Menu

Monthly Archives: February 2025

Are pre-owned smartphones safe? How to choose a second-hand phone and avoid security risks

Buying a pre-owned phone doesn’t have to mean compromising your security – take these steps to enjoy the benefits of cutting-edge technology at a fraction of the cost

Philip Torr: AI to the people | Starmus highlights

We’re on the cusp of a technological revolution that is poised to transform our lives – and we hold the power to shape its impact

Month in security with Tony Anscombe – November 2024 edition

Zero days under attack, a new advisory from ‘Five Eyes’, thousands of ICS units left exposed, and mandatory MFA for all – it’s a wrap on another month filled with impactful cybersecurity news

Achieving cybersecurity compliance in 5 steps

Cybersecurity compliance may feel overwhelming, but a few clear steps can make it manageable and ensure your business stays on the right side of regulatory requirements

Bootkitty marks a new chapter in the evolution of UEFI threats

ESET researchers make a discovery that signals a shift on the UEFI threat landscape and underscores the need for vigilance against future threats

Richard Marko: Rethinking cybersecurity in the age of global challenges | Starmus highlights

ESET’s CEO unpacks the complexities of cybersecurity in today’s hyper-connected world and highlights the power of innovation in stopping digital threats in their tracks

Firefox and Windows zero days chained to deliver the RomCom backdoor

The backdoor can execute commands and lets attackers download additional modules onto the victim’s machine, ESET research finds

Scams to look out for this holiday season

‘Tis the season to be wary – be on your guard and don’t let fraud ruin your shopping spree

Bootkitty: Analyzing the first UEFI bootkit for Linux

ESET researchers analyze the first UEFI bootkit designed for Linux systems

RomCom exploits Firefox and Windows zero days in the wild

ESET Research details the analysis of a previously unknown vulnerability in Mozilla products exploited in the wild and another previously unknown Microsoft Windows vulnerability, combined in a zero-click exploit

Kathryn Thornton: Correcting Hubble’s vision | Starmus highlights

The veteran of four space missions discusses challenges faced by the Hubble Space Telescope and how human ingenuity and teamwork made Hubble’s success possible

My information was stolen. Now what?

The slow and painful recovery process

ESET APT Activity Report Q2 2024–Q3 2024: Key findings

ESET Chief Security Evangelist Tony Anscombe highlights some of the most intriguing insights revealed in the latest ESET APT Activity Report

What is “Scam Likely”? Putting the phone down on unwanted calls

Tired of dodging all those ‘Scam Likely’ calls? Here’s what’s behind the label and how to stay one step ahead of phone scammers.

Unveiling WolfsBane: Gelsemium’s Linux counterpart to Gelsevirine

ESET researchers analyzed previously unknown Linux backdoors that are connected to known Windows malware used by the China-aligned Gelsemium group, and to Project Wood

ESET Research Podcast: Gamaredon

ESET researchers introduce the Gamaredon APT group, detailing its typical modus operandi, unique victim profile, vast collection of tools and social engineering tactics, and even its estimated geolocation

Beats by bot: The AI remix revolution

Artificial intelligence is reshaping the music landscape, turning listeners into creators and sparking new debates over creativity, copyright, and the future of music

Beyond the checkbox: Demystifying cybersecurity compliance

In an era of escalating digital threats, cybersecurity compliance goes beyond ticking a legal box – it’s a crucial shield safeguarding assets, reputation, and the very survival of your business

XCSSET macOS malware returns with first new version since 2022

The following vulnerability has been discovered in the glog package for Go: When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process’s log file path

3 key features of Postman’s AI Agent Builder
How to keep AI hallucinations out of your code
What if generative AI can’t get it right?
Twin Google flaws allowed researcher to get from YouTube ID to Gmail address in a few easy steps
Fujitsu worries US tariffs will see its clients slow digital spend
This open text-to-speech model needs just seconds of audio to clone your voice

Multiple vulnerabilties have been found in freelrdp2, a free implementation of the Remote Desktop Protocol (RDP). The vulnerabilties potentially allows authentication bypasses on configuration errors, buffer overreads, DoS vectors, buffer overflows or accessing files

ClatScope: Streamlining OSINT for Security and Linux Admins

Update to 133.0.6943.98 CVE-2025-0995: Use after free in V8 CVE-2025-0996: Inappropriate implementation in Browser UI CVE-2025-0997: Use after free in Navigation CVE-2025-0998: Out of bounds memory access in V8

Update to upstream 2.1-48. 20250211 Addition of 06-bf-06/0x07 microcode (in intel-ucode/06-97-02) at revision 0x38; Addition of 06-bf-07/0x07 microcode (in intel-ucode/06-97-02) at revision 0x38; Addition of 06-bf-06/0x07 microcode (in intel-ucode/06-97-05) at revision 0x38; Addition of 06-bf-07/0x07 microcode (in intel-ucode/06-97-05) at revision 0x38;

Update to 133.0.6943.98 CVE-2025-0995: Use after free in V8 CVE-2025-0996: Inappropriate implementation in Browser UI CVE-2025-0997: Use after free in Navigation CVE-2025-0998: Out of bounds memory access in V8

Multiple vulnerabilities were fixed in trafficserver, a caching proxy server. CVE-2024-38479

C’©dric Krier has found that trytond, the Tryton application server, accepts compressed content from unauthenticated requests which makes it vulnerable to zip bomb attacks (see DLA 4022-1).

Buckle up for faster Python programs
Nearly 10 years after Data and Goliath, Bruce Schneier says: Privacy’s still screwed
EPMS: the cornerstone of cybersecurity in defense operations
Democratize security processes in your software development lifecycle

Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162

Latest upstream release. It adds support for tiles and fixes reading images generated by iOS 18+. See https://github.com/strukturag/libheif/releases for more details about the changes since 1.17.6. NOTE: heif-convert tool was renamed to heif-dec. How to test:

Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.

Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.

Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.

Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.

AI coding assistants limited but helpful, developers say
If you dread a Microsoft Teams invite, just wait until it turns out to be a Russian phish
SonicWall firewalls now under attack: Patch ASAP or risk intrusion via your SSL VPN
Transparency in AI: How Open-Source LLMs Can Prevent Hidden Vulnerabilities
Critical PostgreSQL bug tied to zero-day attack on US Treasury

* bsc#1236878 Cross-References: * CVE-2024-12133

2 charged over alleged New IRA terrorism activity linked to cops’ spilled data

Several security issues were fixed in Apache ActiveMQ.

Watchdog ponders why Apple doesn’t apply its strict app tracking rules to itself
Buckle up for the supercharged Python interpreter
Avoiding the cloud migration graveyard

* bsc#1212641 * bsc#1219912 * bsc#1229079 * bsc#1229104 * bsc#1231024

* bsc#1212641 * bsc#1219912 * bsc#1229079 * bsc#1229104 * bsc#1231024

US charges two Russian men in connection with Phobos ransomware operation
Chinese spies suspected of ‘moonlighting’ as tawdry ransomware crooks

https://security-tracker.debian.org/tracker/DSA-5866-1

JetBrains’ Ktor adds CLI for simpler project creation
More victims of China’s Salt Typhoon crew emerge: Telcos just now hit via Cisco bugs
US lawmakers press Trump admin to oppose UK’s order for Apple iCloud backdoor
US Coast Guard told to improve its cybersecurity, after warning raised that hacked ports could cost $2 billion per day

* bsc#1012628 * bsc#1194869 * bsc#1215199 * bsc#1216813 * bsc#1218470

* bsc#1236705 Cross-References: * CVE-2025-0938

* bsc#1218879 * bsc#1218880 * bsc#1218881 * bsc#1218882 * bsc#1218883

* bsc#1228044 * bsc#1236282 Cross-References: * CVE-2025-0395

North Korea targets crypto developers via NPM supply chain attack
How to adopt platform engineering in 2025
US woman faces years in federal prison for running laptop farm for N Korean IT workers
How to use mutexes and semaphores in C#
Diving into the Windows Copilot Runtime
Mysterious Palo Alto firewall reboots? You’re not alone
Have I Been Pwned likely to ban resellers from buying subs, citing ‘sh*tty behavior’ and onerous support requests
Feds want devs to stop coding ‘unforgivable’ buffer overflow vulnerabilities
Sophos sheds 6% of staff after swallowing Secureworks
Go 1.24 arrives with generic type aliases, boosted WebAssembly support
Smashing Security podcast #404: Podcast not found
Trump’s cyber chief pick has little experience in The Cyber
Arizona laptop farmer pleads guilty for funneling $17M to Kim Jong Un
Ransomware isn’t always about the money: Government spies have objectives, too
UK, US, Oz blast holes in LockBit’s bulletproof hosting provider Zservers
Russia’s Sandworm caught snarfing credentials, data from American and Brit orgs
Snowflake announces preview of Cortex Agent APIs to power enterprise data intelligence
Crimelords and spies for rogue states are working together, says Google

* bsc#1229644 * bsc#1230998 * bsc#1231993 Cross-References:

* bsc#1229644 * bsc#1229663 * bsc#1230998 * bsc#1231993

* bsc#1230998 * bsc#1231993 Cross-References: * CVE-2024-45016

Dynamic web apps with HTMX, Python, and Django
Rust memory management explained
Keep your code open to possibilities
February’s Patch Tuesday sees Microsoft offer just 63 fixes
Don’t use public ASP.NET keys (duh), Microsoft warns