Menu

Monthly Archives: August 2025

Several security issues were fixed in Open VM Tools.

Update to 139.0.7258.154 CVE-2025-9478: Use after free in ANGLE

CVE-2025-8067 Out-Of-Bounds Read in UDisks Daemon

Update to release v0.27.0 Resolves: rhvz#2388453, rhbz#2384137, rhbz#2384154 Upstream new features and fixes

CVE-2025-8010: Type Confusion in V8 CVE-2025-8011: Type Confusion in V8 CVE-2025-8576: Use after free in Extensions CVE-2025-8578: Use after free in Cast CVE-2025-8579: Inappropriate implementation in Gemini Live in Chrome

Remove prebuild libffts.a library

New udisks2 packages are available for Slackware 15.0 and -current to fix a security issue.

Red Hat Trusted Artifact Signer can now be hosted on RHEL

Update to latest upstream (142.0.1) Updated to new upstream release (142.0)

https://security-tracker.debian.org/tracker/DSA-5992-1

Researcher who found McDonald’s free-food hack turns her attention to Chinese restaurant robots

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1240414 Cross-References: * CVE-2025-31115

* bsc#1238078 * bsc#1243450 * bsc#1244116 Cross-References:

* bsc#1220262 Cross-References: * CVE-2023-50782

* bsc#1244270 * bsc#1244272 * bsc#1244273 * bsc#1244279 * bsc#1244336

Microsoft’s signals shift from OpenAI with launch of first in-house AI models for Copilot
AWS catches Russia’s Cozy Bear clawing at Microsoft credentials
Sweden scrambles after ransomware attack puts sensitive worker data at risk
This month in security with Tony Anscombe – August 2025 edition

From Meta shutting down millions of WhatsApp accounts linked to scam centers all the way to attacks at water facilities in Europe, August 2025 saw no shortage of impactful cybersecurity news

Enterprise password management outfit Passwordstate patches Emergency Access bug

* bsc#1248502 Cross-References: * CVE-2025-8067

* bsc#1248502 Cross-References: * CVE-2025-8067

* bsc#1248502 Cross-References: * CVE-2025-8067

* bsc#1248119 * bsc#1248120 * bsc#1248122 Cross-References:

OpenAI adds MCP and SIP support to gpt-realtime for smarter voice-based agents
UK government dragged for incomplete security reforms after Afghan leak fallout
Evolving Kubernetes for generative AI inference
New tools make Python app distribution easier than ever
Three tips for building agentic AI systems on cloud platforms
The era of cheap AI coding assistants may be over

https://security-tracker.debian.org/tracker/DSA-5991-1

https://security-tracker.debian.org/tracker/DSA-5990-1

FBI cyber cop: Salt Typhoon pwned ‘nearly every American’
JetBrains updates Kotlin-based AI agent development framework

https://security-tracker.debian.org/tracker/DSA-5988-1

https://security-tracker.debian.org/tracker/DSA-5987-1

DHS says it needs $100M worth of counter-drone tech to protect America
Not in my browser! Vivaldi capo doubles down on generative AI ban
Gemini CLI integrates with Zed for AI-powered coding
FBI, Dutch cops seize fake ID marketplace that sold identity docs for $9
How does China keep stealing our stuff, wonders DoD group responsible for keeping foreign agents out
Don’t let “back to school” become “back to (cyber)bullying”

Cyberbullying is a fact of life in our digital-centric society, but there are ways to push back

First known AI-powered ransomware uncovered by ESET Research

The discovery of PromptLock shows how malicious use of AI models could supercharge ransomware and other threats

Wave of npm supply chain attacks exposes thousands of enterprise developer credentials
16 billion credentials exposed: why your business needs a password manager now
SK Telecom walloped with $97M fine after schoolkid security blunders let attackers run riot
TransUnion admits 4.5M affected after third-party support app breached
Thousands of Citrix NetScaler boxes still sitting ducks despite patches
Ransomware crooks knock Swedish municipalities offline for measly sum of $168K
Euro banks block billions in rogue PayPal direct debits after fraud glitch
Law firm email blunder exposes Church of England abuse victim details
Using Cosmos DB in Microsoft Fabric
From Teradata to lakehouse: Lessons from a real-world data platform modernization
8 vendors bringing AI to devsecops and application security

* bsc#1246472 Cross-References: * CVE-2025-7519

* bsc#1244270 * bsc#1244272 * bsc#1244273 * bsc#1244279 * bsc#1244336

* bsc#1246597 Cross-References: * CVE-2025-6965

* bsc#1245573 Cross-References: * CVE-2025-6297

* bsc#1246232 * bsc#1246233 * bsc#1246267 * bsc#1246299

* bsc#1244554 * bsc#1244555 * bsc#1244557 * bsc#1244580 * bsc#1244700

If you thought China’s Salt Typhoon was booted off critical networks, think again
What Is a Privilege Escalation Vulnerability?

https://security-tracker.debian.org/tracker/DSA-5989-1

ChatGPT hates LA Chargers fans
Smashing Security podcast #432: Oops! I auto-filled my password into a cookie banner
Sting nails two front firms in Nork IT worker scam
Crims laud Claude to plant ransomware and fake IT expertise
Putin on the code: DoD reportedly relies on utility written by Russia-based Yandex dev
Nx NPM packages poisoned in AI-assisted supply chain attack
The intruder is in the house: Storm-0501 attacked Azure, stole data, demanded payment via Teams
Cephalus ransomware: What you need to know
Salesforce data missing? It might be due to Salesloft breach, Google says
Linux Rootkits: Detecting, Preventing, and Surviving an Attack

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Who are you again? Infosec experiencing ‘Identity crisis’ amid rising login attacks
Hands-on with Solid: Reactive programming with signals
The discipline of great code
BGP’s security problems are notorious. Attempts to fix that are a work in progress
Google issued ‘State-backed attack in progress’ warnings after spotting web hijack scheme
MariaDB buys back the company it sold two years ago

fix CVE-2025-9165: memory leak in tiffcmp (rhbz#2389608)

Update to upstream version 0.2.8 Update idna dependency to a version not affected by CVE-2024-12224

fix CVE-2025-8534: null pointer dereference in tiff2ps (rhbz#2386494) fix CVE-2024-13978: null pointer dereference in tiff2pdf (rhbz#2386201)

Microsoft unveils Proxy 4 library for polymorphic coding in C++
First AI-powered ransomware spotted, but it’s not active – yet
Critical Docker Desktop flaw allows container escape
Azure apparatchik shows custom silicon keeping everything locked down
DOGE accused of duplicating critical Social Security database on unsecured cloud
ZipLine attack uses ‘Contact Us’ forms, White House butler pic to invade sensitive industries
Citrix patches trio of NetScaler bugs – after attackers beat them to it
The AI Fix #65: Excel Copilot will wreck your data, and can AI fix social media?
Yemen Cyber Army hacker jailed after stealing millions of people’s data
Crypto thief earns additional prison time for assaulting witness
Broadcom launches VMware Tanzu Data Intelligence and Tanzu Platform 10.3 to drive agentic AI
Broadcom and Canonical expand partnership, promising accelerated innovation