Menu

Monthly Archives: February 2025

https://security-tracker.debian.org/tracker/DSA-5865-1

https://security-tracker.debian.org/tracker/DSA-5864-1

Probe finds US Coast Guard has left maritime cybersecurity adrift
Yup, AMD’s Elba and Giglio definitely sound like they work corporate security
‘Key kernel maintainers’ still back Rust in the Linux kernel, despite the doubters
Triplestrength hits victims with triple trouble: Ransomware, cloud hijacks, crypto-mining

https://security-tracker.debian.org/tracker/DSA-5863-1

OpenText recently surveyed 255 MSPs to uncover key trends shaping the future of Managed Detection and Response (MDR). The findings reveal not only what cybersecurity professionals are prioritizing but also how MSPs can better meet the evolving demands of their small and midsize business (SMB) customers. One key takeaway from the survey: 81% of respondents […]

Man who SIM-swapped the SEC’s X account pleads guilty
I’m a security expert, and I almost fell for a North Korea-style deepfake job applicant …Twice

* bsc#1228165 * bsc#1236705 Cross-References: * CVE-2025-0938

* bsc#1227056 * bsc#1236483 Cross-References: * CVE-2023-45288

* bsc#1218879 * bsc#1218880 * bsc#1218881 * bsc#1218882 * bsc#1218883

Why the generative AI hype is good
Review: Zencoder has a vision for AI coding
The cloud giants stumble
C++, Go, and Rust gaining popularity – Tiobe
Apple warns ‘extremely sophisticated attack’ may be targeting iThings
All your 8Base are belong to us: Ransomware crew busted in global sting
What you need to know about Python 3.14’s faster interpreter
Toll booth bandits continue to scam via SMS messages

February is a great month to refresh your cyber awareness skills. February 11 marks Safer Internet Day, encouraging us to work together to make the internet a safer and better place. It’s the perfect time to learn more about cybersecurity risks and best practices for protecting yourself and your loved ones online. And while February […]

Secret Taliban records published online after hackers breach computer systems
Navigating AI-Driven Security Challenges in Linux Environments
US news org still struggling to print papers a week after ‘cybersecurity event’

* bsc#1236619 * jsc#PED-12018 Cross-References: * CVE-2025-24528

* bsc#1233760 Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6

How Secure Is Linux? Examining Features That Ensure Safety
Secure Your DevTools: Critical UAF Vulnerability Warning
Firefox 135 Released: Key Updates & Advanced Browser Protection Features
Tails 6.12: An Essential Privacy, Security, and Reliability Upgrade

USN-7206-3 caused some regression in rsync.

Google’s generative AI Toolbox for Databases to help connect agents with databases
UK armed forces fast-tracking cyber warriors to defend digital front lines
Will Kubernetes ever get easier?
Are database administrators doomed?
When LLMs become influencers

* bsc#1236596 Cross-References: * CVE-2024-11187

Judge says US Treasury ‘more vulnerable to hacking’ since Trump let the DOGE out
India’s banking on the bank.in domain cleaning up its financial services sector
DeepSeek’s iOS app is a security nightmare, and that’s before you consider its TikTok links

https://security-tracker.debian.org/tracker/DSA-5862-1

Huawei revenue growing fast, suggesting China’s scoffing at sanctions

https://security-tracker.debian.org/tracker/DSA-5861-1

Vulnerabilities were found in sssd, a set of daemons to manage access to remote directories and authentication mechanisms, which could lead to privilege escalation.

update to 1.33.0

Security fix for CVE-2023-52892, CVE-2024-27354

Add code to deal with sched_setattr() not being exported in glibc 2.41 Address CVE-2024-54159 denial of services via symlink attack

Update to 1.17.3 Fixes CVE-2024-0134 or GHSA-7jm9-xpwx-v999 Fixes CVE-2024-0135 or GHSA-9v84-cc9j-pxr6, CVE-2024-0136 or GHSA- vcfp-63cx-4h59, and CVE-2024-0137 or GHSA-frhw-w3wm-6cw4

New ASPA support is now always compiled in and available if enable-aspa is set. The aspa Cargo feature has been removed. (#990) If merging mutliple ASPA objects for a single customer ASN results in more than 16,380 provider ASNs, the ASPA is dropped. (Note that ASPA objects with more

Updated to latest upstream (135.0)

Update to 0.8.4

xrdp allows an infinite number of login attempts. (CVE-2024-39917) References: – https://bugs.mageia.org/show_bug.cgi?id=33985 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/FMYGECEBC7XEBNQ2ZHXYRQBLCMHHXKP5/

When an input DER data contains a large number of SEQUENCE OF or SET OF elements, decoding the data and searching a specific element in it take quadratic time to complete. This could be utilized for a remote DoS attack by presenting a crafted certificate to the network peer.

Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.

Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.

https://security-tracker.debian.org/tracker/DSA-5860-1

UK Home Office silent on alleged Apple backdoor order

* bsc#1236270 Cross-References: * CVE-2024-11218

UK industry leaders unleash hurricane-grade scale for cyberattacks
Data breaches at UK law firms are on the rise, research reveals

A vulnerability has been discovered in the OpenJDK Java runtime, which may result in authorisation bypass or information disclosure. For Debian 11 bullseye, this problem has been fixed in version

Full-stack JavaScript leads the way
The hidden threat of neglected cloud infrastructure
Apple missed screenshot-snooping malware in code that made it into the App Store, Kaspersky claims

Updated to latest upstream (135.0)

If Ransomware Inc was a company, its 2024 results would be a horror show

Fix CVE-2025-0781

Fix CVE-2025-0781

GitHub Copilot previews agent mode
Coordinates of millions of smartphones feared stolen, sparking yet another lawsuit against data broker
Federal judge tightens DOGE leash over critical Treasury payment system access

https://security-tracker.debian.org/tracker/DSA-5859-1

Dems want answers on national security risks posed by hiring freeze, DOGE probes
Oracle maintains hold on JavaScript trademark
Thailand cuts power and internet to areas of Myanmar to disrupt scam gangs

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Google rolls out cheaper AI model as industry scrutinizes costs
Using NATS with .NET Aspire

Several security issues were fixed in Ruby.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Several security issues were fixed in CKEditor.

Democrats demand to know WTF is up with that DOGE server on OPM’s network

Fix for CVE-2025-0781

Robocallers who phoned the FCC pretending to be from the FCC land telco in trouble
Smashing Security podcast #403: Coinbase crypto heists, QR codes, and ransomware in the classroom
Mixing Rust and C in Linux likened to cancer by kernel maintainer
Malicious package found in the Go ecosystem

What are passkeys? You may have seen the term “passkeys” appearing more frequently in tech news, app updates, and security discussions. Major companies like Apple, Google, and Microsoft are rolling out passkeys as a replacement for passwords, promising both enhanced security and a smoother user experience. But what exactly are passkeys, and why are they […]

Digma Preemptive Observability Analysis engine tackles AI code bugs
DOGE latest: Citrix supremo has ‘read-only’ access to US Treasury payment system

Simplifying security management is an important step toward better protection without sacrificing operational efficiency. With the added capability of automating processes by integrating with popular tools, security management can also deliver streamlined workflows. OpenText Secure Cloud provides billing reconciliation by integrating with popular tools such as HaloPSA, ConnectWise PSA, AutoTask, and Kaseya BMS so you […]

Netgear fixes critical bugs as Five Eyes warn about break-ins at the edge