Menu

Monthly Archives: September 2025

1,200 undergrads hung out to dry after jailbreak attack on laundry machines
Navigating AI risk: Building a trusted foundation with Red Hat
Privacy activists warn digital ID won’t stop small boats – but will enable mass surveillance
Hack to school: Parents told to keep their little script kiddies in line
When it comes to AI, bigger isn’t always better
The hidden threat to AI performance
Making good choices: How to get the best from Python tools
Huntress’s ‘hilarious’ attacker surveillance splits infosec community
VS Code 1.104 emphasizes AI model selection, agent security
We’re number 1! America now leads the world in surveillanceware investment

https://security-tracker.debian.org/tracker/DSA-5997-1

https://security-tracker.debian.org/tracker/DSA-5996-1

Hijacker helper VoidProxy boosts Google, Microsoft accounts on demand
AI-powered penetration tool, an attacker’s dream, downloaded 10K times in 2 months
Anti-DDoS outfit walloped by record packet flood
Spectre haunts CPUs again: VMSCAPE vulnerability leaks cloud secrets
Senator blasts Microsoft for ‘dangerous, insecure software’ that helped pwn US hospitals
Brussels faces privacy crossroads over encryption backdoors
Attacker steals customer data from Brit rail operator LNER during break-in at supplier
Experts scrutinized Ofcom’s Online Safety Act governance. They’re concerned
How to implement caching in ASP.NET Core minimal APIs
How LinkedIn built an agentic AI platform
Unlocking LLM superpowers: How PagedAttention helps the memory maze
BAE Systems surfaces autonomous submarine for military use
NASA bars Chinese citizens from its facilities, networks, even Zoom calls
Beijing went to ‘EggStreme’ lengths to attack Philippines military, researchers say

https://security-tracker.debian.org/tracker/DSA-5998-1

Smashing Security podcast #434: Whopper Hackers, and AI Whoppers
Akira ransomware crims abusing trifecta of SonicWall security holes for extortion attacks
US charges suspected ransomware kingpin, and offers $10 million bounty for his capture
JFrog announces ‘agentic repo’ for AI-driven development
Apple slips up on ChillyHell macOS malware, lets it past security . . . for 4 years
Preventing business disruption and building cyber-resilience with MDR

Given the serious financial and reputational risks of incidents that grind business to a halt, organizations need to prioritize a prevention-first cybersecurity strategy

Jaguar Land Rover U-turns to confirm ‘some data’ affected after cyber prang
.NET 10 moves to release candidate stage
Uncle Sam indicts alleged ransomware kingpin tied to $18B in damages
Flu jab email mishap exposes hundreds of students’ personal data
Organize Rust projects for faster compilation with Cargo workspaces
9 vital concepts of modern JavaScript
Six hard truths for software development bosses
Lovesac warns customers their data was breached after suspected RansomHub attack six months ago
Cybercrooks ripped the wheels off at Jaguar Land Rover. Here’s how not to get taken for a ride
This Patch Tuesday, SAP is the worst offender and Microsoft users can kinda chill

https://security-tracker.debian.org/tracker/DSA-5995-1

JDK 26: The new features in Java 26
More packages poisoned in npm attack, but would-be crypto thieves left pocket change
New cybersecurity rules land for Defense Department contractors

Important: postgresql:15 security update

Important: postgresql:16 security update

Important: mingw-sqlite security update

Important: kernel-rt security update

Moderate: kernel-rt security update

Moderate: kernel-rt security update

Defense Dept didn’t protect social media accounts, left stream keys out in public
No gains, just pains as 1.6M fitness phone call recordings exposed online
The AI Fix #67: Will Smith’s AI crowd scandal, and gullible agents fall for scams
What the Plex? Streaming service suffers yet another password spill
When AI nukes your database: The dark side of vibe coding
Nokia successor HMD spawns secure device biz with Euro-made smartphone
Anthropic’s Claude Code runs code to test if it is safe – which might be a big mistake
Beyond AI protocols: Preparing for MCP and A2A in production
How to evaluate AI agent development tools and platforms
Conflicting opinions on the ROI of AI
UK toughens Online Safety Act with ban on self-harm content
Forget disappearing messages – now Signal will store 100MB of them for you for free
Perl programming language rises again – Tiobe
WhatsApp’s former security boss claims reporting infosec failings led to ousting
Groovy 5 expands Java and JDK support
The US government has no idea how many cybersecurity pros it employs
Drift massive attack traced back to loose Salesloft GitHub account
Dev snared in crypto phishing net, 18 npm packages compromised
Salt Typhoon used dozens of domains, going back five years. Did you visit one?
Google intros EmbeddingGemma for on-device AI
PACER buckles under MFA rollout as courts warn of support delays
CISA sounds alarm over TP-Link wireless routers under attack
What Are Container Escape Vulnerabilities?
UK tech minister booted out in weekend cabinet reshuffle
13 reasons SQL has got to go
How to spin Python’s challenges into AI gold

https://security-tracker.debian.org/tracker/DSA-5994-1

https://security-tracker.debian.org/tracker/DSA-5993-1

* bsc#1243314 Cross-References: * CVE-2025-4945

Under lock and key: Safeguarding business data with encryption

As the attack surface expands and the threat landscape grows more complex, it’s time to consider whether your data protection strategy is fit for purpose

* bsc#1230028 * bsc#1247207 Cross-References: * CVE-2024-58266

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

The crazy, true story behind the first AI-powered ransomware
Shell to pay: Crims invade your PC with CastleRAT malware, now in C and Python
Databricks adds Data Science Agent to automate analytics tasks
Rust Innovation Lab launched, sponsors first project
Critical, make-me-super-user SAP S/4HANA bug under active exploitation
GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes

ESET researchers have identified a new threat actor targeting Windows servers with a passive C++ backdoor and a malicious IIS module that manipulates Google search results

Germany charges hacker with Rosneft cyberattack in latest wake-up call for critical infrastructure