Menu

Monthly Archives: May 2025

nodejs:20 enhancement update

nodejs:18 enhancement update

You’ll never guess which mobile browser is the worst for data collection
The best new features and fixes in Python 3.14
Toll road scams are in overdrive: Here’s how to protect yourself

Have you received a text message about an unpaid road toll? Make sure you’re not the next victim of a smishing scam.

The Hidden Risks of Russian-Linked Open-Source Tool easyjson
Curl project founder snaps over deluge of time-sucking AI slop bug reports

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

IBM’s watsonx.data could simplify agentic AI-related data issues

Several security issues were fixed in the Linux kernel.

Technical debt is just an excuse
8 ways to do more with modern JavaScript
How to gracefully migrate your JavaScript programs to TypeScript
TeleMessage, the Signal clone used by US government officials, suffers hack
New Zealand kind-of moves to ban social media for under-16s, require age checks for new accounts

https://security-tracker.debian.org/tracker/DSA-5916-1

Super spyware maker NSO must pay Meta $168M in WhatsApp court battle
Google updates Gemini 2.5 Pro model for coders
Computacenter IT guy let girlfriend into Deutsche Bank server rooms, says fired whistleblower
Pentagon declares war on ‘outdated’ software buying, opens fire on open source
IBM updates watsonx Orchestrate with new agent-building capabilities
Static analysis proposed for shell programs
The AI Fix #49: The typo from hell
CNCF and Synadia Resolve NATS Trademark Dispute

An update that fixes four vulnerabilities is now available.

Public clouds burnish their on-premises options
Why LLM applications need better memory management
Using AI-powered email classification to accelerate help desk responses

Several security issues were fixed in OpenJDK 24.

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 17.

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

CISA slammed for role in ‘censorship industrial complex’ as budget faces possible $500M cut
Signal chat app clone used by Signalgate’s Waltz was apparently an insecure mess
JetBrains open-sources Mellum LLM

Phishing attacks are a significant threat to consumers, with cybercriminals constantly evolving their tactics to deceive unsuspecting individuals. The integration of artificial intelligence (AI) into phishing schemes has made these attacks even more sophisticated and challenging to detect. AI-enabled phishing attacks seriously threaten consumers and their data. The volume of these attacks is staggering with […]

How MCP could add value to MongoDB databases
Bringing DevOps, DevSecOps, and MLOps together
Knowing when to use AI coding assistants

* bsc#1223272 * bsc#1234028 * bsc#1235091 * bsc#1235092 * bsc#1236007

* bsc#1202828 * bsc#1217770 * bsc#1224413 * jsc#PED-11066 * jsc#PED-1174

* bsc#1202828 * bsc#1217770 * bsc#1224413 * jsc#PED-11066 * jsc#PED-1174

Trump promises protection for TikTok, for which he has a ‘warm spot in my heart’
India’s chipmaking ambitions hurt by Zoho’s no-go and Adani unease
Microsoft tries to knife passwords once and for all – at least for consumers
RSA Conf wrap: AI and China on everything, everywhere, all at once
RSAC 2025 wrap-up – Week in security with Tony Anscombe

From the power of collaborative defense to identity security and AI, catch up on the event’s key themes and discussions

Deno 2.3 adds compile improvements, support for local NPM packages
Altman’s eyeball-scanning biometric blockchain orbs officially come to America

ansible 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 introduced a regression in the win_template module. This caused win_template tasks to fail with an error. For Debian 11 bullseye, this problem has been fixed in version

Update to 136.0.7103.59 CVE-2025-4096: Heap buffer overflow in HTML CVE-2025-4050: Out of bounds memory access in DevTools CVE-2025-4051: Insufficient data validation in DevTools CVE-2025-4052: Inappropriate implementation in DevTools

April 2025 CPU

A heap-based buffer overflow vulnerability was discovered in vips, an fast image processing library designed with efficiency in mind, which may result in denial of service (application crash) if a specially crafted TIFF image file is processed.

Update to 136.0.7103.59 * CVE-2025-4096: Heap buffer overflow in HTML * CVE-2025-4050: Out of bounds memory access in DevTools * CVE-2025-4051: Insufficient data validation in DevTools * CVE-2025-4052: Inappropriate implementation in DevTools

Update to 128.10.0 https://www.thunderbird.net/en-US/thunderbird/128.10.0esr/releasenotes/

Update to version 1.5.0 (for now, without PPS feature enabled due to potential correctness issues in the code). Release notes: https://github.com/pendulum-project/ntpd-rs/releases/tag/v1.5.0 Also contains the fix for GHSA-v83q-83hj-rw38.

Update to version 0.24.4. Also contains fixes for RUSTSEC-2025-0006.

Update pnpm to version 10.9.0 to fix CVE-2024-47829 and nodejs-bash-language- server to version 5.6.0

https://security-tracker.debian.org/tracker/DSA-5915-1

https://security-tracker.debian.org/tracker/DSA-5914-1

https://security-tracker.debian.org/tracker/DSA-5913-1

TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks

ESET researchers analyzed Spellbinder, a lateral movement tool used to perform adversary-in-the-middle attacks

Disney Slack attack wasn’t Russian protesters, just a Cali dude with malware
Generative AI makes fraud fluent – from phishing lures to fake lovers
AWS changes the pricing of CloudWatch logs in Lambda
Three Brits charged over ‘active shooter threats’ swattings in US, Canada
Amazon launches Nova Premier, its ‘most capable’ AI model yet
Leaderboard illusion: How big tech skewed AI rankings on Chatbot Arena
British govt agents step in as Harrods becomes third mega retailer under cyberattack
Experiments in JavaScript: What’s new in reactive design
Public cloud providers get into the chip market

Update to 1.17.4 Fixes CVE-2025-23359 or GHSA-4hmh-pm5p-9j7j

Update to 128.10.0 https://www.thunderbird.net/en-US/thunderbird/128.10.0esr/releasenotes/

Update to latest upstream (138.0)

Update to 1.17.4 Fixes CVE-2025-23359 or GHSA-4hmh-pm5p-9j7j

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Update to 1.17.4 Fixes CVE-2025-23359 or GHSA-4hmh-pm5p-9j7j

JetBrains AI Assistant panned in JetBrains Marketplace
Dems look to close the barn door after top DOGE dog has bolted

https://security-tracker.debian.org/tracker/DSA-5911-1

https://security-tracker.debian.org/tracker/DSA-5910-1

https://security-tracker.debian.org/tracker/DSA-5909-1

Healthcare group Ascension discloses second cyberattack on patients’ data
How Amazon red-teamed Alexa+ to keep your kids from ordering 50 pizzas
Redis bets big on an open source return

Several security issues were fixed in micropython.

Chris Krebs loses Global Entry membership amid Trump feud
Data watchdog will leave British Library alone – further probes ‘not worth our time’

The following vulnerability has been discovered in the gorilla/csrf package for Go: Prior to 1.7.3, gorilla/csrf did not validate the Origin header against an allowlist. It executed its validation of the Referer header for

In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used. (CVE-2025-43965) In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order). (CVE-2025-46393)

Multiple vulnerabilties were discovered in u-boot, a boot loader for embedded systems.