Menu

Monthly Archives: March 2025

US tech jobs outlook clouded by DOGE cuts, Trump tariffs
The AI Fix #42: AIs with anxiety, and why AIs don’t know what happened
Microsoft isn’t fixing 8-year-old shortcut exploit abused for spying
Google acquisition target Wiz links fresh supply chain attack to 23K pwned GitHub repos

* bsc#1237467 Cross-References: * CVE-2025-26618

UK wants dirt on data brokers before criminals get there first
Mandatory Coinbase wallet migration? It’s a phishing scam!

* bsc#1228017 * bsc#1229640 * bsc#1231204 * bsc#1233679

* bsc#1233679 Cross-References: * CVE-2024-50302

* bsc#1229640 * bsc#1231204 * bsc#1233679 Cross-References:

Extortion crew threatened to inform Edward Snowden (?!) if victim didn’t pay up
‘Dead simple’ hijacking hole in Apache Tomcat ‘now actively exploited in the wild’
Court filing: DOGE aide broke Treasury policy by emailing unencrypted database
Amazon to kill off local Alexa processing, all voice requests shipped to the cloud

https://security-tracker.debian.org/tracker/DSA-5879-1

What is KubeVirt? How does it migrate VMware workloads to Kubernetes?

FreeType could be made to crash or run programs if it opened a specially crafted font file.

GitHub supply chain attack spills secrets from 23,000 projects

* bsc#1239197 Cross-References: * CVE-2025-22868

* bsc#1239197 Cross-References: * CVE-2025-22868

Attackers attempted hijacking 12,000 GitHub accounts with click-fix alerts
UK government to open £16B IT services competition after 6-month delay

Several security issues were fixed in X.Org X Server.

Microsoft wouldn’t look at a bug report without a video. Researcher maliciously complied
Free file converter malware scam “rampant” claims FBI
Borked Chromecasts are beginning to receive their update – just hope you didn’t do a factory reset
Combining AI and no-code for business app development
Why AI-generated code isn’t good enough (and how it will get better)
AI can give you code but not community

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

https://security-tracker.debian.org/tracker/DSA-5880-1

FCC stands up Council on National Security to fight China in ways that CISA used to

An update that fixes one vulnerability is now available.

An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files which may result in arbitrary code execution. References:

patchlevel 1202 Security fix for CVE-2025-29768

Update to upstream 20250311: amdgpu: many firmware updates qcom: Update gpu firmwares for qcs8300 chipset add firmware for qat_420xx devices amdgpu: DMCUB updates for various ASICs

Latest maintenance release from 7.1 branch. Changelog: https://github.com/FFmpeg/FFmpeg/blob/n7.1.1/Changelog . Contains backported fix for CVE-2025-22921.

New freetype packages are available for Slackware 15.0 to fix a security issue.

Update to 134.0.6998.88 High CVE-2025-1920: Type Confusion in V8 High CVE-2025-2135: Type Confusion in V8 Medium CVE-2025-2136: Use after free in Inspector Medium CVE-2025-2137: Out of bounds read in V8

deadlock potential with VT-d and legacy PCI device pass-through [XSA-467, CVE-2025-1713]

Update to upstream 20250311: amdgpu: many firmware updates qcom: Update gpu firmwares for qcs8300 chipset add firmware for qat_420xx devices amdgpu: DMCUB updates for various ASICs

Update to 134.0.6998.88 High CVE-2025-1920: Type Confusion in V8 High CVE-2025-2135: Type Confusion in V8 Medium CVE-2025-2136: Use after free in Inspector Medium CVE-2025-2137: Out of bounds read in V8

This release addresses CVEs: CVE-2025-27835, CVE-2025-27832, CVE-2025-27831, CVE-2025-27836, CVE-2025-27830, CVE-2025-27833, CVE-2025-27837, CVE-2025-27834 The 10.05.0 release deprecates the non-standard operator “selectdevice”, all code should now be using the standard “setpagedevice” operator.

In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn’t aligned correctly. In versions before GLIBC version 2.29 and if aligned correctly, it allows arbitrary writes […]

JDK 25: The new features in Java 25
Stupendous Python stunts without a net
Apple’s alleged UK encryption battle sparks political and privacy backlash

* bsc#1233307 Cross-References: * CVE-2024-11168

* bsc#1202848 * bsc#1215945 * bsc#1223070 * bsc#1223235 * bsc#1223256

* bsc#1238702 Cross-References: * CVE-2025-22870

* bsc#1215420 * bsc#1224700 * bsc#1224763 * bsc#1225742 * bsc#1231847

Introducing Red Hat OpenShift Service Mesh 3.0
New kids on the ransomware block channel Lockbit to raid Fortinet firewalls
What is Llama? Meta AI’s family of large language models explained
IT leaders are driving a new cloud computing era
Java hiring plans slip, survey says

https://security-tracker.debian.org/tracker/DSA-5878-1

Dems ask federal agencies for reassurance DOGE isn’t feeding data into AI willy-nilly
Google says it’s rolling out fix for stricken Chromecasts
Chromecast chaos – 2nd gen devices go belly-up as Google struggles to fix certificate issue
That ‘angry guest’ email from Booking.com? It’s a scam, not a 1-star review
CISA: We didn’t fire red teams, we just unhired a bunch of them
Medusa ransomware: FBI and CISA urge organisations to act now to mitigate threat
DeepSeek can be gently persuaded to spit out malware code

* bsc#1239197 Cross-References: * CVE-2025-22868

* bsc#1208995 * bsc#1220946 * bsc#1225742 * bsc#1232472 * bsc#1232919

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

How DeepSeek innovated large language models
Speeding up .NET application development with Uno Studio
Medusa ransomware affiliate tried triple extortion scam – up from the usual double demand
Google unveils Gemma 3 multi-modal AI models
Get off that old Firefox by Friday or you’ll be sorry, says Moz
Smashing Security podcast #408: A gag order backfires, and a snail mail ransom demand
GitHub to unbundle Advanced Security
At long last, OpenStack (now known as OpenInfra Foundation) joins Linux Foundation
OpenAI takes on rivals with new Responses API, Agents SDK
Man found guilty of planting infinite loop logic bomb on ex-employer’s system

Our digital lives are filled with essential personal information, and it’s easy to forget how vulnerable all that data can be. But if your hard drive crashes, your laptop gets stolen, or you fall victim to cybercrime, the loss can be devastating. Your financial records, your work files, and even years of family photos can […]

Expired Juniper routers find new life – as Chinese spy hubs
The Security-Conscious Sysadmin’s Guide to Choosing the Right Linux Distro
This is the FBI, open up. China’s Volt Typhoon is on your network

* bsc#1237377 Cross-References: * CVE-2025-0633

Several security issues were fixed in Jinja2.

UK must pay cyber pros more than its Prime Minister, top civil servant says
Airgapped Python: Setting up Python without a net(work)
Designing a dynamic web application with Astro
Why Wasm fascinates me

Several security issues were fixed in opensc.

.NET could be made to elevate privileges.

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings. (CVE-2025-26699)

Jinja sandbox breakout through attr filter selecting format method. (CVE-2025-27516) References: – https://bugs.mageia.org/show_bug.cgi?id=34081

CISA worker says 100-strong red team fired after DOGE cancelled contract