Menu

Monthly Archives: May 2025

How to use template strings in Python 3.14

A vulnerability has been discovered in FreeType, which can lead to remote code execution.

Abseil could be made to crash if it received specially crafted input.

Ransomware scum have put a target on the no man’s land between IT and operations
Scala stabilizes named tuples

Update to 136.0.7103.92 CVE-2025-4372: Use after free in WebAudio

Apple patched one first, but Microsoft’s blasted five exploited flaws this Pa-Tu

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Intel’s data-leaking Spectre defenses scared off yet again
Qatar’s $400M jet for Trump is a gold-plated security nightmare
Commvault fixes critical Command Center issue after flaw finder alert
The AI Fix #50: AI brings dead man back for killer’s trial, and the judge loves it
‘We still have embeds in CISA’: CTO of Brit cyber agency talks post-Trump relationship with US counterpart
4 key capabilities of Kong’s Event Gateway for real-time event streams
Emerging ClickFix Attacks Are Now Targeting Linux Systems
Marks & Spencer admits cybercrooks made off with customer info
Google to unveil AI agent for developers at I/O, expand Gemini integration
As US vuln-tracking falters, EU enters with its own security bug database
What ‘cloud first’ can teach us about ‘AI first’
How to use genAI for requirements gathering and agile user stories
Agentic mesh: The future of enterprise agent ecosystems

* bsc#1242008 * bsc#1242009 Cross-References: * CVE-2025-31650

Several security issues were fixed in the Linux kernel.

Türkiye-linked spy crew exploited a messaging app zero-day to snoop on Kurdish army in Iraq

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5918-1

M365 apps on Windows 10 to get security fixes into 2028
C# 14 introduces extension members
CISA mutes own website, shifts routine cyber alerts to Musk’s X, RSS, email
Why aggregating your asset inventory leads to better security
Attackers pwn charter airline helping Trump’s deportation campaign

Unlimited output buffer for unauthenticated clients has been fixed in the key¢”value database Redis. For Debian 11 bullseye, this problem has been fixed in version

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

A vulnerability has been discovered in Orc, which can lead to arbitrary code execution

Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in arbitrary code execution.

Britain’s cyber agents and industry clash over how to tackle shoddy software
MySQL at 30: Still important but no longer king
How to build (real) cloud-native applications
What software developers need to know about cybersecurity
Unending ransomware attacks are a symptom, not the sickness
DOGE worker’s old creds found exposed in infostealer malware dumps
You think ransomware is bad now? Wait until it infects CPUs

PDF signature forgery with adbe.pkcs7.sha1 SubFilter. (CVE-2025-2866) References: – https://bugs.mageia.org/show_bug.cgi?id=34234 – https://lists.debian.org/debian-security-announce/2025/msg00070.html

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on

Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function. (CVE-2025-31162) Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.

5.22.9

https://deluge.readthedocs.io/en/deluge-2.2.0/changelog.html 2.2.0 (2025-04-28) Breaking changes Removed Python 3.6 support (Python >= 3.7) Core

Update to version 22.15.0

GenAI isn’t taking software engineering jobs, but it is reshaping leadership roles
Catching a phish with many faces

Here’s a brief dive into the murky waters of shape-shifting attacks that leverage dedicated phishing kits to auto-generate customized login pages on the fly

Feds disrupt proxy-for-hire botnet, indict four alleged net miscreants
UK Ministry of Defence is spending less with US biz, and more with Europeans
Visual Studio Code beefs up AI coding features

Update to 47.7 notably fixing CVE-2025-3839

xz 5.8.1

xz 5.8.1

xz 5.8.1

xz 5.8.1

Fixes CVE-2025-47256 .

https://security-tracker.debian.org/tracker/DSA-5917-1

Beware of phone scams demanding money for ‘missed jury duty’

When we get the call, it’s our legal responsibility to attend jury service. But sometimes that call won’t come from the courts – it will be a scammer.

Sizing up the AI code generators
VC behemoth Insight Partners fears top-secret financial info swiped by cyber-miscreants
GenAI won’t take software engineering jobs, but is reshaping leadership

It all starts so innocently. You get a text saying “Your package couldn’t be delivered. Click here to reschedule.”  Little do you know, clicking that link could open the door for scammers to steal your identity, empty your bank account, or even plant malicious software (malware) on your device. Unless you know what to look out […]

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

openSUSE deep sixes Deepin desktop over security stink

* bsc#1224259 Cross-References: * CVE-2024-4853

* bsc#1242210 Cross-References: * CVE-2025-32873

* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References:

The dual challenge: Security and compliance
Trust and authenticity: In the kitchen and the software supply chain
LockBit ransomware gang breached, secrets exposed
Hackers hit deportation airline GlobalX, leak flight manifests, and leave an unsubtle message for “Donnie” Trump
7 application security startups at RSAC 2025
Cloud repatriation hits its stride
Python popularity climbs to highest ever – Tiobe
Delta Air Lines class action cleared for takeoff over CrowdStrike chaos
NCSC warns of IT helpdesk impersonation trick being used by ransomware gangs after UK retailers attacked

A vulnerability has been fixed in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality.

Comparing the AI code generators
Running PyTorch on an Arm Copilot+ PC
SAS supercharges Viya platform with AI agents, copilots, and synthetic data tools
Sudo-rs make me a sandwich, hold the buffer overflows
Node.js 24 drops MSVC support
PowerSchool paid thieves to delete stolen student, teacher data. Looks like crooks lied
Smashing Security podcast #416: High street hacks, and Disney’s Wingdings woe
After that 2024 Windows fiasco, CrowdStrike has a plan – jobs cuts, leaning on AI

Django could be made to crash if it received specially crafted network traffic.

New mariadb packages are available for Slackware 15.0 and -current to fix security issues.

Moderate: libXpm security update