Menu

Monthly Archives: April 2025

JetBrains IDEs now include AI tools by subscription
Krebs throws himself on the grenade, resigns from SentinelOne after Trump revokes clearances
Onehouse opens up the lakehouse with Open Engines

* bsc#1240958 * bsc#1240961 * bsc#1240962 * bsc#1240963 * bsc#1240964

* bsc#1240893 Cross-References: * CVE-2025-31492

* bsc#1240971 Cross-References: * CVE-2025-32464

* bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364

Expired US Funding Threatened to Disrupt Security Flaw Tracking
Brit soldiers tune radio waves to fry drone swarms for pennies
Enter the parallel universe of Java’s Vector API
Headlamp: A multicluster management UI for Kubernetes
Whistleblower describes DOGE IT dept rampage at America’s labor watchdog

https://security-tracker.debian.org/tracker/DSA-5903-1

Smashing Security podcast #413: Hacking the hackers… with a credit card?
Gleam 1.10 improves compiler, JavaScript codegen
Free Blue Screens of Death for Windows 11 24H2 users
Signalgate chats vanish from CIA chief phone
Identifying the cyber risks that matter
CVE program gets last-minute funding from CISA – and maybe a new home
Attacks on the education sector are surging: How can cyber-defenders respond?

Academic institutions have a unique set of characteristics that makes them attractive to bad actors. What’s the right antidote to cyber-risk?

Law firm ‘didn’t think’ data theft was a breach, says ICO. Now it’s nursing a £60K fine

* bsc#1239826 * jsc#MSQA-936 Cross-References: * CVE-2025-23392

* bsc#1240893 Cross-References: * CVE-2025-31492

* bsc#1239863 * bsc#1239864 * bsc#1240958 * bsc#1240961 * bsc#1240962

* bsc#1224295 * bsc#1234840 * bsc#1239308 Cross-References:

* bsc#1239649 Cross-References: * CVE-2024-12088

Russians lure European diplomats into malware trap with wine-tasting invite
Insurance firm Lemonade warns of breach of thousands of driving license numbers
6 languages you can deploy to WebAssembly right now
The programming language wars
Guess what happens when ransomware fiends find ‘insurance’ ‘policy’ in your files
Uncle Sam abruptly turns off funding for CVE program. Yes, that CVE program
JRuby 10 brings faster startup times
Now 1.6M people had SSNs, life chapter and verse stolen from insurance IT biz
4chan, the ‘internet’s litter box,’ appears to have been pillaged by rival forum
China names alleged US snoops over Asian Winter Games attacks
All right, you can have one: DOGE access to Treasury IT OK’d judge
OpenAI GPT-4.1 models promise improved coding and instruction following
RansomHouse ransomware: what you need to know
The AI Fix #46: AI can read minds now, and is your co-host a clone?
Chinese snoops use stealth RAT to backdoor US orgs – still active last week

* bsc#1065729 * bsc#1179878 * bsc#1180814 * bsc#1185762 * bsc#1195823

* bsc#1240971 Cross-References: * CVE-2025-32464

* bsc#1240958 * bsc#1240961 * bsc#1240962 * bsc#1240963 * bsc#1240964

* bsc#1228714 * bsc#1232818 * bsc#1235218 * bsc#1238788 * bsc#1238790

ActiveX blocked by default in Microsoft 365 because remote code execution is bad, OK?
Where it Hertz: Customer data driven off in Cleo attacks
Measuring success in dataops, data governance, and data security
Google’s bold step toward hybrid AI integration
EU gives staff ‘burner phones, laptops’ for US visits
Don’t delete that mystery empty folder. Windows put it there as a security fix
Microsoft .NET Aspire adds resource graph, publishers
New SSL/TLS certs to each live no longer than 47 days by 2029
Cyber congressman demands answers before CISA gets cut down to size

Perl could be made to crash or run programs if it processed specially crafted data.

* bsc#1065729 * bsc#1180814 * bsc#1183682 * bsc#1190336 * bsc#1190768

* bsc#1228714 * bsc#1232818 * bsc#1235218 * bsc#1238788 * bsc#1238790

* bsc#1228714 * bsc#1235218 Cross-References: * CVE-2024-41090

Official abuse of state security has always been bad, now it’s horrifying
How pet projects fuel innovation and careers in tech
7 reasons low-code and no-code tools fail to deliver
DeepSeek’s open source movement
CIO and digi VP to depart UK retail giant Asda as Walmart divorce woes settle
Medusa ransomware gang claims to have hacked NASCAR
Old Fortinet flaws under attack with new method its patch didn’t prevent
China reportedly admitted directing cyberattacks on US infrastructure
Hacktivism resurges – but don’t be fooled, it’s often state-backed goons in masks

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, cross-site scripting or restriction bypass.

Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation

Update to 6.0.39 (CVE-2024-45700, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699)

Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation

https://security-tracker.debian.org/tracker/DSA-5902-1

https://security-tracker.debian.org/tracker/DSA-5901-1

Multiple vulnerabilities were found in wpa, a set of tools including the widely-used wpasupplicant client for authenticating with WPA and WPA2 wireless networks.

.NET 10 Preview 3 bolsters standard library, C#, WebAssembly
LLMs can’t stop making up software dependencies and sabotaging everything

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN. (CVE-2025-32364) Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in

ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. (CVE-2025-27795) References: – https://bugs.mageia.org/show_bug.cgi?id=34163

https://security-tracker.debian.org/tracker/DSA-5900-1

Microsoft total recalls Recall totally to Copilot+ PCs

https://security-tracker.debian.org/tracker/DSA-5899-1

Update to 1.34.5. Fixes CVE-2025-31498.

Limit the data stored in session state. Remove the empty area below the title bar in Web Inspector when not docked. Fix various crashes and rendering issues

Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions

Update to 7.2.5 (CVE-2024-36469, CVE-2024-42325, CVE-2024-45700)

* bsc#1073014 Cross-References: * CVE-2017-17521

* bsc#1239618 * jsc#PED-12500 * jsc#SLE-21253 Cross-References:

Ransomware reaches a record high, but payouts are dwindling
Ransomware crims hammering UK more than ever as British techies complain the board just doesn’t get it

For most of us, tax season is all about finding documents, filling out forms, and crossing your fingers you’re getting a refund. But while you’re busy trying to get your returns filed on time, tax scammers and identity thieves are busy trying to steal your precious personal information. During tax season, a vast amount of […]