Menu

Monthly Archives: August 2025

AWS blames bug for Kiro pricing glitch that drained developer limits

Several security issues were fixed in libxml2.

PyApp: An easy way to package Python apps as executables
Is the generative AI bubble about to burst?
Your code is more strongly coupled than you think

* bsc#1012628 * bsc#1139073 * bsc#1204142 * bsc#1210025 * bsc#1211226

McDonald’s not lovin’ it when hacker exposes nuggets of rotten security

https://security-tracker.debian.org/tracker/DSA-5980-1

.NET 10 Preview 7 adds XAML generator
Don’t want drive-by Ollama attackers snooping on your local chats? Patch now
Like burglars closing a door, Apache ActiveMQ attackers patch critical vuln after breaking in
Investors beware: AI-powered financial scams swamp social media

Can you tell the difference between legitimate marketing and deepfake scam ads? It’s not always as easy as you may think.

Speed cameras knocked out after cyber attack
Casino tech outfit Bragg cops to intrusion but says data jackpot untouched

* bsc#1242666 * bsc#1243428 Cross-References: * CVE-2025-3416

* bsc#1244631 * bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

US spy chief claims UK backed down over Apple backdoor demand
The successes and challenges of AI agents
Retrieval-augmented generation with Nvidia NeMo Retriever
IBM can’t afford an unreliable cloud
More customers asking for Google’s Data Boundary, says Cloud Experience boss
Browser wars are back, predicts Palo Alto, thanks to AI

https://security-tracker.debian.org/tracker/DSA-5979-1

Go language previews performance-boosting garbage collector
Facial recognition works better in the lab than on the street, researchers show
Pot calls kettle black as China dubs US ‘surveillance empire’ over chip tracking
Microsoft’s Nuance coughs up $8.5M to rid itself of MOVEit breach suit
Workday warns of CRM breach after social engineers make off with business contact details
What Is A Virtual Private Network (VPN)?

* bsc#1236217 * bsc#1246118 * bsc#1247719 * bsc#1247720 * jsc#SLE-18320

Google adds VM monitoring to Database Center amid enterprise demand
Introducing Red Hat Technical Account Management Service for Product Security
Boffins say tool can sniff 5G traffic, launch ‘attacks’ without using rogue base stations
Every question you ask, every comment you make, I’ll be recording you
How does the metrics layer enhance the power of advanced analytics?
Why software developers burn out, and how to fix it
Why AI fails at business context, and what to do about it

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1244631 * bsc#1245218 * bsc#1245350 * bsc#1245989 * bsc#1247350

* bsc#1244337 * bsc#1247350 * bsc#1247351 Cross-References:

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

Someone’s poking the bear with infostealers targeting Russian crypto developers

https://security-tracker.debian.org/tracker/DSA-5978-1

P2P payment service Zelle sued for enabling payment fraud hell

Update to upstream 1.4.2, fix CVE-2025-22870

* bsc#1245320 Cross-References: * CVE-2025-6032

* bsc#1245320 Cross-References: * CVE-2025-6032

Election workers fear threats and intimidation without feds’ support in 2026

Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker

Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker

Typhoon-adjacent Chinese crew broke into Taiwanese web host
Cisco’s Secure Firewall Management Center now not-so secure, springs a CVSS 10 RCE hole

An update that fixes 5 vulnerabilities is now available.

Cyberattack on Dutch prosecution service is keeping speed cameras offline
Telco giant Colt suffers attack, takes systems offline
The truth about Python’s AI-powered popularity surge
Can your cloud provider really scale?
LLM chatbots trivial to weaponize for data theft, say boffins
Should UK.gov save money by looking for open source alternatives to Microsoft? You decide

fix CVE-2025-46206 (rhbz#2386395)

fixes CVE-2025-8534: null pointer dereference in tiff2p fixes CVE-2024-13978: null pointer dereference in tiff2pdf

update MANUAL to cover threat related to user HTML iframe

Ransomware crews don’t care about your endpoint security – they’ve already killed it

Several security issues were fixed in AIDE.

* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5975-1

https://security-tracker.debian.org/tracker/DSA-5974-1

Psst: wanna buy a legit FBI email account for $40?
‘MadeYouReset’ HTTP/2 flaw lets attackers DoS servers
Lock down your critical infrastructure, CISA begs admins
BtcTurk suspends operations amid alleged $49M hot wallet heist
Law and water: Russia blamed for US court system break-in and Norwegian dam drama
What Is a Use-After-Free (UAF) Vulnerability?
Italian hotels breached en masse since June, government confirms

Several security issues were fixed in Request Tracker.

Stock in the Channel pulls website amid cyberattack
Monitoring microservices: Best practices for robust systems
Wassette: A bridge between Wasm and MCP

Several security issues were fixed in Sidekiq.

The £9 billion question: To Microsoft or not to Microsoft?

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5977-1

https://security-tracker.debian.org/tracker/DSA-5976-1

Smashing Security podcast #430: Poisoned Calendar invites, ChatGPT, and Bromide
Fortinet discloses critical bug with working exploit code amid surge in brute-force attempts