Menu

Monthly Archives: July 2025

Update to 128.13.0 https://www.thunderbird.net/en-US/thunderbird/128.13.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-62/

JetBrains working on higher-abstraction programming language
Senator to Google: Give us info from telco Salt Typhoon probes
ToolShell: An all-you-can-eat buffet for threat actors

ESET Research has been monitoring attacks involving the recently discovered ToolShell zero-day vulnerabilities

Rogue CAPTCHAs: Look out for phony verification pages spreading malware

Before rushing to prove that you’re not a robot, be wary of deceptive human verification pages as an increasingly popular vector for delivering malware

Freelance dev shop Toptal caught serving malware after GitHub account break-in
Microsoft admits it ‘cannot guarantee’ data sovereignty

Several security issues were fixed in OpenJDK 24.

Several security issues were fixed in OpenJDK 21.

Advisor to Brit tech contractors Qdos confirms client data leak
What public cloud gets wrong with AI
How to use Dapper Plus in .NET Core
What you can do now with Python 3.14 RC1

* bsc#1225889 * bsc#1245542 Cross-References: * CVE-2024-1298

* bsc#1229122 * bsc#1241865 Cross-References: * CVE-2025-22872

Not ready for prime time: Agentic IDEs need maturity before enterprise rollout
DNS security is important but DNSSEC may be a failed experiment
Supply chain attack compromises NPM packages to spread backdoor malware
Laptop farmer behind $17M North Korean IT worker scam locked up for 8.5 years
Google Labs introduces Opal for developing AI mini apps
Euro healthcare giant AMEOS Group shuts down IT systems after mystery attack

https://security-tracker.debian.org/tracker/DSA-5964-1

Subliminal learning: When AI models learn what you didn’t teach them
No login? No problem: Cisco ISE flaw gave root access before fix arrived, say researchers
So much for watermarks: UnMarker tool nukes AI provenance tags
Microsoft: SharePoint attacks now officially include ransomware infections
Coyote malware abuses Microsoft’s UI Automation to hunt banking creds
The EFF is 35, but the battle to defend internet freedom is far from over
Compromised Amazon Q extension told AI to delete everything – and it shipped
Eau no! Dior tells customers their data was swiped in cyber snafu
Hacker inserts destructive code in Amazon Q as update goes live
Not pretty, not Windows-only: npm phishing attack laces popular packages with malware
Free decryptor for victims of Phobos ransomware released
Mem0: An open-source memory layer for LLM applications and AI agents
Microsoft’s action-focused small language model Mu

* bsc#1234854 * bsc#1234892 * bsc#1235005 * bsc#1235921 * bsc#1238912

Several security issues were fixed in the Linux kernel.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Updated to latest upstream (141.0)

MCP C# SDK updated to support latest Model Context Protocol spec

https://security-tracker.debian.org/tracker/DSA-5965-1

Smashing Security podcast #427: When 2G attacks, and a romantic road trip goes wrong
XMLUI builds React-based UIs with simple markup
IRL Com recruits teens for real-life stabbings, shootings, FBI warns

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Nothing to see here: Brave browser blocks privacy-busting Microsoft Recall
Microsoft SharePoint victim count hits 400+ orgs in ongoing attacks
Why is your data worth so much? | Unlocked 403 cybersecurity podcast (S2E4)

Behind every free online service, there’s a price being paid. Learn why your digital footprint is so valuable, and why you might be the product.

VMware prevents some perpetual license holders from downloading patches
UK to ban public sector from paying ransomware demands
Three questions you should always be able to answer about your security environment
$380M lawsuit claims intruder got Clorox’s passwords from Cognizant simply by asking
Copilot Vision on Windows 11 sends data to Microsoft servers

* bsc#1244403 * bsc#1244404 * bsc#1244407 Cross-References:

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of sandbox restrictions.

* bsc#1244644 * bsc#1246112 Cross-References: * CVE-2025-27465

* bsc#1243648 Cross-References: * CVE-2024-56558

China warns citizens to beware backdoored devices, on land and under the sea
Funding for program to stop next Stuxnet from hitting US expired Sunday
AWS imposes caps on Kiro usage, introduces waitlist for new users
Arch Linux users told to purge Firefox forks after AUR malware scare
Surprise, surprise: Chinese spies, IP stealers, other miscreants attacking Microsoft SharePoint servers
Silicon Valley engineer admits theft of US missile tech secrets
Java Applet API removal slated for JDK 26
Humans can be tracked with unique ‘fingerprint’ based on how their bodies block Wi-Fi signals
Microsoft patches critical SharePoint 2016 zero-days amid active exploits
The AI Fix #60: Elon’s AI girlfriend, the arsonist red panda, and the AI that will kill you

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

UK to ban ransomware payments by public sector organizations
Open source’s superior security is a matter of eyeballs: Be kind to the brains behind them
A pragmatic approach to enterprise AI
Artificial general intelligence is an artificial general illusion
AI coding at the command line with Gemini CLI
Nuxt 4.0 improves project organization, data fetching, TypeScript support
Dell scoffs at breach, says miscreants only stole ‘fake data’
Another massive security snafu hits Microsoft, but don’t expect it to stick

Summer is flying by and before you know it, you’ll be buying backpacks and taking first-day-of-school photos. Back-to-school season brings new classes and friends, but it also brings new digital dangers. By the time you’ve dropped your kids off for their first day of class, chances are they’ve already been exposed to their first cyberthreat […]

Several security issues were fixed in Drupal.

Several security issues were fixed in the Linux kernel.

CHAOS RAT in AUR: When Trust in Open-Source Goes Too Far

* bsc#1194400 * bsc#1212493 * bsc#1219964 * bsc#1222539 * bsc#1229008

* bsc#1241865 Cross-References: * CVE-2025-22872

Four new Android spyware samples linked to Iran’s intel agency
Google launches TPU monitoring library to boost AI infrastructure efficiency
Europol targets Kremlin-backed cybercrime gang NoName057(16)
9 AI development skills tech companies want
How CodeRabbit brings AI to code reviews
Why front-end development will persist