Menu

Monthly Archives: September 2025

Fake North Korean IT workers sneaking into healthcare, finance, and AI
Tile trackers are a stalker’s dream, say Georgia Tech researchers
Google bolts AI into Drive to catch ransomware, but crooks not shaking yet
From fake lovers to sextortionists: 260 scammers arrested in Africa
Safe C++ proposal for memory safety flames out
Warnings about Cisco vulns under active exploit are falling on deaf ears
TMI: How cloud collaboration suites drive oversharing and unmanaged access
The AI Fix #70: AI behaves… until it knows you’re watching
Supply Chain Attacks Are Spreading: NPM, PyPI, and Docker Hub All Hit in 2025
Dutch teens recruited on Telegram, accused of Russia-backed hacking plot
Britain’s policing minister punts facial recog nationwide
£5.5B Bitcoin fraudster pleads guilty after years on the run
Model Context Protocol (MCP) certification: When will it arrive and what will it mean?
‘Blame the intern’ is not an agentic AI security strategy
When personal ambitions undermine enterprise security
Greg Kroah-Hartman explains the Cyber Resilience Act for open source developers

Multiple vulnerabilities were fixed in tiff, a library and tools providing support for the Tag Image File Format (TIFF). CVE-2024-13978

31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815

31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815

31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815

Feds cut funding to program that shared cyber threat info with local governments

A vulnerability has been discovered in python-internetarchive, a Python library and command-line interface for searching, downloading and uploading content to the Internet Archive.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

JavaFX 25 previews JavaFX controls in title bars
One line of malicious npm code led to massive Postmark email heist
Asahi runs dry as online attackers take down Japanese brewer
UK may already be at war with Russia, ex-MI5 head suggests

USN-7280-2 introduced a regression in Python 2.7

USN-7015-4 introduced a regression in Python 2.7

* bsc#1247674 Cross-References: * CVE-2025-54571

An update that solves one vulnerability can now be installed.

* bsc#1247674 Cross-References: * CVE-2025-54571

* bsc#1236658 * bsc#1236746 * bsc#1237208 * bsc#1237308 * bsc#1237585

UK minister suggests government could ditch ‘dangerous’ Elon Musk’s X
Harrods blames its supplier after crims steal 430k customers’ data in fresh attack
Jaguar Land Rover gets £1.5B government jump-start after cyber breakdown
Digital ID, same place, different time: In this timeline, the result might surprise us
How MCP is making AI agents actually do things in the real world
A brief history of AI
Smoothing out AI’s rough edges
Submarine cable security is all at sea, and UK govt ‘too timid’ to act, says report
When AI is trained for treachery, it becomes the perfect agent
Trump demands Microsoft fire its head of global affairs
Dutch teen duo arrested over alleged ‘Wi-Fi sniffing’ for Russia
Datacenter fire takes 647 South Korean government services offline

An update that solves 2 vulnerabilities can now be installed.

An update that solves 18 vulnerabilities can now be installed.

An update that solves 7 vulnerabilities can now be installed.

Three security issues were discovered in the Squid proxy caching server, which could result in the execution of arbitrary code, information disclosure or denial of service.

It was discovered that the symlink validation in node-tar-fs, a Node.js module that provides filesystem-like access to tar files, could be bypassed.

Firefox 140.3.1 has been released, which fixes connection errors with some sites; if HTTP/3 connections failed, the fallback is now handled more gracefully.

https://security-tracker.debian.org/tracker/DSA-6014-1

https://security-tracker.debian.org/tracker/DSA-6013-1

https://security-tracker.debian.org/tracker/DSA-6003-2

https://security-tracker.debian.org/tracker/DSA-6012-1

Hunt for RedNovember: Beijing hacked critical orgs in year-long snooping campaign
Alibaba unveils $53B global AI plan – but it will need GPUs to back it up

Update to 140.0.7339.207 * CVE-2025-10890: Side-channel information leakage in V8 * CVE-2025-10891: Integer overflow in V8 * CVE-2025-10892: Integer overflow in V8

4.0.6.3221

Update to 140.0.7339.207 * CVE-2025-10890: Side-channel information leakage in V8 * CVE-2025-10891: Integer overflow in V8 * CVE-2025-10892: Integer overflow in V8

From answer engine to infrastructure: Perplexity launches Search API for developers

Eugene Medvedev discovered that nncp, a package facilitating secure store-and-forward file and mail exchange, was susceptible to path traversal with the freq and file commands.

An update that fixes one vulnerability is now available.

Cyber threat-sharing law set to shut down, along with US government

* bsc#1234896 * bsc#1244824 * bsc#1245970 * bsc#1246473 * bsc#1246911

Microsoft spots fresh XCSSET malware strain hiding in Apple dev projects
Salesforce facing multiple lawsuits after Salesloft breach
‘An attacker’s playground:’ Crims exploit GoAnywhere perfect-10 bug
LockBit’s new variant is ‘most dangerous yet,’ hitting Windows, Linux and VMware ESXi
Prompt injection – and a $5 domain – trick Salesforce Agentforce into leaking sales

* bsc#1247901 * bsc#1247902 * bsc#1247904 Cross-References:

* bsc#1246974 * bsc#1249375 Cross-References: * CVE-2025-8114

An update that solves two vulnerabilities can now be installed.

* bsc#1246974 * bsc#1249375 Cross-References: * CVE-2025-8114

An update that solves three vulnerabilities can now be installed.

* bsc#1246001 * bsc#1246356 * bsc#1247499 Cross-References:

Volvo North America confirms staff data stolen following ransomware attack on IT supplier
UK and US security agencies order urgent fixes as Cisco firewall bugs exploited in wild
UK to roll out mandatory digital ID for right to work by 2029
What is infrastructure as code? Automating your infrastructure builds
Python and Poetry: 4 tools for keeping Python simple
SaaS: The quiet power behind cloud computing
Brits warned as illegal robo-callers with offshored call centers fined half a million
Microsoft Marketplace opens for AI apps, agents
North Korea’s Lazarus Group shares its malware with IT work scammers
GitHub Copilot-backed app modernization available for Java, .NET
Callous crims break into preschool network, publish toddlers’ data
Zero-day deja vu as another Cisco IOS bug comes under attack
Top Linux Malware Scanners for Detection and System Hardening

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

EU starting registration of fingerprints and faces for short-stay foreigners

Several security issues were fixed in the Linux kernel.

Two vulnerabilities were found in libxslt, an XSLT 1.0 processing library, which could lead to to denial of service or information disclosure.

Empty shelves, empty coffers: Co-op pegs cyber hit at £80m
Introduction to Java records: Simplified data-centric programming in Java
Spec-driven AI coding with GitHub’s Spec Kit
The best new features in Postgres 18