* bsc#1243313 Cross-References: * CVE-2025-47273
* bsc#1242931 Cross-References: * CVE-2025-4207
ESET Research has been tracking Danabot’s activity since 2018 as part of a global effort that resulted in a major disruption of the malware’s infrastructure
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
A few fixes
This is the May 2025 update for .NET 8 for Fedora. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.16/8.0.116.md Runtime: https://github.com/dotnet/core/blob/main/release-
Update to version 12.5.2. Fixes CVE-2025-22247
Update to 128.10.2 https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/
A few fixes
ESET Research shares its findings on the workings of Danabot, an infostealer recently disrupted in a multinational law enforcement operation
The bustling cybercrime enterprise has been dealt a significant blow in a global operation that relied on the expertise of ESET and other technology companies
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Update to 128.10.2 https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/ Update to 128.10.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-34/ https://www.thunderbird.net/en-US/thunderbird/128.10.1esr/releasenotes/
CVE-2025-46646 ghostscript: Mishandling of Overlong UTF-8 Encoding in decode_utf8() (fedora#2362639, fedora#2362446)
Fix for CVE-2025-47268
https://security-tracker.debian.org/tracker/DSA-5925-1
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel’® Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2024-28956) Insufficient resource pool in the core management mechanism for some
Heap buffer overflow in HTML. (CVE-2025-4096) Out of bounds memory access in DevTools. (CVE-2025-4050) Insufficient data validation in DevTools. (CVE-2025-4051) Inappropriate implementation in DevTools. (CVE-2025-4052) Use after free in WebAudio. (CVE-2025-4372)
Our intense monitoring of tens of thousands of malicious samples helped this global disruption operation
* bsc#1229504 * bsc#1233019 * bsc#1234847 Cross-References:
* bsc#1233019 * bsc#1234847 Cross-References: * CVE-2024-50115
* bsc#1233019 * bsc#1233678 * bsc#1234847 Cross-References:
https://security-tracker.debian.org/tracker/DSA-5924-1
libfcgi-perl could be made to crash or execute arbitrary code.
* bsc#1243268 Cross-References: * CVE-2025-47287
Update to version 0.2.6.
Latest upstream release. Changelog: https://github.com/gorhill/uBlock/releases/tag/1.64.0 . Fixes CVE-2025-4215 .
Update to version 0.2.6.
ESET Chief Security Evangelist Tony Anscombe highlights key findings from the latest issue of the ESET APT Activity Report
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2024 and Q1 2025
PostgreSQL could be made to crash if it received specially crafted network traffic.
* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757
* bsc#1235958 * bsc#1235971 * bsc#1239651 * bsc#1242971 * jsc#PED-12028
* bsc#1242622 * jsc#PED-12028 Cross-References: * CVE-2025-3416
* bsc#1240897 Cross-References: * CVE-2025-3360
