Menu

Monthly Archives: March 2025

Top cybersecurity boffin, wife vanish as FBI raids homes
New Python lock file format will specify dependencies
Oracle Cloud security SNAFU latest: IT giant accused of pedantry as evidence scrubbed
Apple’s Swift language gets version manager
Meet Giovanni Bechis: The New Lead of SpamAssassin’s Future
Check Point confirms breach, but says it was ‘old’ data and crook made ‘false’ claims
£3 million fine for healthcare MSP with sloppy security after it was hit by ransomware attack

A security issue was fixed in MariaDB.

* bsc#1237367 * bsc#1239185 * bsc#1239322 Cross-References:

* bsc#1234452 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5

The perl module Data::Entropy was using the cryptographically insecure rand() function as default entropy source. For Debian 11 bullseye, this problem has been fixed in version

Cloud security explained: What’s left exposed?
How AI is transforming IDEs into intelligent development assistants
14 alternative managed Kubernetes platforms
How Terraform is evolving infrastructure as code
China cracks down on personal information collection. No, seriously
Oracle Health reportedly warns of info leak from legacy server

Microcode updates has been released for Intel(R) processors, addressing multiple potential vulnerabilties that may allow local privilege escalation, denial of service or information disclosure.

Multiple vulnerabilities were discovered in vim, an enhanced vi editor. CVE-2021-3872

Update to 0.4.8; Fixes: RHBZ#2237964, RHBZ#2282129

An issue has been found in librabbitmq, a AMQP client library and tools written in C. The issue is related to credential visibility when

Malware in Lisp? Now you’re just being cruel

Update to 2.12.10

CVE-2025-2588

Google introduces Gemini 2.5 reasoning models
ECMAScript 2025 JavaScript standard takes shape

* bsc#1235147 Cross-References: * CVE-2024-5594

* bsc#1239685 Cross-References: * CVE-2025-2361

* bsc#1238685 Cross-References: * CVE-2025-22870

How Cloud Security is Transforming Cybersecurity Services
VanHelsing ransomware: what you need to know
Cardiff’s children’s chief confirms data leak 2 months after cyber risk was ‘escalated’
Thread-y or not, here’s Python!
Are we creating too many AI models?
After Chrome patches zero-day used to target Russians, Firefox splats similar bug
Cyber-crew claims it cracked American cableco, releases terrible music video to prove it

CVE-2025-2588

Update to 1.1.43, fixes CVE-2024-55549 and CVE-2025-24855.

Added patch for CVE-2024-4068 (rhbz#2280624)

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

China’s FamousSparrow flies back into action, breaches US org after years off the radar
Adobe announces AI agents for customer interaction

https://security-tracker.debian.org/tracker/DSA-5888-1

Several security issues were fixed in the Linux kernel.

Security shop pwns ransomware gang, passes insider info to authorities
CrushFTP CEO’s feisty response to VulnCheck’s CVE for critical make-me-admin bug

Alexander Tan discovered that the OpenSAML C++ library was susceptible to forging of signed SAML messages. For additional details please refer to the upstream advisory at https://shibboleth.net/community/advisories/secadv_20250313.txt

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

UK’s first permanent facial recognition cameras installed in South London
Ransomwared NHS software supplier nabs £3M discount from ICO for good behavior
Malaysian PM says “no way” to $10 million ransom after alleged cyber attack against Kuala Lumpur airport
What next for WASI on Azure Kubernetes Service?
Smashing Security podcast #410: Unleash the AI bot army against the scammers – now!
Microsoft lauds Hyperlight Wasm for WebAssembly workloads
Signalgate storm intensifies as journalist releases full secret Houthi airstrike chat

https://security-tracker.debian.org/tracker/DSA-5886-1

US defense contractor cops to sloppy security, settles after infosec lead blows whistle
Files stolen from NSW court system, including restraining orders for violence
Credible nerd says stop using atop, doesn’t say why, everyone panics
Critical RCE flaws put Kubernetes clusters at risk of takeover

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239460 Cross-References: * CVE-2025-24049

Databricks’ TAO method to allow LLM training with unlabeled data
NCSC taps influencers to make 2FA go viral
Intro to Alpine.js: A JavaScript framework for minimalists
What you need to know about Go, Rust, and Zig
Open-source Styrolite project aims to simplify container runtime security
Vibe coding is groovy

https://security-tracker.debian.org/tracker/DSA-5887-1

Oracle releases ML-optimized GraalVM for JDK 24
Warning for developers, web admins: update Next.js to prevent exploit
There are perhaps 10,000 reasons to doubt Oracle Cloud’s security breach denial
The AI Fix #43: I, for one, welcome our new robot overlords!
Infosec pro Troy Hunt HasBeenPwned in Mailchimp phish

This upload fixes two security issues in the version of nginx shipped in bullseye. CVE-2024-7347

Fauna to shut down FaunaDB service in May
GenAI tools for R: New tools to make R programming easier
Cosmonic uses WebAssembly to manage apps
Google acquires Wiz: A win for multicloud security
You know that generative AI browser assistant extension is probably beaming everything to the cloud, right?

* bsc#1239465 Cross-References: * CVE-2025-27363

VanHelsing ransomware emerges to put a stake through your Windows heart
Hm, why are so many DrayTek routers stuck in a bootloop?

Several security issues were fixed in SmartDNS.

Public-facing Kubernetes clusters at risk of takeover thanks to Ingress-Nginx flaw