Menu

Monthly Archives: April 2025

Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions

CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355026) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355024) CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow

This is an update fixing CVE 2025-30232.

https://security-tracker.debian.org/tracker/DSA-5896-1

https://security-tracker.debian.org/tracker/DSA-5895-1

https://security-tracker.debian.org/tracker/DSA-5894-1

https://security-tracker.debian.org/tracker/DSA-5893-1

https://security-tracker.debian.org/tracker/DSA-5892-1

Critical deserialization bug in Apache Parquet allows RCE
Google Cloud Next ’25: What to expect
Trump fires NSA boss, deputy

Imagine waking up one day to find that someone has stolen your identity, opened credit cards in your name, or even withdrawn money from your bank accounts. It’s something that can easily happen if your personal data falls into the hands of cybercriminals. In our interconnected world, data breaches and identity theft are a constant […]

* bsc#1229122 * bsc#1240550 Cross-References: * CVE-2025-22871

30 minutes to pwn town: Are speedy responses more important than backups for recovery?
Basking in JavaScript refinements
Enterprises are getting worse at multicloud
Alan Turing Institute: UK can’t handle a fight against AI-enabled crims
Ex-ASML, NXP staffer accused of stealing chip secrets, peddling them to Moscow
Retirement funds reportedly raided after unexplained portal probes and data theft

Upgrade to 2.48.0: Move tile rendering to worker threads when rendering with the GPU. Fix preserve-3D intersection rendering. Added new function for creating Promise objects to the JavaScriptCore GLib API. The MediaRecorder backend gained WebM support (requires at least GStreamer

Signalgate: Pentagon watchdog probes Defense Sec Hegseth
Sonatype warns of 18,000 open source malware packages

Several security issues were fixed in the Linux kernel.

For flux sake: CISA, annexable allies warn of hot DNS threat

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. (CVE-2024-56161)

Rust language adds trait upcasting

* bsc#1228012 * bsc#1228578 * bsc#1233023 Cross-References:

Suspected Chinese spies right now hijacking buggy Ivanti gear – for third time in 3 years
Hyperlight Wasm points to the future of serverless
GitHub upgrades tooling to help developers stop leaking secrets
When disaster strikes, proper preparation prevents poor performance
Accelerate cloud infrastructure initiatives with Lucid Software
HellCat ransomware: what you need to know
Why is someone mass-scanning Juniper and Palo Alto Networks products?

* bsc#1238591 * bsc#1239625 * bsc#1239637 Cross-References:

* bsc#1239302 * bsc#1239676 Cross-References: * CVE-2024-56337

* bsc#1240075 * bsc#1240077 * bsc#1240080 * bsc#1240081

EU: These are scary times – let’s backdoor encryption!
Heterogeneous stacks, ransomware, and ITaaS: A DR nightmare
How to use guard clauses in C#
Customer info allegedly stolen from Royal Mail, Samsung via compromised supplier

https://security-tracker.debian.org/tracker/DSA-5891-1

https://security-tracker.debian.org/tracker/DSA-5890-1

Smashing Security podcast #411: The fall of Troy, and whisky barrel scammers
Raw Deel: Corporate spy admits role in espionage at HR software biz Rippling
Django 5.2 release touts automatic model importing
Crimelords at Hunters International tell lackeys ransomware too ‘risky’
Informatica readies new Claire Copilot capabilities for IDMC
Oracle’s masterclass in breach comms: Deny, deflect, repeat
Don’t let cyberattacks keep you down
Google fixes GCP flaw that could expose sensitive container images
3 key features in Kong AI Gateway 3.10

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

* bsc#1234452 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5

* bsc#1219437 * bsc#1234089 * bsc#1237367 * bsc#1239185 * bsc#1239322

* bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029

For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection
When bots commit: AI-generated code in open source projects
Oracle faces Texas-sized lawsuit over alleged cloud snafu and radio silence
One of the last of Bletchley Park’s quiet heroes, Betty Webb, dies at 101
Making Python faster won’t be easy, but it’ll be worth it
HTMX and Alpine.js: How to combine two great, lean front ends
Rewriting Social Security will be a train wreck
Apple belatedly patches actively exploited bugs in older OSes
North Korea’s fake tech workers now targeting European employers
Forget Signal. National Security Adviser Waltz now accused of using Gmail for work

https://security-tracker.debian.org/tracker/DSA-5889-1

Red Hat Developer Hub adds analysis dashboard
Understand Python’s new lock file format
Microsoft to mark five decades of Ctrl-Alt-Deleting the competition
The AI Fix #44: AI-generated malware, and a stunning AI breakthrough
Download the Strategizing Data Analytics for AI Enterprise Spotlight
Google makes end-to-end encrypted Gmail easy for all – even Outlook users

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

UK threatens £100K-a-day fines under new cyber bill
Hackers exploit little-known WordPress MU-plugins feature to hide malware
How to start developing a balanced AI governance strategy
Agentic AI won’t make public cloud providers rich
Java plan prepares to restrict final field mutation
GCHQ intern took top secret spy tool home, now faces prison
CISA spots spawn of Spawn malware targeting Ivanti flaw