Menu

Monthly Archives: September 2025

Check your own databases before asking to see our passport photos, Home Office tells UK cops
Three in four European companies are hooked on US tech
Google releases MCP server to Data Commons public data sets

https://security-tracker.debian.org/tracker/DSA-6011-1

https://security-tracker.debian.org/tracker/DSA-6010-1

https://security-tracker.debian.org/tracker/DSA-5979-2

Smashing Security podcast #436: The €600,000 gold heist, powered by ransomware

Parents across America face a growing wave of sophisticated online fraud designed to exploit their deepest fears and protective instincts. Americans reported losing more than $12.5 billion to fraud in 2024, representing a 25% increase over the prior year, according to new Federal Trade Commission data. Parents represent a particularly vulnerable target because scammers understand […]

New string of phishing attacks targets Python developers
SonicWall releases rootkit-busting firmware update following wave of attacks
INC ransomware: what you need to know
Google warns China-linked spies lurking in ‘numerous’ enterprises since March
The AI Fix #69: How we really use ChatGPT, and will AI agents crash the economy?

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

UK agency makes arrest in airport cyberattack investigation

* bsc#1246001 * bsc#1246356 * bsc#1247499 Cross-References:

* bsc#1231862 * bsc#1246001 * bsc#1246356 * bsc#1247499

* bsc#1246001 * bsc#1247499 Cross-References: * CVE-2025-38181

Cybercriminals cash out with casino giant’s employee data

Several security issues were fixed in the Linux kernel.

Disk Encryption: An Authoritative Guide for Linux Users
Configuring Proxy Servers on Linux for Enhanced Security and Privacy
Top Synthetic Data Generation Tools for AI and Testing in 2025
Campaigners urge UK PM Starmer to dump digital ID wheeze before it’s announced
Open source registries signal shift toward paid models as AI strains infrastructure
Politicos: ‘There is a good strong case for government intervention’ on JLR cyberattack
How to manage Python projects with Poetry
Reactive Java with Spring WebFlux and Reactor
How immutability tamed the Wild West
GraalVM 25 arrives, backed by JDK 25
QR codes become the vehicle for malware in new technique

https://security-tracker.debian.org/tracker/DSA-6009-1

https://security-tracker.debian.org/tracker/DSA-6008-1

Nearly half of businesses suffered deepfaked phone calls against staff
Third time’s the charm? SolarWinds (again) patches critical Web Help Desk RCE
OnePlus leaves researchers on read over Android bug that exposes texts
SIM city: Feds say 100,000-card farms could have killed cell towers in NYC
Kaspersky: RevengeHotels checks back in with AI-coded malware

Several security issues were fixed in pip.

OpenSSF warns that open source infrastructure doesn’t run on thoughts and prayers
GitHub moves to tighten npm security amid phishing, malware plague
What Is a Speculative Execution Linux Security Vulnerability?
Teradata taps open source frameworks to offer agent-building capabilities
Oracle gets to store US users’ TikTok data, says Trump

* bsc#1235237 Cross-References: * CVE-2024-55553

An update that solves two vulnerabilities can now be installed.

* bsc#1242617 * bsc#1243862 Cross-References: * CVE-2024-12224

* bsc#1246602 * bsc#1246604 * bsc#1247938 * bsc#1247939

* bsc#1246602 * bsc#1246604 * bsc#1247938 * bsc#1247939

Workers fear for their jobs as JLR’s latest shutdown extended
Full Disk Encryption: What It Is, How It Works, and Why It Matters for Linux Security in 2025
Suspected Iran-backed attackers targeting European aerospace sector with novel malware
UK chancellor Putin the blame on Russia for cyber chaos, but evidence says otherwise
Vibe coding and the future of software development
The productivity paradox of AI-assisted coding
Cloud computing has an ROI problem
EV charging biz zaps customers with data leak scare
GitHub introduces registry for finding MCP servers
Web Codegen Scorer evaluates AI-generated web code
Cops cuff another teen over alleged Scattered Spider attack that broke Vegas casinos
EU’s cyber agency blames ransomware as Euro airport check-in chaos continues

* bsc#1249391 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

An update that contains one feature can now be installed.

Car giant Stellantis says customer data nicked after partner vendor pwned
Advanced debug logging techniques: A technical guide
Do vector-native databases beat add-ons for AI applications?
NPM attacks and the security of software supply chains

* bsc#1248252 Cross-References: * CVE-2025-53192

An update that solves one vulnerability can now be installed.

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

FOMO? Brit banking biz rolls out AI tools, talks up security
Trump says Michael Dell is part of the team buying TikTok, with Larry Ellison and maybe some Murdochs
Tech troubles create aviation chaos on both sides of the Atlantic
Ransomware attack linked to museum break-in and theft of golden exhibits

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 11 vulnerabilities can now be installed.

Multiple vulnerabilities were found in PAM namespace module used to configure private namespaces for user sessions. CVE-2024-22365

https://security-tracker.debian.org/tracker/DSA-6007-1

Gamaredon X Turla collab

Notorious APT group Turla collaborates with Gamaredon, both FSB-associated groups, to compromise high‑profile targets in Ukraine

Everything You Need to Know About Linux Proxy Servers (2025 Guide)

Fix Out of bounds read for cookie path (CVE-2025-9086) Fix predictable WebSocket mask (CVE-2025-10148)

New upstream release fixing the following security weaknesses (CVE-2025-8114, CVE-2025-8277)

Rust 1.90 brings workspace publishing support to Cargo

* bsc#1247589 Cross-References: * CVE-2025-50422

* bsc#1248461 Cross-References: * CVE-2025-9301

ChatGPT joins human league, now solves CAPTCHAs for the right prompt
Ivanti EPMM holes let miscreants plant shady listeners, CISA says
Small businesses, big targets: Protecting your business against ransomware

Long known to be a sweet spot for cybercriminals, small businesses are more likely to be victimized by ransomware than large enterprises

Ding ding: Fortra rings the perfect-10 bell over latest GoAnywhere MFT bug
Scattered Spider teen cuffed after buying games and meals with extortion bitcoin
One token to pwn them all: Entra ID bug could have granted access to every tenant

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, information disclosure or bypass of the same-origin policy.

OpenAI plugs ShadowLeak bug in ChatGPT that let miscreants raid inboxes

The system could be made to crash or run programs as an administrator.

The system could be made to crash or run programs as an administrator.