Menu

Monthly Archives: September 2025

Charities warn Ofcom too soft on Online Safety Act violators

The system could be made to crash or run programs as an administrator.

The system could be made to crash or run programs as an administrator.

How Oracle became a cloud player
How AI changes the data analyst role
Adding up the hidden costs of generative AI
Wasm 3.0 adds 64-bit backing, language support

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that an exploit for CVE-2025-10585 exists in the wild.

Vastaamo psychotherapy hack: US citizen charged in latest twist of notorious data breach
Replit update sparks developers’ dissatisfaction over pricing
MI6 reveals ‘Silent Courier’ dark web portal upgrade it hopes will help it recruit new spies

https://security-tracker.debian.org/tracker/DSA-6006-1

https://security-tracker.debian.org/tracker/DSA-6005-1

https://security-tracker.debian.org/tracker/DSA-6004-1

AI Alliance forges agent-native language, knowledge base
Google pushes emergency patch for Chrome 0-day – check your browser version now
Crims bust through SonicWall to grab sensitive config data
Cybercriminals pwn 850k+ Americans’ healthcare data
Two ‘Scattered Spider’ teens charged over attack on London’s transport network
Cloudflare DDoSed itself with React useEffect hook blunder

* bsc#1233421 Cross-References: * CVE-2024-52615

* bsc#1246197 * bsc#1249191 * bsc#1249348 * bsc#1249367 * jsc#PED-13055

* bsc#1246197 * bsc#1249191 * bsc#1249348 * bsc#1249367 * jsc#PED-13055

Insight Partners confirms ransomware hit, more than 12,000 caught in data dragnet
Panda-monium: China-backed cyber crew spoof Congressman to dig for dirt on US trade talks
Designing AI-ready architectures in compliance-heavy environments
Smoother Kubernetes sailing with AKS Automatic
“Pompompurin” resentenced: BreachForums creator heads back behind bars
San Francisco AI technology conference draws protests
Russian fake-news network, led by an ex-Florida sheriff’s deputy, storms back into action with 200+ new sites

https://security-tracker.debian.org/tracker/DSA-6003-1

Smashing Security podcast #435: Lights! Camera! Hacktion!
Scattered Spider gang feigns retirement, breaks into bank instead
HybridPetya: The Petya/NotPetya copycat comes with a twist

HybridPetya is the fourth publicly known real or proof-of-concept bootkit with UEFI Secure Boot bypass functionality

From mischief to malware: ICO warns schools about student hackers
Axiom Space aims for orbit with its Orbital Data Center Node
MongoDB adds vector search to self-managed editions to power generative AI apps
BreachForums kingpin goes from walk-free deal to 3-year stretch

* bsc#1236851 * bsc#1248070 Cross-References: * CVE-2025-23419

* bsc#1235673 * bsc#1235674 Cross-References: * CVE-2024-57822

* bsc#1243581 * bsc#1248410 * bsc#1248687 Cross-References:

* bsc#1237208 * bsc#1247528 * bsc#1247529 * bsc#1247530 * bsc#1247531

UK telco Colt’s recovery from August cyberattack pushes into November
What Is a Checksum? Meaning, Examples & Why You Should Use Them
Rust tutorial: Get started with the Rust language
Is AI the 4GL we’ve been waiting for?
The rise of AI-ready private clouds
Software developers aren’t buying it
UEFI Secure Boot for Linux Arm64 – where do we stand?
Ruh-roh. DDR5 memory vulnerable to new Rowhammer attack
Australia to let Big Tech choose its own adventure to enact kids social media ban
Visual Studio 2026 doubles down on AI-assisted coding
Microsoft blocks bait for ‘fastest-growing’ 365 phish kit, seizes 338 domains
Criminals broke into the system Google uses to share info with cops
Apple 0-day likely used in spy attacks affected devices as old as iPhone 8
Self-propagating worm fuels latest npm supply chain compromise
Luxury fashion brands Gucci, Balenciaga and Alexander McQueen hacked – customer data stolen
The AI Fix #68: AI telepathy, and rights for robots
‘FileFix’ attacks use fake Facebook security alerts to trick victims into running infostealers
Preparing your organization for the quantum future
JLR stuck in neutral as losses skyrocket amid cyberattack cleanup
China slaps 1-hour deadline on reporting serious cyber incidents

This update upgrade the package to version 0.36. This version fixes CVE-2025-40923 by using Crypt::SysRandom to generate secure session IDs.

This update upgrade the package to version 0.44. This version fixes CVE-2025-40924 by using Crypt::SysRandom to generate properly random session IDs.

This update upgrade the package to version 1.019. This version fixes CVE-2025-40920 by using Crypt::SysRandom to generate nonces instead of Data::UUID.

Update to 140.0.7339.127 CVE-2025-10200: Use after free in Serviceworker CVE-2025-10201: Inappropriate implementation in Mojo

2.4.14 (fixes CVE-2025-58060 and CVE-2025-58364)

Fix crash with spice GL (bz 2391334) Update to 10.1.0 GA release Automatic update for qemu-10.1.0-0.4.rc4.fc43.

https://security-tracker.debian.org/tracker/DSA-6002-1

Careless engineer stored recovery codes in plaintext, got whole org pwned
Security begins with visibility: How IGA brings hidden access risks to light
Former FinWise employee may have accessed nearly 700K customer records
Nork snoops whip up fake South Korean military ID with help from ChatGPT
China turns the screws on Nvidia with antitrust probe
The EU Cyber Resilience Act’s impact on open source security
Jaguar Land Rover supply chain workers must get Covid-style support, says union
2-agent architecture: Separating context from execution in AI systems
AI developer certifications tech companies want
Down and out with Cerebras Code
More hardware won’t fix bad engineering
UK Lords take aim at Ofcom’s ‘child-protection’ upgrades to Online Safety Act
Cyber-scam camp operators shift operations to vulnerable countries as sanctions strike
15 ransomware gangs ‘go dark’ to enjoy ‘golden parachutes’
Data destruction done wrong could cost your company millions

https://security-tracker.debian.org/tracker/DSA-6001-1

Databricks at a crossroads: Can its AI strategy prevail without Naveen Rao?
Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass

UEFI copycat of Petya/NotPetya exploiting CVE-2024-7344 discovered on VirusTotal

HybridPetya: More proof that Secure Boot bypasses are not just an urban legend

https://security-tracker.debian.org/tracker/DSA-6000-1

https://security-tracker.debian.org/tracker/DSA-5999-1

Samsung fixes Android 0-day that may have been used to spy on WhatsApp messages
Kotlin 2.2.20 boosts WebAssembly support
Are cybercriminals hacking your systems – or just logging in?

As bad actors often simply waltz through companies’ digital front doors with a key, here’s how to keep your own door firmly locked tight

All your vulns are belong to us! CISA wants to maintain gov control of CVE program
British rail passengers urged to stay on guard after hack signals failure