Menu

Monthly Archives: April 2025

Docker’s new MCP Catalog, Toolkit to solve major developer challenges, experts say
Claims assistance firm fined for cold-calling people who put themselves on opt-out list
Hackers access sensitive SIM card data at South Korea’s largest telecoms company
Python and WebAssembly? Here’s how to make it work
Hype versus execution in agentic AI

Several security issues were fixed in the Linux kernel.

Darcula adds AI to its DIY phishing kits to help would-be vampires bleed victims dry

Update to 1.24.1, fixes CVE-2025-2291.

Backport fixes for CVE-2025-32910, CVE-2025-32911, CVE-2025-32913 Backport fixes for CVE-2025-32050 CVE-2025-32052 CVE-2025-32053 CVE-2025-32906 CVE-2025-32907 CVE-2025-32909

Update to 1.24.1, fixes CVE-2025-2291.

SSNs and more on 5.5M+ patients feared stolen from Yale Health
Microsoft mystery folder fix might need a fix of its own
Assassin’s Creed maker faces GDPR complaint for forcing single-player gamers online

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Multiple vulnerabilities have been fixed in the OpenRazer drivers for devices from Razer, a company selling hardware mainly targeted at gamers. CVE-2022-23467

M&S takes systems offline as ‘cyber incident’ lingers
Your vendor may be the weakest link: Percentage of third-party breaches doubled in a year
Booby-trapped Alpine Quest Android app geolocates Russian soldiers

Backport fixes for CVE-2025-32364 and CVE-2025-32365.

Ransomware scum and other crims bilked victims out of a ‘staggering’ $16.6B last year, says FBI
Smashing Security podcast #414: Zoom.. just one click and your data goes boom!
Blue Shield says it shared health info on up to 4.7M patients with Google Ads
Ripple NPM supply chain attack hunts for private keys
We’re calling it now: Agentic AI will win RSAC buzzword Bingo
Will super-smart AI be attacking us anytime soon?

What practical AI attacks exist today? “More than zero” is the answer – and they’re getting better.

The AI Fix #47: An AI is the best computer programmer in the world
Crosswalks hacked to play fake audio of Musk, Zuck, and Jeff Bezos
Who needs phishing when your login’s already in the wild?

Several security issues were fixed in the Linux kernel.

Overcoming SaaS Security Risks with Open-Source Tools
Ex-NSA chief warns AI devs: Don’t repeat infosec’s early-day screwups
America’s cyber defenses are being dismantled from the inside

Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB

Latest updates.

Resolves CVE-2024-53868

Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB

Latest updates.

RIP, Google Privacy Sandbox
Two CISA officials jump ship, both proud of pushing for Secure by Design software
Fog ransomware channels Musk with demands for work recaps or a trillion bucks

Update to 128.9.2 https://www.thunderbird.net/en-US/thunderbird/128.9.1esr/releasenotes/ https://www.thunderbird.net/en-US/thunderbird/128.9.2esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-27/

A pot of $250K is now available to ransomware researchers, but it feeds a commercial product
This is not just any ‘cyber incident’ … this is an M&S ‘cyber incident’
UN says Asian scam call center epidemic expanding globally amid political heat

In today’s digital world, your personal data is like cold hard cash, and that’s why cyberthieves are always looking for ways to steal it. Whether it’s an email address, a credit card number, or even medical records, your personal information is incredibly valuable in the wrong hands. For hackers, breaking into a company database is […]

Linux 6.15-rc3: Security Advisory for UBLK Driver Enhancements
Vibe code or retire
Why enterprise investment in AI agents hasn’t yielded results
Breaking the cloud monopoly
Microsoft updates AI chat template for cloud app dev
Bug hunter tricked SSL.com into issuing cert for Alibaba Cloud domain in 5 steps

Backport proposed fix for CVE-2025-31344 from OpenMandriva. Install gif_getarg.h header.

Fix CVE-2024-56406

Fix CVE-2024-56406

Fix CVE-2024-56406

Today’s LLMs craft exploits from patches at lightning speed

Several security issues were fixed in Eclipse Mosquitto.

Microsoft rated this bug as low exploitability. Miscreants weaponized it in just 8 days
New Supply Chain Attack Targets Telegram Bots

Multiple vulnerabilities have been fixed in the fig2dev utilities for converting XFig figure files. CVE-2025-31162

Understanding application modernization
What GitHub can tell us about the future of open source
Data mesh vs. data fabric vs. data virtualization: There’s a difference

Mishandling of semicolons in the userinfo subcomponent of a URI has been fixed in GNU Wget, a utility for retrieving files over HTTP, HTTPS, FTP and FTPS.

USN-6200-2 introduced a regression in ImageMagick.

Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB

rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered. See https://www.arin.net/announcements/20250116-tal/ rpki-client reports Certification Authorities that do not meaningfully participate in the RPKI as non-functional CAs. By definition, a CA is non-

release v1.16.0

By the numbers: Security insights from Red Hat and IBM

Several vulnerabilities were discovered in the Erlang/OTP implementation of the SSH protocol, which may result in denial of service or the execution of arbitrary code.

Fix bz2358011

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

https://security-tracker.debian.org/tracker/DSA-5906-1

Dems fret over DOGE feeding sensitive data into random AI
Hacking US crosswalks to talk like Zuck is as easy as 1234

https://security-tracker.debian.org/tracker/DSA-5905-1

https://security-tracker.debian.org/tracker/DSA-5904-1

Several vulnerabilities were discovered in the shadow suite of login tools. An attacker may extract a password from memory in limited situations, and confuse an administrator inspecting /etc/passwd from within a terminal.

New libxml2 packages are available for Slackware 15.0 and -current to fix security issues.

CapCut copycats are on the prowl

Cybercriminals lure content creators with promises of cutting-edge AI wizardry, only to attempt to steal their data or hijack their devices instead

They’re coming for your data: What are infostealers and how do I stay safe?

Here’s what to know about malware that raids email accounts, web browsers, crypto wallets, and more – all in a quest for your sensitive data

Oracle hopes talk of cloud data theft dies off. CISA just resurrected it for Easter
Google previews Gemini 2.5 Flash hybrid reasoning model

* bsc#1241150 Cross-References: * CVE-2025-32460

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

CVE fallout: The splintering of the standard vulnerability tracking system has begun
Learning how to measure genAI’s impact
How U.S. tariffs could impact cloud computing