Menu

Monthly Archives: March 2025

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Qilin ransomware gang claims attacks on cancer clinic, OB-GYN facility
How prevention is better than cure
Ransomware thugs threaten Tata Technologies with leak if demands not met

https://security-tracker.debian.org/tracker/DSA-5874-1

VMware splats guest-to-hypervisor escape bugs already exploited in wild
The AI Fix #40: ChatGPT saved my life, and making evil AIs by accident
Embracing AI and Machine Learning Frameworks on Linux
CISA refutes claims it has been ordered to stop monitoring Russian cyber threats
How Google tracks Android device users before they’ve even opened an app
Why genAI-powered intelligent document processing is a big deal
Does Microsoft’s Majorana chip meet enterprise needs?
Teradata adds Enterprise Vector Store to augment RAG
It’s bad enough we have to turn on cams for meetings, now the person staring at you may be an AI deepfake
Plugging the holes in open banking

Several security issues were fixed in cmark-gfm.

So … Russia no longer a cyber threat to America?

Several security issues were fixed in spip.

wpa_supplicant and hostapd could be made to expose sensitive information over the network.

TypeScript 5.8 reaches general availability

Use-after-free of the root cursor. (CVE-2025-26594) Buffer overflow in XkbVModMaskText(). (CVE-2025-26595) Heap overflow in XkbWriteKeySyms(). (CVE-2025-26596) Buffer overflow in XkbChangeTypesOfKey(). (CVE-2025-26597) Out-of-bounds write in CreatePointerBarrierClient(). (CVE-2025-26598)

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Cybersecurity not the hiring-’em-like-hotcakes role it once was

March is a time for leprechauns and four-leaf clovers, and as luck would have it, it’s also a time to learn how to protect your private data from cybercrime. Each year, the first week of March (March 2-8) is recognized as National Consumer Protection Week (NCPW). During this time, many government agencies and consumer protection […]

Stop targeting Russian hackers, Trump administration orders US Cyber Command
Microsoft unveils finalized EU Data Boundary as European doubt over US grows
Polish space agency confirms cyberattack

* bsc#1237284 * bsc#1237287 Cross-References: * CVE-2024-57256

* bsc#1236974 Cross-References: * CVE-2024-12243

* bsc#1236974 Cross-References: * CVE-2024-12243

UK watchdog investigates TikTok and Reddit over child data privacy concerns
Governments can’t seem to stop asking for secret backdoors
The most relevant new features in JDK 24
How eBPF is changing container networking
Who needs Google technology? Probably not you
US Cyber Command reportedly pauses cyberattacks on Russia
Download the AI Risk Management Enterprise Spotlight

A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. A privileged attacker could cause a Denial-of-Service (DoS) of the MariaDB server.

C++ creator calls for help to defend programming language from ‘serious attacks’

A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file. (CVE-2025-22919) A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted

nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm –without-symbol-version` function. (CVE-2024-57360) GNU Binutils objdump.c disassemble_bytes stack-based overflow. (CVE-2025-0840)

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

https://security-tracker.debian.org/tracker/DSA-5872-1

Red Hat is now a CVE Numbering Authority of Last Resort in the CVE Program

Update to chromium-133.0.6943.141

CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function

CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function

New version 4.2.11

Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162

deadlock potential with VT-d and legacy PCI device pass-through [XSA-467, CVE-2025-1713]