Menu

Monthly Archives: June 2025

Hire me! To drop malware on your computer
Salesforce tags 5 CVEs after SaaS security probe uncovers misconfig risks
Asia dismantles 20,000 malicious domains in infostealer crackdown
Analysis to action: Operationalizing your threat intelligence
Databricks aims to optimize agent building for enterprises with Agent Bricks
Building an analytics architecture for unstructured data and multimodal AI
Databricks targets AI bottlenecks with Lakeflow Designer

* bsc#1238324 * bsc#1239077 Cross-References: * CVE-2022-49080

Microsoft slows Windows 11 24H2 Patch Tuesday due to a ‘compatibility issue’
10 JavaScript concepts you need to succeed with Node
Get started with the new Python Installation Manager
Managing software projects is a double-edged sword

* bsc#1243273 Cross-References: * CVE-2025-4516

* bsc#1239949 * bsc#1241050 * bsc#1243217 * bsc#1243218

* bsc#1239949 * bsc#1241050 * bsc#1243217 * bsc#1243218

CISO who helped unmask Badbox warns: Version 3 is coming

https://security-tracker.debian.org/tracker/DSA-5941-1

Microsoft warns of 66 flaws to fix for this Patch Tuesday, and two are under active attack
Mistral AI unveils Magistral reasoning model
Cisco Live: AI will bring developer workflow closer to the network
Texas warns 300,000 crash reports siphoned via compromised user account
Digital AI introduces Quick Protect Agent, a no-code way to protect mobile apps
Critical Wazuh bug exploited in growing Mirai botnet infection
Winning the war on ransomware with AI: Four real-world use cases
The AI Fix #54: Will AI collapse under its own garbage, and AI charity “Hunger Games”
Trump guts digital ID rules, claims they help ‘illegal aliens’ commit fraud
Not-So-Secure Boot: 2 Secure Boot Exploits Discovered
Cloud brute-force attack cracks Google users’ phone numbers in minutes
M&S online ordering system operational 46 days after cyber shutdown
Peep show: 40K IoT cameras worldwide stream secrets to anyone with a browser
Mastering AI risk: An end-to-end strategy for the modern enterprise
What the AI coding assistants get right, and where they go wrong
Don’t be a victim of high cloud costs

* bsc#1234282 * bsc#1238043 * bsc#1243117 Cross-References:

* bsc#1238324 * bsc#1239077 Cross-References: * CVE-2022-49080

* bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References:

* bsc#1232900 * bsc#1236701 * bsc#1239077 * bsc#1239096

Several security issues were fixed in tomcat8, tomcat9, tomcat10.

Apple tries to contain itself with lightweight Linux VMs for macOS
SQL slips in language popularity index

https://security-tracker.debian.org/tracker/DSA-5940-1

The AI platform wars will be won on the developer experience
Let them eat junk food: Major organic supplier to Whole Foods, Walmart, hit by cyberattack

DoS with sanitiseArg/sanitizeArg has been fixed in modsecurity-apache, a module for the Apache webserver to tighten Web application security. For Debian 11 bullseye, this problem has been fixed in version

New AI tool targets critical hole in thousands of open source apps
The 2024 Red Hat Product Security Risk Report: CVEs, XZ Backdoor, SSCAs, AI…oh my!
Blocking stolen phones from the cloud can be done, should be done, won’t be done
Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
Building a multi-zone and multi-region SQL Server Failover Cluster Instance in Azure
9 APIs you’ll love for AI integrations and automated workflows
Are technologists a threat to doing business securely?

Disallowing use of the arcfour-hmac(-md5) encryption type for session keys Add support for the PKINIT paChecksum2 sequence, required for Active Directory interoperability on Windows Server 2025 Fix generation of RADIUS Message-Authenticator in FIPS mode

China’s asteroid-and-comet hunter probe unfurls a ‘solar wing’

Kirill Firsov discovered that Roundcube, a skinnable AJAX based webmail solution for IMAP servers, was performing PHP Object deserialization on unvalidated input, which could lead to remote code execution by an authenticated attacker.

US infrastructure could crumble under cyberattack, ex-NSA advisor warns

Several vulnerabilities were discovered in modsecurity-apache, an Apache module to tighten the Web application security, which may result in denial of service (high memory consumption).

New libvpx packages are available for Slackware 15.0 and -current to fix security issues.

Enterprises are getting stuck in AI pilot hell, say Chatterbox Labs execs

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data.

Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump. (CVE-2025-4598) References:

Security constraint bypass for CGI scripts. (CVE-2025-46701) References: – https://bugs.mageia.org/show_bug.cgi?id=34332 – https://openwall.com/lists/oss-security/2025/05/29/4

Add patch for double free

Update to version 4.21.6

Fix CVE-2025-23016

Marks & Spencer’s ransomware nightmare – more details emerge
US offers $10 million reward for tips about state-linked RedLine hackers

Update to Samba 4.22.2 – Security fix for CVE-2025-0620

Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink

This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.

Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink

This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.

ChatGPT used for evil: Fake IT worker resumes, misinfo, and cyber-op assist
BladedFeline: Whispering in the dark

ESET researchers analyzed a cyberespionage campaign conducted by BladedFeline, an Iran-aligned APT group with likely ties to OilRig

Fresh strain of pro-Russian wiper flushes Ukrainian critical infrastructure
Smashing Security podcast #420: Fake Susies, flawed systems, and fruity fixes for anxiety
Uncle Sam moves to seize $7.7M laundered by North Korean IT worker ring

* bsc#1243268 Cross-References: * CVE-2025-47287

* bsc#1236826 * bsc#1239671 * bsc#1241012 Cross-References:

* bsc#1240392 Cross-References: * CVE-2025-2704

* bsc#1236974 Cross-References: * CVE-2024-12243

Your ransomware nightmare just came true – now what?

Several security issues were fixed in the Linux kernel.

JavaScript innovation and the culture of programming
Decentralized mesh cloud: A promising concept

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-24223

https://security-tracker.debian.org/tracker/DSA-5939-1

https://security-tracker.debian.org/tracker/DSA-5938-1

https://security-tracker.debian.org/tracker/DSA-5937-1

Uncle Sam puts $10M bounty on RedLine dev and Russia-backed cronies
AT&T not sure if new customer data dump is déjà vu
Adobe adds Product Support Agent for AI-assisted troubleshooting
Cellebrite buys Corellium to help cops bust phone encryption
Trump’s cyber czar pick grilled over CISA cuts: ‘If we have a cyber 9/11, you’re the guy’
Snowflake: Latest news and insights
BidenCash busted as Feds nuke stolen credit card bazaar
Workday’s new dev tools help enterprises connect with external agents