Menu

Monthly Archives: April 2025

Ex-NSA cyber-boss: AI will soon be a great exploit coder
Smashing Security podcast #415: Hacking hijinks at the hospital, and WASPI scams

In today’s digital world, passwords have become a necessary part of life. But even though you use them for almost everything you do online, you probably don’t give them the thought they truly deserve. May 1, 2025, is World Password Day, a reminder that passwords are the unsung heroes of cybersecurity, the first line of […]

Ex-CISA chief decries cuts as Trump demands loyalty above all else
Maryland man pleads guilty to outsourcing US govt work to North Korean dev in China
Zoho adds AI capabilities to its low code dev platform
This month in security with Tony Anscombe – April 2025 edition

From the near-demise of MITRE’s CVE program to a report showing that AI outperforms elite red teamers in spearphishing, April 2025 was another whirlwind month in cybersecurity

Meta will offer its Llama AI model as an API too
FBI steps in amid rash of politically charged swattings

H2O could be made to crash if it received specially crafted network traffic.

PostgreSQL could be made to execute arbitrary code if it received specially crafted input.

* bsc#1233294 * bsc#1235431 Cross-References: * CVE-2024-50205

Ghost in the shell script: Boffins reckon they can catch bugs before programs run
Catching up with Angular 19
Four essential ingredients of software development

* bsc#1239909 Cross-References: * CVE-2025-2588

Cloud doesn’t mean secure: How Intruder finds what others miss
Apiiro launches AI-powered risk analysis map for software
GCC 15 compilers arrive with Rust, C, C++, and Cobol enhancements

https://security-tracker.debian.org/tracker/DSA-5908-1

Watch out for any Linux malware sneakily evading syscall-watching antivirus

Several security issues were fixed in Mistral.

Several security issues were fixed in Mistral.

Apache Tomcat could be made to crash if it received specially crafted network traffic.

Apache Tomcat could be made to crash if it received specially crafted network traffic.

How safe and secure is your iPhone really?

Your iPhone isn’t necessarily as invulnerable to security threats as you may think. Here are the key dangers to watch out for and how to harden your device against bad actors.

Enterprise tech dominates zero-day exploits with no signs of slowdown
China now America’s number one cyber threat – US must get up to speed
The AI Fix #48: AI Jesus, and is the AI Singularity almost upon us?
Infosec pros tell Trump to quit bullying Chris Krebs – it’s undermining security
China is using AI to sharpen every link in its attack chain, FBI warns
Ransomware attacks on critical infrastructure surge, reports FBI
21 million employee screenshots leaked in bossware breach blunder
The one interview question that will protect you from North Korean fake workers
5 ways generative AI boosts cloud and IT operations
Why hasn’t cheaper hardware lowered cloud prices?

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Swiss boffins admit to secretly posting AI-penned posts to Reddit in the name of science
Open source text editor poisoned with malware to target Uyghur users

Update to version 2.10.0. Aside from the new upstream features, this update also refreshes many bundled dependencies, fixing a few CVEs. https://github.com/caddyserver/caddy/releases/tag/v2.10.0

Update to version 2.10.0. Aside from the new upstream features, this update also refreshes many bundled dependencies, fixing a few CVEs. https://github.com/caddyserver/caddy/releases/tag/v2.10.0

Ex-Disney employee gets 3 years in the clink for goofy attacks on mousey menus
Cybersecurity CEO accused of running malware on hospital PC blabs about it on LinkedIn
How to survive as a CISO aka ‘chief scapegoat officer’
Admission impossible: NSA, CISA brass absent from RSA Conf
Microsoft previews SignalR client for iOS

Heap buffer overflow in Codecs. (CVE-2025-3619) Use after free in USB. (CVE-2025-3620) References: – https://bugs.mageia.org/show_bug.cgi?id=34208

Heap buffer overflow in Codecs. (CVE-2025-3619) Use after free in USB. (CVE-2025-3620) References: – https://bugs.mageia.org/show_bug.cgi?id=34208

Juray Sarinay discovered that PDF documents signed with the adbe.pkcs7.sha1 standard were incompletely validated by LibreOffice, which could cause invalid signatures to be accepted as legitimate.

Juray Sarinay discovered that PDF documents signed with the adbe.pkcs7.sha1 standard were incompletely validated by LibreOffice, which could cause invalid signatures to be accepted as legitimate.

The future of AI in cybersecurity in a word: Optimistic

Several security vulnerabilities have been discovered in libsoup2.4, a http client/server library popularly used in GNOME, et.al. CVE-2025-2784

From 112K to 4M folks’ data – HR biz attack goes from bad to mega bad
Back online after ‘catastrophic’ attack, 4chan says it’s too broke for good IT
Understanding the Linux Filesystem Case Sensitivity Debate

Multiple vulnerabilities have been fixed in the PDF rendering library poppler. CVE-2020-36023

AWS updates Amazon Bedrock’s Data Automation capability
Conquering the costs and complexity of cloud, Kubernetes, and AI
14 tiny tricks for big cloud savings
OpenSearch in 2025: Much more than an Elasticsearch fork

* bsc#1241584 * bsc#1241585 Cross-References: * CVE-2015-3885

* bsc#1239680 Cross-References: * CVE-2025-2312

Microsoft pitches pay-to-patch reboot reduction subscription for Windows Server 2025
Samsung admits Galaxy devices can leak passwords through clipboard wormhole

Jupyter Notebook could be made to crash if it received specially crafted input.

Update to 135.0.7049.114

Update to pgadmin-9.2.

April 2025 CPU

April 2025 CPU

April 2025 CPU

April 2025 CPU

https://security-tracker.debian.org/tracker/DSA-5907-1

[CVE-2025-32414] Buffer overflow when parsing text streams with Python API [CVE-2025-32415] Heap-based Buffer Overflow in xmlSchemaIDCFillNodeTables

BUG/MEDIUM: sample: fix risk of overflow when replacing multiple regex back-refsAleandro Prudenzano of Doyensec and Edoardo Geraci of Codean Labs reported a bug in sample_conv_regsub(), which can cause replacements of multiple back-references to overflow the temporary trash buffer. The problem happens when doing “regsub(match,replacement,g)”:

* bsc#1230092 Cross-References: * CVE-2024-45310

Deepfake ‘doctors’ take to TikTok to peddle bogus cures

Look out for AI-generated ‘TikDocs’ who exploit the public’s trust in the medical profession to drive sales of sketchy supplements

Update to 135.0.7049.114

Update to 135.0.7049.114

New upstream version 5.8.1 (with a rebuild to try and fix a gating problem). New upstream version 5.8.1

Signalgate lessons learned: If creating a culture of security is the goal, America is screwed
Baidu hits the turbo button to get back into AI race
Thesys introduces generative UI API for building AI apps
Amid CVE funding fumble, ‘we were mushrooms, kept in the dark,’ says board member
More Ivanti attacks may be on horizon, say experts who are seeing 9x surge in endpoint scans
Databricks to infuse $250M to double its R&D staff in India this year
MarkItDown: Microsoft’s open-source tool for Markdown conversion
Micro front ends on the Microsoft web platform
Microsoft touts AI Dev Gallery for Windows
Puppet devsecops updated to deal with security maladies
Oh, cool. Microsoft melts bug that froze Server 2025 Remote Desktop sessions
How fraudsters abuse Google Forms to spread scams

The form and quiz-building tool is a popular vector for social engineering and malware. Here’s how to stay safe.

M&S stops online orders as ‘cyber incident’ issues worsen
Emergency patch for potential SAP zero-day that could grant full system control
Cloud native explained: How to build scalable, resilient applications

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6