Menu

Monthly Archives: May 2025

Multiple stack-based buffer overflows have been fixed in the net-tools network utilities. For Debian 11 bullseye, this problem has been fixed in version

Double free on init failure has been fixed in libvpx, a library for decoding and encoding VP8 and VP9 videos. For Debian 11 bullseye, this problem has been fixed in version

Damascened Peacock: Russian hackers targeted UK Ministry of Defence
Mysterious leaker GangExposed outs Conti kingpins in massive ransomware data dump

Several issues have been found in espeak-ng, a Multi-lingual software speech synthesizer. The issues are related to buffer overflow or underflow in several

Buffer underflow on glib through glib/gstring.c via function g_string_insert_unichar. (CVE-2025-4373) References: – https://bugs.mageia.org/show_bug.cgi?id=34310

Heap buffer under-read in gnu coreutils sort via key specification. (CVE-2025-5278) References: – https://bugs.mageia.org/show_bug.cgi?id=34313

Multiple security issues were discovered in Flask-CORS, a Flask extension for handling Cross Origin Resource Sharing (CORS). CVE-2024-1681

New upstream version (139.0)

This update contains the backported fix for CVE-2024-52804 (cookie parsing DoS vuln).

CheerpJ WebAssembly JVM previews Java 17 support

https://security-tracker.debian.org/tracker/DSA-5931-1

https://security-tracker.debian.org/tracker/DSA-5930-1

MariaDB’s acquisition of Codership: Why enterprises should care
ConnectWise customers get mysterious warning about ‘sophisticated’ nation-state hack
Feds arrest DoD techie, claim he dumped top secret files in park for foreign spies to find
US medical org pays $50M+ to settle case after crims raided data and threatened to swat cancer patients
Teradata partners with Fivetran to assist data centralization in VantageCloud
Meta – yep, Facebook Meta – is now a defense contractor
Angular v20 arrives with eyes on generative AI development

Apport could be made to leak sensitive information.

* bsc#1243353 Cross-References: * CVE-2025-5263 * CVE-2025-5264

* bsc#1241274 * bsc#1241275 * bsc#1241276 * bsc#1242208 * bsc#1243429

* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268

* bsc#1242931 Cross-References: * CVE-2025-4207

AWS’ Serverless MCP Server to aid agentic development of managed applications
Crims defeat human intelligence with fake AI installers they poison with ransomware

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure. For Debian 11 bullseye, these problems have been fixed in version

Data watchdog put cops on naughty step for lost CCTV footage
F-strings with superpowers: What’s new in Python 3.14 beta
A wake-up call for real cloud ROI
The UK wants you to sign up for £1B cyber defense force
Interlock ransomware: what you need to know
Infosecurity Europe 2025 drives cybersecurity priorities amid growing global risks
Security outfit SentinelOne’s services back online after lengthy outage
Feds gut host behind pig butchering scams that bilked $200M from Americans

https://security-tracker.debian.org/tracker/DSA-5932-1

Microsoft’s May Patch Tuesday update fails on some Windows 11 VMs

https://security-tracker.debian.org/tracker/DSA-5923-2

https://security-tracker.debian.org/tracker/DSA-5928-1

Why is China deep in US networks? ‘They’re preparing for war,’ HR McMaster tells lawmakers
Unlocking data’s true potential: The open lakehouse as AI’s foundation
8,000+ Asus routers popped in ‘advanced’ mystery botnet plot
Google Cloud’s BigLake-driven lakehouse updates aim to optimize performance, costs

* bsc#1242008 * bsc#1242009 Cross-References: * CVE-2025-31650

* bsc#1236217 * bsc#1242715 Cross-References: * CVE-2025-22873

* bsc#1241658 * bsc#1241659 Cross-References: * CVE-2025-43965

* bsc#1243216 Cross-References: * CVE-2025-3875 * CVE-2025-3877

* bsc#1242809 Cross-References: * CVE-2025-3887

Microsoft envisions Windows Update as the unified platform for all software updates
Billions of cookies up for grabs as experts warn over session security
Tails and Tor: A New Alliance for Digital Security
Mistral AI launches code embedding model, claims edge over OpenAI and Cohere
European Commission: Make Europe Great Again… for startups
Using Microsoft Fabric to create digital twins
Docling: An open-source toolkit for advanced document processing
Reports of Deno’s demise ‘greatly exaggerated,’ Deno creator says
Victoria’s Secret website laid bare for three days after ‘security incident’
Adversarial AI: The new frontier in financial cybersecurity

https://security-tracker.debian.org/tracker/DSA-5929-1

Smashing Security podcast #419: Star Wars, the CIA, and a WhatsApp malware mirage
Attack on LexisNexis Risk Solutions exposes data on 300k +
Word to the wise: Beware of fake Docusign emails

Cybercriminals impersonate the trusted e-signature brand and send fake Docusign notifications to trick people into giving away their personal or corporate data

The AI Fix #52: AI adopts its own social norms, and AI DJ creates diversity scandal

A path traversal vulnerability in `PackageIndex` was found in setuptools. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context.

GNU C Library could be made to crash or run programs if it processed specially crafted dynamically shared library.

* bsc#1243313 Cross-References: * CVE-2025-47273

* bsc#1243356 Cross-References: * CVE-2025-21490

* bsc#1242809 Cross-References: * CVE-2025-3887

Russian IT pro sentenced to 14 years forced labor for sharing medical data with Ukraine
Revive Your Old PC & Fortify Your System with FunOS
The cost of compromise: Why password attacks are still winning in 2025
AI didn’t kill Stack Overflow
How to hire software developers
DragonForce double-whammy: First hit an MSP, then use RMM software to push ransomware
ASUS to chase business PC market with free AI, or no AI – because nobody knows what to do with it

https://security-tracker.debian.org/tracker/DSA-5927-1

https://security-tracker.debian.org/tracker/DSA-5926-1

Don’t click on that Facebook ad for a text-to-AI-video tool
Adidas customers’ personal information at risk after data breach
New Russian cyber-spy crew Laundry Bear joins the email-stealing pack
Adidas confirms criminals stole data from customer service provider

A flaw was discovered in the dynamic linking support in the GNU C Library, the C standard library implementation used by Debian. Privilege escalation may be possible in statically compiled setuid

Salesforce to buy Informatica in $8 billion deal

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in Intel Microcode.

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

Ransomware attack on MATLAB dev MathWorks – licensing center still locked down
AWS adds observability support to Aurora PostgreSQL Limitless
IT leadership lessons from ‘Leroy Jenkins’
What we know now about generative AI for software development
Lessons from building retrieval systems for AI assistants

PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2021-3539

Multicloud developer lessons from the trenches

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.