Menu

Monthly Archives: March 2025

Choose your own Patch Tuesday adventure: Start with six zero-day fixes, or six critical flaws
JavaOne 2025 heralds Java’s 30th birthday

https://security-tracker.debian.org/tracker/DSA-5877-1

‘Uber for nurses’ exposes 86k+ medical records, PII in open S3 bucket for months
FTC’s $25.5M scam refund treats victims to $34 each
The AI Fix #41: Can AIs be psychopaths, and why we should be AI optimists
Go-based TypeScript to dramatically improve speed, scalability

* bsc#1208995 * bsc#1220946 * bsc#1225742 * bsc#1232472 * bsc#1232919

* bsc#1208995 * bsc#1220946 * bsc#1224700 * bsc#1225742 * bsc#1232905

* bsc#1050081 * bsc#1051510 * bsc#1065729 * bsc#1100823 * bsc#1101669

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Weaviate adds agents to its tech stack to ease gen AI app development
3 of the best LLM integration tools for R
Has AWS lost its edge?
MINJA sneak attack poisons AI models for other chatbot users
Allstate Insurance sued for delivering personal info on a platter, in plaintext, to anyone who went looking for it
Fortran, Delphi rise in Tiobe popularity index
Google begs owners of crippled Chromecasts not to hit factory reset
Webinar: Credential security in the age of AI: Insights for IT leaders
Sidewinder goes nuclear, charts course for maritime mayhem in tactics shift
Enhancing Cybersecurity Quality Assurance with AI & Machine Learning
Rhysida pwns two US healthcare orgs, extracts over 300K patients’ data
Consumer Reports calls out slapdash AI voice-cloning safeguards
Databricks’ new updates aim to ease gen AI app and agent development
How NOT to f-up your security incident response

* bsc#1237681 Cross-References: * CVE-2025-27144

* bsc#1237681 Cross-References: * CVE-2025-27144

* bsc#1236531 * bsc#1237681 Cross-References: * CVE-2023-45288

The NHS security culture problem is a crisis years in the making
Building generative AI? Get ready for generative UI
10 things developers love about JavaScript – and 10 things they don’t
Vibes won’t make your software successful
Strap in, get ready for more Rust drivers in Linux kernel
Microsoft admits GitHub hosted malware that infected almost a million devices
India wants backdoors into clouds, email, SaaS, for tax inspectors

Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles

Unbundle libxml2.

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in

Microsoft previews AI chat template for .NET
Kernel saunters – How Apple rearranged its XNU kernel with exclaves

Two vulnerabilities were discovered in openvpn, a virtual private network application which could result in authentication bypass or data injection.

High CVE-2025-1914: Out of bounds read in V8. Medium CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools. Medium CVE-2025-1916: Use after free in Profiles. Medium CVE-2025-1917: Inappropriate Implementation in Browser UI.

Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles

The newest upstream commit Security fix for CVE-2025-27423

update to version 2.25.1, CVE-2025-27154

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2. (CVE-2023-5520) Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV. (CVE-2024-0321) Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

Developer sabotaged ex-employer with kill switch activated when he was let go

https://security-tracker.debian.org/tracker/DSA-5876-1

Microsoft reportedly struggling to build its own reasoning models to rival OpenAI
JFrog unveils JFrog ML for MLOps

https://security-tracker.debian.org/tracker/DSA-5875-1

Uncle Sam charges alleged Garantex admins after crypto-exchange web seizures
Alleged cyber scalpers Swiftly cuffed over $635K Taylor ticket heist
Anthropic’s upgraded Console targets more collaboration among developers
Like whitebox servers, rent-a-crew crime ‘affiliates’ have commoditized ransomware

Several security issues were fixed in the Linux kernel.

JavaScript tools and frameworks we’re watching now
When to choose a bare-metal cloud

Updated to latest upstream (136.0)

Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian

Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian

The Badbox botnet is back, powered by up to a million backdoored Androids
Alibaba says its new AI model rivals DeepSeeks’s R-1, OpenAI’s o1
Visual Studio Code 1.98 shines on GitHub Copilot
International cops seize ransomware crooks’ favorite Russian crypto exchange
Uncle Sam mulls policing social media of all would-be citizens

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Several security issues were fixed in Ansible.

Toronto Zoo ransomware crooks snatch decades of visitor data
Up to $75M needed to fix up rural hospital cybersecurity as ransomware gangs keep scratching at the door

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

How to handle type erasure in advanced Java generics
Portkey: An open-source AI gateway for easy LLM orchestration
The key new features in .NET 10
Cybereason CEO leaves after months of boardroom blowups

Updated to latest upstream (136.0)

The newest upstream commit Security fix for CVE-2025-27423

Feds name and charge alleged Silk Typhoon spies behind years of China-on-US attacks
Smashing Security podcast #407: HP’s hold music, and human trafficking

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

C++ founder champions profiles for memory safety
Ex-NSA grandee says Trump’s staff cuts will ‘devastate’ America’s national security

https://security-tracker.debian.org/tracker/DSA-5873-1

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

China’s Silk Typhoon, tied to US Treasury break-in, now hammers IT and govt targets
Cactus ransomware: what you need to know
Apple drags UK government to court over ‘backdoor’ order
Fake police call cryptocurrency investors to steal their funds

Several security issues were fixed in the Linux kernel.

* bsc#1237683 Cross-References: * CVE-2024-43097 * CVE-2025-1930

Several security issues were fixed in the Linux kernel.

Leeds United kick card swipers into Row Z after 5-day cyberattack

A security issue was fixed in Linux kernel.