlighting how it can help MSPs and SMBs improve incident […]

Security fixes for CVE-2024-11168 and CVE-2025-0938

update to 1.33.2 fix CVE-2025-24898

Security fixes for CVE-2024-11168 and CVE-2025-0938

update to 1.33.2 fix CVE-2025-24898

Multiple vulnerabilities have been found in libxml2, a library providing support to read, modify and write XML and HTML files. These vulnerabilities could potentially lead to denial of servie or other unintended behaviors.

Update to 133.0.6943.126 CVE-2025-0999: Heap buffer overflow in V8 CVE-2025-1426: Heap buffer overflow in GPU CVE-2025-1006: Use after free in Network

This update addresses a null pointer dereferencing issue that could cause the session for a client that sent specially-crafted commands to the server to crash (not the sessions of other clients).

This update addresses a null pointer dereferencing issue that could cause the session for a client that sent specially-crafted commands to the server to crash (not the sessions of other clients).

Amazon concedes that Chime SDK makes far more sense than the Chime application itself

Bing Shi discovered that GnuTLS, a portable library which implements the Transport Layer Security and Datagram Transport Layer Security protocols, had inefficient handling of certificate data with a large number of names or name constraints, potentially leading to Denial of

* bsc#1236946 Cross-References: * CVE-2024-27856 * CVE-2024-54543

Fake job offers target software developers with infostealers

A North Korea-aligned activity cluster tracked by ESET as DeceptiveDevelopment drains victims’ crypto wallets and steals their login details from web browsers and password managers

Experts race to extract intel from Black Basta internal chat leaks

* bsc#1237084 Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP6