Menu

Monthly Archives: February 2025

Man sentenced to 7 years in prison for role in $50m internet scam
Is 2025 the year of quantum computing?
US cranks up espionage charges against ex-Googler accused of trade secrets heist
Common Vulnerability Scoring System (CVSS) vs. Risk: Why are we still having this conversation?
Databricks acquires BladeBridge to aid data warehouse migrations
How to make lightweight Docker images (and keep them slim)
Cloud development environments for the win
Smart Traffic Enforcement: Kazakhstan’s Qorgau System in Action

OpenJDK 23 could be made to expose sensitive information over the network.

OpenJDK 21 could be made to expose sensitive information over the network.

OpenJDK 17 could be made to expose sensitive information over the network.

OpenJDK 11 could be made to expose sensitive information over the network.

USN-7096-1 caused some minor regressions in OpenJDK 8.

AWS tightens default security on Redshift

Rebuilt against golang-x-net 0.33.0 for CVE-2024-45338

Rust update fixes ‘forever’ compilation

https://security-tracker.debian.org/tracker/DSA-5858-1

Google: How to make any AMD Zen CPU always generate 4 as a random number
Automated builds, tests, and quality gates are key to software quality – report
The AI Fix #36: A DeepSeek special
Poisoned Go programming language package lay undetected for 3 years
Grubhub serves up security incident with a side of needing to change your password
US accuses Canadian math prodigy of $65M crypto scheme
Cyberattack on NHS causes hospitals to miss cancer care targets
Abandoned AWS S3 buckets can be reused in supply-chain attacks that would make SolarWinds look ‘insignificant’
Anthropic unveils new framework to block harmful content from AI models
UK govt must learn fast and let failing projects die young
Not seeing ROI from your AI? Observability may be the missing link
What you need to know about developing AI agents
Public cloud providers are missing the mark with AI

* bsc#1236136 Cross-References: * CVE-2024-13176

* bsc#1236518 Cross-References: * CVE-2023-45288

* bsc#1236460 Cross-References: * CVE-2022-49043

Google patches odd Android kernel security bug amid signs of targeted exploitation
Why digital resilience is critical to banks

Updated to 132.0.6834.159 * Medium CVE-2025-0762: Use after free in DevTools

Linux Foundation warns of US OFAC sanctions
TSA’s airport facial-recog tech faces audit probe

When it comes to endpoint detection and response (EDR) compatibility within an MDR offering, managed service providers (MSPs) are weighing two key priorities: native EDR integration or the flexibility to support multiple solutions. According to a recent OpenText survey, opinions are split almost evenly. While 52% of MSPs view native compatibility as moderately or very […]

EU supports AI challenge to Silicon Valley and China
Download the Agentic AI Enterprise Spotlight
Responding to Chrome’s Latest Security Vulnerabilities: Update to Chrome 132 Now!
2 officers bailed as anti-corruption unit probes data payouts to N Irish cops
Solver can code that for you
Tetragon: Extending eBPF and Cilium to runtime security
The DeepSeek lesson

* bsc#1236518 Cross-References: * CVE-2023-45288

* bsc#1236272 Cross-References: * CVE-2024-11218 * CVE-2024-9407

* bsc#1236272 Cross-References: * CVE-2024-11218 * CVE-2024-9407

Matthias Gerstner reported that pam-u2f, a PAM module which allows to use U2F (Universal 2nd Factor) devices in the PAM authentication stack, does not properly handle PAM_IGNORE return values, allowing to bypass the second factor or password-less login without inserting the proper

Privacy Commissioner warns the ‘John Smiths’ of the world can acquire ‘digital doppelgangers’
Medical monitoring machines spotted stealing patient data, users warned to pull the plug ASAP

https://security-tracker.debian.org/tracker/DSA-5857-1

JavaScript Temporal to ease dates and times

Several issues have been found in ffmpeg, a package that contains tools for transcoding, streaming and playing of multimedia files Those issues are related to possible integer overflows, double-free on

What does it mean to build in security from the ground up?
Gilmore Girls fans nabbed as Eurocops dismantle two major cybercrime forums
Monitoring Red Hat Ansible Automation Platform using Performance Co-Pilot

Data Privacy Week (Jan. 27-31) is an excellent opportunity to reflect on the importance of protecting one of your most valuable assets: your personal information. Whether you’re browsing online as a consumer or running a business, data privacy is paramount in an environment where cyber threats can lurk around every corner. In the spirit of […]

Cyber threats have never been more relentless, and businesses of all sizes are feeling the pressure. That’s where Managed Detection and Response (MDR) comes in—a lifeline for overburdened security teams navigating a threat landscape that’s growing more sophisticated by the day. At its core, MDR is about augmenting, complementing, and upskilling internal security operations. It’s […]

update to 0.10.4

Updated to 132.0.6834.159 * Medium CVE-2025-0762: Use after free in DevTools

Rebase to 20.18.2 Resolves: CVE-2025-22150 CVE-2025-23085 CVE-2025-23083

Update to version 18.20.6 (rhbz#2341760) (rhbz#2340936) (rhbz#2300997) Resolves CVE-2025-23084

Rebase to 20.18.2 Resolves: CVE-2025-22150 CVE-2025-23085 CVE-2025-23083

Update to version 18.20.6 (rhbz#2341760) (rhbz#2340936) (rhbz#2300997) Resolves CVE-2025-23084

New ASPA support is now always compiled in and available if enable-aspa is set. The aspa Cargo feature has been removed. (#990) If merging mutliple ASPA objects for a single customer ASN results in more than 16,380 provider ASNs, the ASPA is dropped. (Note that ASPA objects with more