Menu

Monthly Archives: March 2025

Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens

0.9.30, rebuild due golang CVE-2025-22870

OTF, which backs Tor, Let’s Encrypt and more, sues to save funding from Trump cuts
Top Trump officials text classified Yemen airstrike plans to journo in Signal SNAFU
FCC on the prowl for Huawei and other blocked Chinese makers in America
As nation-state hacking becomes ‘more in your face,’ are supply chains secure?

https://security-tracker.debian.org/tracker/DSA-5885-1

Ivan Fratric discovered two use-after-free vulnerabilities in libxslt, an XSLT processing runtime library, which may result in the execution of arbitrary code if a specially crafted files are processed.

AI agents swarm Microsoft Security Copilot
23andMe’s genes not strong enough to avoid Chapter 11
Anatomy of Linux Ransomware Attacks and Protection Strategies
Is Washington losing its grip on crypto, or is it a calculated pivot to digital dominance?

Two use-after-free vulnerabilities have been fixed in the XSLT processing library libxslt. CVE-2024-55549

Microsoft tastes the unexpected consequences of tariffs on time
Learning AI governance lessons from SaaS and Web2
Prompt engineering courses and certifications tech companies want
OpenTofu becomes the real deal
Mobsters now overlap with cybercrime gangs and use AI for evil, Europol warns

Several security issues were fixed in NLTK.

Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens

China bans compulsory facial recognition and its use in private spaces like hotel rooms
Oracle Cloud says it’s not true someone broke into its login servers and stole data

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-44192

An update that fixes two vulnerabilities is now available.

Ex-NSA boss: Election security focus helped dissuade increase in Russian meddling with US
Mitigating threats against telco networks in the cloud

Update to 4.3.6 (rhbz#2352545)

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

Update to 4.3.6 (rhbz#2352545)

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

Backported fix for CVE-2024-12361 .

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

https://security-tracker.debian.org/tracker/DSA-5884-1

A cross-site scripting vulnerability was discovered in hgweb, the integrated stand-alone web interface of the Mercurial version control system.

Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes

Kotlin bolsters K2 compiler plugin support, WebAssembly debugging

https://security-tracker.debian.org/tracker/DSA-5883-1

OpenSilver extends to iOS and Android

* bsc#1197331 * bsc#1203769 * bsc#1235441 * bsc#1237768 * bsc#1238271

* bsc#1239750 Cross-References: * CVE-2022-49737

https://security-tracker.debian.org/tracker/DSA-5882-1

go-gh could be made to expose sensitive information over the network.

* bsc#1239547 Cross-References: * CVE-2025-24201

* bsc#1239547 Cross-References: * CVE-2025-24201

* bsc#1237363 * bsc#1237370 * bsc#1237418 Cross-References:

Nvidia launches AgentIQ toolkit to connect disparate AI agents
Everyone needs a genAI strategy now
Bridging the digital skills gap
AdTech CEO whose products detected fraud jailed for financial fraud
Paragon spyware deployed against journalists and activists, Citizen Lab claims
Capital One cracker could be sent back to prison after judges rule she got off too lightly
Developers: apply these 10 mitigations first to prevent supply chain attacks
Dept of Defense engineer took home top-secret docs, booked a fishing trip to Mexico – then the FBI showed up
Microsoft .NET 10 Preview 2 shines on C#, runtime, encryption
BlackLock ransomware: What you need to know
Infoseccers criticize Veeam over critical RCE vulnerability and a failing blacklist
Ex-Sun CEO Scott McNealy reflects on Java’s founding
What OpenInfra Joining Linux Foundation Means for Cloud Security Posture Management
Smashing Security podcast #409: Peeping perverts and FBI phone calls
Too many software supply chain defense bibles? Boffins distill advice
The post-quantum cryptography apocalypse will be televised in 10 years, says UK’s NCSC

Several security issues were fixed in Valkey.

Red Hat Advanced Cluster Security 4.7 simplifies management, enhances workflows, and generates SBOMs
Secure AI inferencing: POC with NVIDIA NIM on CoCo with OpenShift AI

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in HTTP request smuggling, validation bypass or denial of service.

Supply-chain CAPTCHA attack hits over 100 car dealerships
How to implement idempotent APIs in ASP.NET Core
TypeScript gets Go-faster stripes

Multiple vulnerabilities were discovered in modules shipped with cpython 3.9, the primary interpreter for the Python programming language.

fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864

fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864

Several security issues were fixed in Alpine.

Effective Strategies to Optimize Linux Security in 2025
Attackers swipe data of 500k+ people from Pennsylvania teachers union
Names, bank info, and more spills from top sperm bank
IBM scores perfect 10 … vulnerability in mission-critical OS AIX
Rising Malware Threats to Linux: Understanding Risks and Defenses
Cloud trends 2025: Repatriation and sustainability make their marks
Ex-US Cyber Command chief: Europe and 5 Eyes can’t fully replicate US intel
Exploring FireDragon: A High-Performing, Secure Linux Browser
Apache Tomcat Vulnerability CVE-2025-24813 Exposes Linux Servers to Remote Attacks

* bsc#1229640 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452

* bsc#1228755 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452

* bsc#1231204 * bsc#1233679 Cross-References: * CVE-2024-46818

* bsc#1229640 * bsc#1231204 * bsc#1233679 Cross-References:

GitHub suffers a cascading supply chain attack compromising CI/CD secrets
SAP introduces Joule for Developers
Astro with HTMX: Server-side rendering made easy
You can build it on a Chromebook
Show top LLMs buggy code and they’ll finish off the mistakes rather than fix them
CISA fires, now rehires and immediately benches security crew on full pay
Oracle reveals five new features coming to Java

https://security-tracker.debian.org/tracker/DSA-5881-1

Oracle, Nvidia partner to add AI software into OCI services