Menu

Monthly Archives: August 2025

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

* bsc#1248119 * bsc#1248120 * bsc#1248122 Cross-References:

* bsc#1248119 * bsc#1248120 * bsc#1248122 Cross-References:

Alleged mastermind behind K-Pop celebrity stock heist extradited to South Korea
Farmers Insurance harvests bad news: 1.1M customers snared in data breach
A wake-up call for identity security in devops
How to avoid the risks of rapidly deploying AI agents
How does AI affect cloud attack vectors?
Malware-ridden apps made it into Google’s Play Store, scored 19 million downloads

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5986-1

Visual Studio Code update auto-starts MCP servers

Americans aged 60 and older lost $4.8 billion in 2024 to scammers, according to a report released by the FBI. These figures represent real people, real families, and life-changing financial devastation. The impact extends beyond just the numbers. The average loss among people over the age of 60 was $83,000, more than four times the […]

Databricks buys Tecton to give context to AI agents

* bsc#1232234 * bsc#1246221 Cross-References: * CVE-2024-10041

* bsc#1232234 * bsc#1246221 Cross-References: * CVE-2024-10041

* bsc#1234018 * bsc#1234019 * bsc#1234020 * bsc#1245313 * bsc#1246790

* bsc#1239547 * bsc#1239863 * bsc#1239864 * bsc#1247562 * bsc#1247563

Securing AI workloads in Azure: A zero-trust architecture for MLOps
What alternative clouds are good for
Enterprise essentials for generative AI
Australian university used Wi-Fi location data to identify student protestors
AWS, Cloudflare, Digital Ocean, and Google helped Feds investigate alleged Rapper Bot DDoS perp

https://security-tracker.debian.org/tracker/DSA-5985-1

Bug bounties: The good, the bad, and the frankly ridiculous ways to do it

Security fixes Bumped the minimum github.com/go-viper/mapstructure/v2 version to 2.3.0 for GHSA-fv92-fjc5-jj9h or GO-2025-3787 Bumped the minimum github.com/NVIDIA/nvidia-container-toolkit version to 1.17.8 for CVE-2025-23266 and CVE-2025-23267

How RingReaper Linux Malware Exploits io_uring to Evade EDR Systems

https://security-tracker.debian.org/tracker/DSA-5984-1

“What happens online stays online” and other cyberbullying myths, debunked

Separating truth from fiction is the first step towards making better parenting decisions. Let’s puncture some of the most common misconceptions about online harassment.

The need for speed: Why organizations are turning to rapid, trustworthy MDR

How top-tier managed detection and response (MDR) can help organizations stay ahead of increasingly agile and determined adversaries

Blue Locker ransomware hits critical infrastructure – is your organisation ready?

Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix

Update to 1.67.0 Update to 1.66.0

Update to release v1.33.4 Resolves: rhbz#2388412 Fixes CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix

Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Microsoft adds MCP support to Visual Studio to boost development of agentic applications
Short circuit: Electronics supplier to tech giants suffers ransomware shutdown
Kidney dialysis giant DaVita tells 2.4M people they were snared in ransomware data theft nightmare
Criminal background checker APCS faces data breach
Fake CAPTCHA tests trick users into running malware
Europol says Telegram post about 50,000 Qilin ransomware award is fake
Interpol bags 1,209 suspects, $97M in cybercrime operation focused on Africa

* bsc#1248006 Cross-References: * CVE-2025-55159

Several security issues were fixed in PHP.

Generative AI dos, don’ts, and ‘undos’
From cloud migration to cloud optimization

* bsc#1248006 Cross-References: * CVE-2025-55159

Anthropic adds Claude Code to its Claude enterprise plans

Several security issues were fixed in Python.

Update to version 0.4.11. This version includes a fix for CVE-2025-55159, but there are zero packages in Fedora or EPEL that use the affected API, so no rebuilds are necessary.

Update to v1.136.0 Update to 1.135.2 Update to 1.135.0

Developer jailed for taking down employer’s network with kill switch malware

https://security-tracker.debian.org/tracker/DSA-5983-1

Anthropic scanning Claude chats for queries about DIY nukes for some reason
Microsoft reportedly cuts China’s early access to bug disclosures, PoC exploit code
‘Impersonation as a service’ the next big thing in cybercrime
Honey, I shrunk the image and now I’m pwned
Congressman proposes bringing back letters of marque for cyber privateers
Orange Belgium mega-breach exposes 850K customers to serious fraud
US cops wrap up RapperBot, one of world’s biggest DDoS-for-hire rackets
Apple rushes out fix for active zero-day in iOS and macOS
Colt changes tune, admits data theft as Warlock gang begins auction
Google yet to take down ‘screenshot-grabbing’ Chrome VPN extension

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or bypass of the same-origin policy.

AI crawlers and fetchers are blowing up websites, with Meta and OpenAI the worst offenders

poppler could be made to denial of service if it received a specially crafted PDF file.

How to upload files using minimal APIs in ASP.NET Core
The shift from AI code generation to true development partnership
Up and running with Azure Linux 3.0

* bsc#1245218 * bsc#1247350 * bsc#1247351 Cross-References:

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

GitHub launches Copilot agents panel on GitHub.com
China cut itself off from the global internet for an hour on Wednesday

https://security-tracker.debian.org/tracker/DSA-5982-1

https://security-tracker.debian.org/tracker/DSA-5981-1

Microsoft stays mum about M365 Copilot on-demand security bypass
Smashing Security podcast #431: How to mine millions without paying the bill
Amazon quietly fixed Q Developer flaws that made AI agent vulnerable to prompt injection, RCE
JRebel Enterprise speeds configuration, code updates for cloud-based Java development
FBI: Russian spies exploiting a 7-year-old Cisco bug to slurp configs from critical infrastructure
Commvault releases patches for two nasty bug chains after exploits proven
‘Limited’ data leak at Aussie telco turns out to be 280K customer details
Warlock ransomware: What you need to know
The AI Fix #64: AI can be vaccinated against evil, and the “Rumble in the Silicon Jungle”

* bsc#1244270 * bsc#1244272 * bsc#1244273 * bsc#1244279 * bsc#1244336

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

Several security issues were fixed in Apache HTTP Server.