Menu

Monthly Archives: June 2025

AWS locks down cloud security, hits 100% MFA enforcement for root users
Sitecore CMS flaw let attackers brute-force ‘b’ for backdoor
The AI Fix #55: Atari beats ChatGPT at chess, and Apple says AI “thinking” is an illusion
Redefining identity security in the age of agentic AI

Ready, set, pack! Summer travel season is here and that means family road trips, beach vacations, international adventures and more. While summertime is prime time for getaways, did you know it’s also prime time for online fraud? Scammers are targeting the travel industry, putting millions of travelers at increased risk. Research shows that the travel […]

23andMe hit with £2.3M fine after exposing genetic data of millions
Malicious PyPI package targets Chimera users to steal AWS tokens, CI/CD secrets

* bsc#1223096 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

Secure RHEL Clones Chart Diverging Paths

Django could be made to log injection if received specially crafted input.

Amazon Bedrock faces revamp pressure amid rising enterprise demands
Design a better customer experience with agentic AI
A developer’s guide to AI protocols: MCP, A2A, and ACP
Navigating the rising costs of AI inferencing

Update to 128.11.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/

Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags() Fixes CVE-2025-48432: Potential log injection via unescaped request path

Rebuild against idna 1.0+ for CVE-2024-12224

Rebuild for CVE-2024-12224, CVE-2025-4574

Java 25 to change Windows file operation behaviors
Scattered Spider has moved from retail to insurance
Remorseless extortionists claim to have stolen thousands of files from Freedman HealthCare
Canada’s WestJet says ‘expect interruptions’ online as it navigates cybersecurity turbulence
Eurocops arrest suspected Archetyp admin, shut down mega dark web drug shop
Salesforce study finds LLM agents flunk CRM and confidentiality tests
Microsoft adds export option to Windows Recall in Europe

* bsc#1215935 * bsc#1215936 * bsc#1233606 * bsc#1233608 * bsc#1233609

* bsc#1242015 Cross-References: * CVE-2025-3891

Databricks Data + AI Summit 2025: Five takeaways for data professionals, developers
Spy school dropout: GCHQ intern jailed for swiping classified data

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Rethinking the dividing lines between containers and VMs
Top 6 multicloud management solutions
Understanding how data fabric enhances data security and governance
The key to Oracle’s AI future

Several security issues were fixed in ModSecurity.

How collaborative security can build you a better business
Armored cash transport trucks allegedly hauled money for $190 million crypto-laundering scheme
Optimizing Linux Security in 2025: Key Strategies & Best Practices
Dems demand audit of CVE program as Federal funding remains uncertain

A stack-based buffer overflow has been fixed in ICU, a C++ and C library for Unicode and Globalization support. For Debian 11 bullseye, this problem has been fixed in version

Two vulnerabilities have been fixed in cJSON, a C library for parsing JSON. CVE-2023-26819

An input sanitization flaw in Konsole might allow remote attackers to execute commands via a malicious URL

An integer overflow vulnerability has been found in sysstat which could result in arbitrary code execution.

Fix CVE-2025-49112 Fix CVE-2025-49112

Security update

New version 4.4.7 Ignoring potential error when using udevadm in %post scriptlet

Update to 137.0.7151.103 CVE-2025-5958: Use after free in Media CVE-2025-5959: Type Confusion in V8

Bert ransomware: what you need to know
Why Denmark is breaking up with Microsoft

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

Fix CVE-2025-49466 (fedora#2370375)

Update to 3.12.11. gh-135034: [CVE 2024-12718] [CVE 2025-4138] [CVE 2025-4330] [CVE 2025-4435] [CVE 2025-4517] Fixes multiple issues that allowed tarfile extraction filters (filter=”data” and filter=”tar”) to be bypassed using crafted symlinks and hard links.

Cyber weapons in the Israel-Iran conflict may hit the US
SmartBear unveils AI-driven test automation for iOS and Android apps
Reevaluating Security in Open-Source: Is a Baseline Truly Sufficient?
Visual Studio Code bolsters MCP support
Do you trust Xi with your ‘private’ browsing data? Apple, Google stores still offer China-based VPNs, report says
Dutch police identify users as young as 11-year-old on Cracked.io hacking forum
Apple fixes zero-click exploit underpinning Paragon spyware attacks
Malware attack disguises itself as DeepSeek installer
GitHub launches Remote MCP server in public preview to power AI-driven developer workflows
Wanted: Junior cybersecurity staff with 10 years’ experience and a PhD

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Linux ELF Malware: The New Front in the Battle for Cloud Security
A Closer Look at Apples Native macOS Container Tool
Nifty new Python projects to watch and try
Europe is caught in a cloud dilemma
Slapped wrists for Financial Conduct Authority staff who emailed work data home
South African man imprisoned after ransom demand against his former employer
Fingwit: Biometric Authentication & Dynamic Security on Linux
Ransomware scum disrupted utility services with SimpleHelp attacks
Talos Linux: Redefining Security for Kubernetes Environments

https://security-tracker.debian.org/tracker/DSA-5942-1

.NET 10 Preview 5 highlights C# 14, runtime improvements
Sweden says it is under cyber attack

* bsc#1240750 * bsc#1240752 * bsc#1240754 * bsc#1240756 * bsc#1240757

* bsc#1244035 Cross-References: * CVE-2025-22868 * CVE-2025-22869

* bsc#1237147 * bsc#1241938 * bsc#1243106 Cross-References:

* bsc#1242300 Cross-References: * CVE-2025-47268

* bsc#1232900 * bsc#1236701 * bsc#1239077 * bsc#1239096

* bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References:

Databricks One mirrors Microsoft Copilot strategy to transform enterprise data access
The open source paradox: Unpacking risk, equity and acceptance
Red Hat’s global impact on Linux security
‘Major compromise’ at NHS temping arm exposed gaping security holes
Empty shelves after US’s largest natural and organic food distributor suffers cyber attack
How to use frozen collections in C#
Use geospatial data in Azure with Planetary Computer Pro
Apple rolls out Swift, SwiftUI, and Xcode updates
Salesforce changes Slack API terms to block bulk data access for LLMs
DeepSeek installer or just malware in disguise? Click around and find out
Smashing Security podcast #421: Toothpick flirts, Google leaks, and ICE ICE scammers