Menu

Monthly Archives: May 2025

* bsc#1234847 Cross-References: * CVE-2024-53156

* bsc#1205495 * bsc#1230764 * bsc#1231103 * bsc#1231450 * bsc#1231910

Ransomware attack on food distributor spells more pain for UK supermarkets
Why is Microsoft offering to turn websites into AI apps with NLWeb?
SEC Twitter hack: Man imprisoned for role in attack that caused Bitcoin’s price to soar.

Several security issues were fixed in the Linux kernel.

Cloud asset management: A crucial missing ingredient

* bsc#1242631 * bsc#1243177 Cross-References: * CVE-2025-3416

Virgin Media O2 patches hole that let callers snoop on your coordinates
CISA has a new No. 2 … but still no official top dog
SEC SIM-swapper who Googled ‘signs that the FBI is after you’ put behind bars

Microcode updates has been released for Intel(R) processors, addressing multiple potential vulnerabilties that may allow denial of service or information disclosure.

Microsoft aims to improve agent versatility with Copilot Studio updates
OpenAI launches Codex AI agent to tackle multi-step coding tasks

.NET could be used to perform spoofing over a network.

Millions at risk after attackers steal UK legal aid data dating back 15 years
The AI Fix nominated for top podcast award. Vote now!
IT chiefs of UK’s massive health service urge vendors to make public security pledge
What comes after Stack Overflow?
How we replaced Azure Redis with Memcached
The best Java certifications for software developers

* bsc#1228634 * bsc#1232533 * bsc#1241012 * bsc#1241045

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

Eeek! p0wned Alabama hit by unspecified ‘cybersecurity event’

Enable CSS Overscroll Behavior by default. Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. Fix rendering when device scale factor change comes before the web view geometry update.

China launches an AI cloud into orbit -12 sats for now, 2,800 in coming years
Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’

Mohamed Maatallah discovered a stack-based buffer overflow in the get_name() function in net-tools, a collection of programs for controlling the network subsystem of the Linux kernel, which may result in denial of service (application crash) or potentially the execution of

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo

Update to 1.25.0

Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo

Update to 1.25.0

https://security-tracker.debian.org/tracker/DSA-5923-1

https://security-tracker.debian.org/tracker/DSA-5922-1

https://security-tracker.debian.org/tracker/DSA-5921-1

Boffins devise technique that lets users prove location without giving it away
Using RHEL confidential virtual machines to protect AI workloads on Microsoft Azure

Enable CSS Overscroll Behavior by default. Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. Fix rendering when device scale factor change comes before the web view geometry update.

x86: Indirect Target Selection [XSA-469, CVE-2024-28956]

update to 4.8.2 fixing CVE-2024-47619

update to 4.8.2 to fix CVE-2024-47619

Fired US govt workers, Uncle Xi wants you! – to apply for this fake consulting gig
America’s consumer watchdog drops leash on proposed data broker crackdown

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Google I/O 2025: All eyes on AI and Gemini
Visual Studio previews agent mode for multi-step coding tasks

* bsc#1242617 Cross-References: * CVE-2025-3416

* bsc#1236136 * bsc#1236771 Cross-References: * CVE-2024-13176

Sednit abuses XSS flaws to hit gov’t entities, defense companies

Operation RoundPress targets webmail software to steal secrets from email accounts belonging mainly to governmental organizations in Ukraine and defense contractors in the EU

Operation RoundPress

ESET researchers uncover a Russia-aligned espionage operation targeting webmail servers via XSS vulnerabilities

Defamation case against DEF CON terminated with prejudice
Broadcom employee data stolen by ransomware crooks following hit on payroll provider
Informatica extends MDM support to Microsoft Azure, Oracle
Prescription for disaster: Sensitive patient data leaked in Ascension breach
Good luck to Atos’ 7th CEO and its latest biz transformation
From hype to harm: 78% of CISOs see AI attacks already
Cloud and IT strategies in a time of global upheaval
Programmers dig Python and Zig
Scammers are deepfaking voices of senior US government officials, warns FBI
DoorDash scam used fake drivers, phantom deliveries to bilk $2.59M
Uno Platform introduces unified rendering engine

https://security-tracker.debian.org/tracker/DSA-5919-1

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Cyber fiends battering UK retailers now turn to US stores
Coinbase extorted for $20M. Support staff bribed. Customers scammed. One hell of a breach disclosure…
Socket buys Coana to tell you which security alerts you can ignore
Snowflake CISO on the power of ‘shared destiny’ and ‘yes and’
Accessibility in Microsoft Edge with ARIA and ARIA Notify
LiteLLM: An open-source gateway for unified LLM access

* bsc#1218424 * bsc#1236045 * bsc#1236046 * bsc#1236801 * jsc#SLE-18320

Here’s what we know about the DragonForce ransomware that hit Marks & Spencer

Update to 1.9.9 to fix CVE-2025-30194

Update to 1.9.9 to fix CVE-2025-30194

Databricks to acquire open-source database startup Neon to build the next wave of AI agents

https://security-tracker.debian.org/tracker/DSA-5920-1

.NET 10 Preview 4 enhances Zip processing, JIT compilation, Blazor WebAssembly
Smashing Security podcast #417: Hello, Pervert! – Sextortion scams and Discord disasters
Metal maker meltdown: Nucor stops production after cyber-intrusion

It was discovered that insecure file handling in open-vm-tools, an open source implementation of VMware Tools, may allow an unprivileged local guest user to tamper local files to trigger insecure file operations within that VM.

* bsc#1230959 * bsc#1231748 * bsc#1232326 * bsc#1240366 * bsc#1240607

Why CVSS is failing us and what we can do about it
Uncle Sam pulls $2.4B Leidos deal to support CISA after rival alleges foul play
How can we counter online disinformation? | Unlocked 403 cybersecurity podcast (S2E2)

Ever wondered why a lie can spread faster than the truth? Tune in for an insightful look at disinformation and how we can fight one of the most pressing challenges facing our digital world.

Ivanti patches two zero-days under active attack as intel agency warns customers
Meta’s still violating GDPR rules with latest plan to train AI on EU user data, says noyb
VPN Secure parent company CEO explains why he had to axe thousands of ‘lifetime’ deals
Two years’ jail for down-on-his-luck man who sold ransomware online
Boomi launches agentic AI tools, announces AWS collaboration
Informatica adds agents to automate its Intelligent Data Management Cloud
Go ahead and ignore Patch Tuesday – it might improve your security
Everyone’s deploying AI, but no one’s securing it – what could go wrong?
The three refactorings every developer needs most