Menu

Monthly Archives: June 2025

More than a hundred backdoored malware repos traced to single GitHub user
HMRC: Crooks broke into 100k accounts, stole £43M from British taxpayer in late 2024

Several security issues were fixed in Bootstrap.

How to test your Java applications with JUnit 5
Automating devops with Azure SRE Agent

Several security issues were fixed in the Linux kernel.

* bsc#1243332 * bsc#1243422 * bsc#1243423 Cross-References:

* bsc#1243313 Cross-References: * CVE-2025-47273

* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References:

AI kept 15-year-old zombie vuln alive, but its time is drawing near
China accuses Taiwan of running five feeble APT gangs, with US help
IBM Cloud login breaks for second time this week and Big Blue isn’t saying why

https://security-tracker.debian.org/tracker/DSA-5936-1

Play ransomware crims exploit SimpleHelp flaw in double-extortion schemes
AI is powering enterprise development, GitHub says
Ukraine strikes Russian bomber-maker with hack attack
Ransomware scum leak patient data after disrupting chemo treatments at Kettering
Snowflake customers must choose between performance and flexibility
Fake IT support calls hit 20 orgs, end in stolen Salesforce data and extortion, Google warns
The AI Fix #53: An AI uses blackmail to save itself, and threats make AIs work better
Crims stole 40,000 people’s data from our network, admits publisher Lee Enterprises
UK CyberEM Command to spearhead new era of armed conflict
JavaScript promises: 4 gotchas and how to avoid them
New to Rust? Don’t make these common mistakes
Naming is easy! A guide for developers
Ukraine war spurred infosec vet Mikko Hyppönen to pivot to drones
‘Deliberate attack’ deletes shopping app’s AWS and GitHub resources

https://security-tracker.debian.org/tracker/DSA-5935-1

Meta pauses mobile port tracking tech on Android after researchers cry foul
Kotlin cozies up to Spring Framework
You say Cozy Bear, I say Midnight Blizzard, Voodoo Bear, APT29 …

https://security-tracker.debian.org/tracker/DSA-5934-1

Snowflake acquires Crunchy Data for enterprise-grade PostgreSQL to counter Databricks’ Neon buy
Google quietly pushes emergency fix for Chrome 0-day as exploit runs wild
Snowflake takes aim at legacy data workloads with SnowConvert AI migration tools
X’s new ‘encrypted’ XChat feature seems no more secure than the failure that came before it

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to “*.example.com”, a request to “[::1%25.example.com]:80` will incorrectly match and not be proxied – CVE-2025-22870.

Crooks fleece The North Face accounts with recycled logins
Don’t let dormant accounts become a doorway for cybercriminals

Do you have online accounts you haven’t used in years? If so, a bit of digital spring cleaning might be in order.

C# 14 introduces file-based apps
Snowflake’s Cortex AISQL aims to simplify unstructured data analysis

Several security issues were fixed in the Linux kernel.

Microsoft patches the patch that put Windows 11 in a coma
Snowflake launches Openflow to tackle AI-era data ingestion challenges
The Hidden Security Risks of Open-Source AI
Illicit crypto-miners pouncing on lazy DevOps configs that leave clouds vulnerable

Open VM Tools could be made to overwrite files as the administrator.

The high cost of misconfigured DevOps: Global cryptojacking hits enterprises
Bling slinger Cartier tells customers to be wary of phishing attacks after intrusion
Real-time analytics with StarTree Cloud and Apache Pinot
3 cloud migration secrets

Several security issues were fixed in MariaDB.

The month of June is a time for fun in the sun and a break from the school year, but did you know it’s also the perfect time to step up your family’s online security? June is Internet Safety Month, a yearly reminder to strengthen your defenses against online threats. In today’s hyper-connected world, we […]

Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Various other fixes

Two security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2025-47779

Ukrainians smuggle drones hidden in cabins on trucks to strike Russian airfields
Download the ‘New Thinking about Cloud Computing’ Enterprise Spotlight

* bsc#1214960 * bsc#1230092 Cross-References: * CVE-2024-45310

* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

* bsc#1231284 Cross-References: * CVE-2024-8508

* bsc#1237367 * bsc#1239185 * bsc#1239322 * bsc#1239765 * jsc#PED-12534

* bsc#1234128 * bsc#1234665 * bsc#1239883 * bsc#1243317

US community bank says thieves drained customer data through third party hole
Google’s AI Edge Gallery will let developers deploy offline AI models — here’s how it works
7 ways to improve your AI coding results
Demystifying serverless in the modern data and AI landscape
Private cloud still matters—but it doesn’t matter most
Lumma infostealer takedown may have inflicted only a flesh wound as crew keeps pinching and selling data
This month in security with Tony Anscombe – May 2025 edition

From a flurry of attacks targeting UK retailers to campaigns corralling end-of-life routers into botnets, it’s a wrap on another month filled with impactful cybersecurity news

Unlock sensitive data for AI with Cloudera on Red Hat OpenShift

twitter-bootstrap3 a popular front end framework was affected by a vulnerability. A cross-site scripting (XSS) vulnerability

A vulnerability has been found in kitty, a fast, featureful, GPU based terminal emulator, which possible allows arbitrary code execution. CVE-2022-41322

Update to 128.11.0 https://www.thunderbird.net/en-US/thunderbird/128.11.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-46/

Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Fixes for systemd itself, run0, systemd-networkd, “secure” pager, man pages, shell completions, sd-boot, sd-varlink Hardware database update

https://security-tracker.debian.org/tracker/DSA-5933-1