Menu

Monthly Archives: August 2025

What Is a SQLi Vulnerability?
Google rolls out AI coding tool for GitHub repos
Why blow up satellites when you can just hack them?

https://security-tracker.debian.org/tracker/DSA-5971-1

German security researchers say ‘Windows Hell No’ to Microsoft biometrics for biz
Microsoft, CISA warn yet another Exchange server bug can lead to ‘total domain compromise’
Black Hat’s network ops center brings rivals together for a common cause
CISA releases malware analysis for Sharepoint Server attack
Ukraine claims to have hacked secrets from Russia’s newest nuclear submarine
KLM, Air France latest major organizations looted for customer data
Meta training AI on social media posts? Only 7% in Europe think it’s OK

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

Introducing OpenShift Service Mesh 3.1

Several security issues were fixed in cifs-utils.

Anthropic targets DevSecOps with Claude Code update as AI rivals gear up
The Claude party is almost over
Getting started with A2A in .NET
Amnesty slams Elon Musk’s X for ‘central role’ in fueling 2024 UK riots

* bsc#1221107 * bsc#1246934 Cross-References: * CVE-2024-2236

Could agentic AI save us from the cybercrisis?
Microsoft researchers bullish on AI security agent even though it let 74% of malware slip through
Google updates agents in BigQuery to further automate analytics tasks
Google says the group behind last year’s Snowflake attack slurped data from one of its Salesforce instances
ESET Threat Report H1 2025: ClickFix, infostealer disruptions, and ransomware deathmatch

Threat actors are embracing ClickFix, ransomware gangs are turning on each other – toppling even the leaders – and law enforcement is disrupting one infostealer after another

Ransomware plunges insurance company into bankruptcy

Multiple vulnerabilities have been discovered in Composer, the worst of which can lead to arbitrary code execution.

A vulnerability has been discovered in Spreadsheet-ParseExcel, which can lead to arbitrary code execution.

A vulnerability has been discovered in NSS, which can lead to the recovery of private data.

A vulnerability has been discovered in FontForge, which can lead to arbitrary code execution.

TypeScript 5.9 arrives with deferred module evaluation, expandable hovers
Google Spanner gets a columnar engine to unite OLTP and OLAP workloads
Hospital fined after patient data found in street food wrappers

Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which can lead to execution of arbitrary code.

Multiple vulnerabilities have been discovered in PAM, the worst of which could lead to privilege escalation.

Roo Code review: Autonomous AI-powered development in the IDE
How to code sign binaries on Windows
How to measure coupled code
Vibe coding tool Cursor’s MCP implementation allows persistent code execution
JetBrains previews no-code app builder
Patch now: Millions of Dell PCs with Broadcom chips vulnerable to attack
Study finds humans not completely useless at malware detection
Chained bugs in Nvidia’s Triton Inference Server lead to full system compromise
The AI Fix #62: AI robots can now pass CAPTCHAs, and punch you in the face
What Is a RCE Vulnerability?

* bsc#1245773 Cross-References: * CVE-2025-53367

* bsc#1247249 Cross-References: * CVE-2025-8194

* bsc#1247249 Cross-References: * CVE-2025-8194

Hacker summer camp: What to expect from BSides, Black Hat, and DEF CON
Why benchmarks are key to AI progress
The problem with AI agent-to-agent communication protocols
Python popularity boosted by AI coding assistants – Tiobe
Antivirus vendors fail to spot persistent, nasty, stealthy Linux backdoor
SonicWall investigates ‘cyber incidents,’ including ransomware targeting suspected 0-day
Python-powered malware snags hundreds of credit cards, 200K passwords, and 4M cookies
Mozilla flags phishing wave aimed at hijacking trusted Firefox add-ons
German phone repair biz collapses following 2023 ransomware attack
When hyperscalers can’t safeguard one nation’s data from another, dark clouds are ahead
Millions of age checks performed as UK Online Safey Act gets rolling
Microsegmentation for developers
9 habits of the highly ineffective vibe coder
Erasing the trust gap in AI-driven development

* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:

* bsc#1228645 * bsc#1235250 * bsc#1245771 * bsc#1245776 * bsc#1245793

* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:

* bsc#1235250 * bsc#1245776 * bsc#1245793 * bsc#1245797

* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:

China’s botched Great Firewall upgrade invites attacks on its censorship infrastructure
Lazarus Group rises again, this time with malware-laden fake FOSS
Silent Push CEO on cybercrime takedowns: ‘It’s an ongoing cat-and-mouse game’

Update to 138.0.7204.183 * CVE-2025-8292: Use after free in Media Stream

This update fixes CVE-2025-7345 and CVE-2025-6199.

This update fixes these CVEs: CVE-2025-32364 CVE-2025-32365 CVE-2024-56378

reposurgeon: update to 5.3 version

In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. References: – https://bugs.mageia.org/show_bug.cgi?id=34447

Stefan Buehler discovered a flaw in sope, the set of Objective-C frameworks powering SOGo, which may result in denial of service via a specially crafted POST request.

Is your phone spying on you? | Unlocked 403 cybersecurity podcast (S2E5)

Here’s what you need to know about the inner workings of modern spyware and how to stay away from apps that know too much

Why the tech industry needs to stand firm on preserving end-to-end encryption

Restricting end-to-end encryption on a single-country basis would not only be absurdly difficult to enforce, but it would also fail to deter criminal activity

CISA roasts unnamed critical national infrastructure body for shoddy security hygiene

A flaw was found in how GLib¢”s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn¢”t. As a result, data may be written […]

This update fixes these CVEs: CVE-2025-4948 CVE-2025-32908 CVE-2025-32907 CVE-2025-4969

Backports patch to fix non-CVE 2025-8224

What Is An XSS Vulnerability?

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Apache Flink integrates AI for real-time decision-making
OpenAI removes ChatGPT self-doxing option

https://security-tracker.debian.org/tracker/DSA-5970-1

Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks
China says US spies exploited Microsoft Exchange zero-day to steal military info
This month in security with Tony Anscombe – July 2025 edition

Here’s a look at cybersecurity stories that moved the needle, raised the alarm, or offered vital lessons in July 2025

Florida prison email blunder exposes visitor contact info to inmates

* bsc#1243855 Cross-References: * CVE-2024-12224