Menu

Monthly Archives: July 2025

Why LLMs demand a new approach to authorization
UK’s NCA disputes claim it’s nearly three times less efficient than the FBI

Several security issues were fixed in Nix.

Iran seeks at least three cloud providers to power its government

Contains fixes for regressions introduced during CVE bugfix update (3007.4).

Update to 2.32.4. Fixes CVE-2024-47081.

Update to 3.5.29, fixes CVE-2025-53367.

Nvidia warns its GPUs – even Blackwells – need protection against Rowhammer attacks
You have a fake North Korean IT worker problem – here’s how to stop it

This updates gnutls to the latest upstream release. Notable changes are: PKCS#11 cryptographic provider support Support for kTLS rekeying with kernel 6.14+ Support for the almost standardized ML-DSA private key formats This also fixes 4 CVEs (CVE-2025-32989, CVE-2025-6395, CVE-2025-32988, and

Update to chromium 138.0.7204.92

Update to version 4.34.0

PHP version 8.4.10 (03 Jul 2025) BcMath: Fixed bug GH-18641 (Accessing a BcMathNumber property by ref crashes). (nielsdos) Core:

Fixes CVE-2025-40909 – Clone dirhandles without fchdir

Fixes CVE-2025-40909 – Clone dirhandles without fchdir

Update to 20250708: Drop incorrect nvidia ghost entries xe: Add fan_control v203.0.0.0 for BMG Update AMD cpu microcode amdgpu: Add DCN 3.6/PSP 14.0.5/SDMA 6.1.3/GC 11.5.3

Fix CVE-2024-25176

Visual Studio Code bolsters Copilot Chat, MCP support

Multiple vulnerabilities have been fixed in the email, calendar and contacts client Thunderbird. CVE-2025-5986

* bsc#1233012 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059

Why Apache 2.4.64 Is a Must for Securing Linux Web Servers
CVSS 10 RCE in Wing FTP exploited within 24 hours, security researchers warn
TypeScript 5.9 supports deferred module evaluation
Russian basketball player arrested in ransomware case despite being “useless with computers”
AI coding tools can slow down seasoned developers by 19%
Paddy Power and BetFair have suffered a data breach

Several security issues were fixed in resteasy, resteasy3.0.

UK Online Safety Act ‘not up to scratch’ on misinformation, warn MPs
Python-powered AI agents are here
Sovereign clouds in the age of cost control and AI
Security company hired a used car salesman to build a website, and it didn’t end well
French cops cuff Russian pro basketball player on ransomware charges
Chinese censorship-busters claim Tencent is trying to kill its WeChat archive

Update to 128.12.0 https://www.thunderbird.net/en-US/thunderbird/128.12.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-55/

Lovestruck US Air Force worker admits leaking secrets on dating app

USN-7626-1 introduced a regression in Git

Now everybody but Citrix agrees that CitrixBleed 2 is under exploit
Ada, other older languages vie for top spots in Tiobe language index

* bsc#1245309 * bsc#1245310 * bsc#1245311 * bsc#1245314

Ex-ASML engineer who stole chip tech for Russia gets three years in Dutch prison
Russia, hotbed of cybercrime, says nyet to ethical hacking bill
AiLock ransomware: What you need to know

* bsc#1065729 * bsc#1156395 * bsc#1193629 * bsc#1194869 * bsc#1198410

* bsc#1244081 Cross-References: * CVE-2025-5601

* bsc#1244081 Cross-References: * CVE-2025-5601

* bsc#1243902 Cross-References: * CVE-2025-40908

How AI is quietly saving enterprises thousands on Azure costs
NCA arrests four in connection with UK retail ransomware attacks
Now available: Red Hat Enterprise Linux Security Select Add-On
Sovereign-ish: Google Cloud keeps AI data in UK, but not the support
How to inline methods using MethodImplAttribute in C#
NLWeb: Tapping MCP for natural language web search
Review: How Passwork 7 helps tame business passwords
At last, a use case for AI agents with sky-high ROI: Stealing crypto
Google releases Gemma 3n models for on-device AI
Smashing Security podcast #425: Call of Duty: From pew-pew to pwned
How to trick ChatGPT into revealing Windows keys? I give up
US sanctions alleged North Korean IT sweatshop leader
AMD warns of new Meltdown, Spectre-like bugs affecting CPUs
As Texas floods, so does the internet – with dangerous lies
Breaking Down BERT Ransomware: Lessons for Linux & ESXi Defenders

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Oracle Database@AWS goes GA: Exadata and Autonomous DB now live in the US
Get started with Google Agent Development Kit
Artificial intelligence is a commodity, but understanding is a superpower
The ultimate software engineering abstraction
Clarifai AI Runners connect local models to cloud

https://security-tracker.debian.org/tracker/DSA-5960-1

ECMAScript 2025 JavaScript standard approved

Several security issues were fixed in libssh.

InfoWorld Technology of the Year Awards 2025 nominations now open
The cloud-native imperative for effective cyber resilience
The AI Fix #58: An AI runs a shop into the ground, and AI’s obsession with the number 27
SUSE launching region-locked support for the sovereignty-conscious
Metadata: Your ticket to the AI party
Exploring Parrot OS 6.4: A Vital Release for Security-Centric Workflows
Suspected Chinese cybersnoop grounded in Italy after US tipoff
Microsoft brings OpenAI-powered Deep Research to Azure AI Foundry agents

USN-7010-1 introduced a regression in DCMTK

Nvidia doubles down on GPUs as a service
What you absolutely cannot vibe code right now
How Deutsche Telekom designed AI agents for scale

Sekou Diakite from HPE discovered a mistake with permission handling for Coordinators within the accounting system of Slurm Workload Manager, a cluster resource management and job scheduling system, that it could allow a Coordinator to promote a user to Administrator.

* bsc#1227270 * bsc#1227271 * bsc#1227353 * bsc#1228097 * bsc#1233165

Is your password ecosystem ready for the regulators?
Suspected Scattered Spider domains target everyone from manufacturers to Chipotle

Several security issues were fixed in jQuery.

https://security-tracker.debian.org/tracker/DSA-5961-1

Deno 2.4 restores JavaScript bundling subcommand