Menu

Monthly Archives: August 2025

Supply-chain dependencies: Check your resilience blind spot

Does your business truly understand its dependencies, and how to mitigate the risks posed by an attack on them?

How the always-on generation can level up its cybersecurity game

Digital natives are comfortable with technology, but may be more exposed to online scams and other threats than they think

Crooks can’t let go: Active attacks target Office vuln patched 8 years ago
The MedusaLocker ransomware gang is hiring penetration testers
The AI Fix #63: GPT-5 is the best AI ever, and Jim Acosta interviews a murdered teenager’s avatar
US reveals it seized $1 million worth of Bitcoin from Russian BlackSuit ransomware gang

* bsc#1243747 Cross-References: * CVE-2025-48057

* bsc#1246397 Cross-References: * CVE-2025-48924

* bsc#1085999 * bsc#1246397 Cross-References: * CVE-2025-48924

* bsc#1247249 Cross-References: * CVE-2025-8194

UK expands police facial recognition rollout with 10 new vans heading to a town near you
Claude Sonnet 4 upgrade enables full codebase processing in a single request

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Marc Andreessen wades into the UK’s Online Safety Act furor
Microsoft wares may be UK public sector’s only viable option
Secure chat darling Matrix admits pair of ‘high severity’ protocol flaws need painful fixes
Hands-on with Svelte: Build-time compilation in a reactive framework
Five kinds of static code coupling
Ransomware crew spills Saint Paul’s 43GB of secrets after city refuses to cough up cash
Crypto-crasher Do Kwon admits guilt over failed not-so-stablecoin that erased $41 billion
National Security & AI at DEFCON 2025: Where Code Meets Crisis
Microsoft’s Patch Tuesday baker’s dozen: 12 critical bugs plus a SharePoint RCE
Rubrik unveils ‘undo button’ for AI agent mistakes
Manpower franchise discloses data theft after RansomHub posts alleged stolen data
Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability

ESET Research discovered a zero-day vulnerability in WinRAR being exploited in the wild in the guise of job application documents; the weaponized archives exploited a path traversal flaw to compromise their targets

Major outage at Pennsylvania Attorney General’s Office blamed on ‘cyber incident’
BlackSuit ransomware crew loses servers, domains, and $1m in global shakedown
Devops, SRE and platform engineering: What’s the difference?

An update that fixes 9 vulnerabilities is now available.

* bsc#1221107 Cross-References: * CVE-2024-2236

* bsc#1246296 Cross-References: * CVE-2025-7425

Oh, great.Three notorious cybercrime gangs appear to be collaborating
Hyundai: Want cyber-secure car locks? That’ll be £49, please
A developer’s guide to code generation
The rise of AI model-as-a-service ecosystems

* bsc#1219386 Cross-References: * CVE-2023-5992

The White House could end UK’s decade-long fight to bust encryption
Poisoned telemetry can turn AIOps into AI Oops, researchers show
Rust 1.89 underscores arguments to const generics

https://security-tracker.debian.org/tracker/DSA-5973-1

https://security-tracker.debian.org/tracker/DSA-5972-1

Russia’s RomCom among those exploiting a WinRAR 0-day in highly-targeted attacks
WinRAR zero-day exploited in espionage attacks against high-value targets

The attacks used spearphishing campaigns to target financial, manufacturing, defense, and logistics companies in Europe and Canada, ESET research finds

US scrambles to recoup $1M+ nicked by NORKs
Red teams are safe from robots for now, as AI makes better shield than spear
Wikimedia Foundation loses first court battle to swerve Online Safety Act regulation
Intel chief Lip-Bu Tan to visit White House after Trump calls for him to step down
Deepfake detectors are slowly coming of age, at a time of dire need
UK retail giant M&S restores Click & Collect months after cyber attack, some services still down
Your CV is not fit for the 21st century – time to get it up to scratch
The advantages of stack-based internal developer platforms
Multi-agent AI workflows: The next evolution of AI coding
Who does the unsexy but essential work for open source?

* bsc#1246318 * bsc#1246388 Cross-References: * CVE-2025-52520

* bsc#1233791 * bsc#1233834 Cross-References: * CVE-2024-22117

* bsc#1247519 * bsc#1247520 * bsc#1247522 Cross-References:

Trend Micro offers weak workaround for already-exploited critical vuln in management console
Black Hat USA 2025: Is a high cyber insurance premium about your risk, or your insurer’s?

A sky-high premium may not always reflect your company’s security posture

Android adware: What is it, and how do I get it off my device?

Is your phone suddenly flooded with aggressive ads, slowing down performance or leading to unusual app behavior? Here’s what to do.

DEF CON hackers plug security holes in US water systems amid tsunami of threats
The inside story of the Telemessage saga, and how you can view the data

update to xen-4.19.3 includes patches for x86: Incorrect stubs exception handling for flags recovery [XSA-470, CVE-2025-27465] x86: Transitive Scheduler Attacks [XSA-471, CVE-2024-36350,

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

New release of Incus. Release information: https://github.com/lxc/incus/releases/tag/v6.15.0

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

What is a CSRF Vulnerability?
Chinese biz using AI to hit US politicians, influencers with propaganda
Black Hat USA 2025: Policy compliance and the myth of the silver bullet

Who’s to blame when the AI tool managing a company’s compliance status gets it wrong?

Black Hat USA 2025: Does successful cybersecurity today increase cyber-risk tomorrow?

Success in cybersecurity is when nothing happens, plus other standout themes from two of the event’s keynotes

Star leaky app of the week: StarDict
Ex-White House cyber, counter-terrorism guru: Microsoft considers security an annoyance, not a necessity

* bsc#1246090 Affected Products: * openSUSE Leap 15.4

* bsc#1245573 Cross-References: * CVE-2025-6297

* bsc#1244925 Cross-References: * CVE-2025-50181

Infosec hounds spot prompt injection vuln in Google Gemini apps
Hashcat 7.0.0: Redefining Password Recovery & Security on Linux
Critical NestJS Vulnerability Exposes Developers to RCE Risk
How to Build a Ransomware Kill Chain Strategy for Linux Security
UK secretly allows facial recognition scans of passport, immigration databases
UK proxy traffic surges as users consider VPN alternatives amid Online Safety Act
TeaOnHer copies everything from Tea – including the data breaches
Should public clouds enforce government policies?
Prohibition never works, but that didn’t stop the UK’s Online Safety Act