Menu

Monthly Archives: September 2025

Parents warned that robot toys spied on children’s location without consent

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

* bsc#1249011 Cross-References: * CVE-2025-58160

* bsc#1246623 * jsc#PED-13306 Cross-References: * CVE-2025-40918

PostgreSQL 18 to boost OLTP performance, but misses AI readiness
Is Meta’s $10 billion cloud deal a good idea for you?
What makes JavaScript great
Knock-on effects of software dev break-in hit schools trust
Swiss launch open source AI model as “ethical” alternative to big US LLMs
Attackers snooping around Sitecore, dropping malware via public sample keys
Boffins build automated Android bug hunting system
China-aligned crew poisons Windows servers to manipulate Google results
Gemini 2.5 Flash Image model advances AI image generation
JDK 26 to get HTTP/3 support

FFmpeg could be made to crash if it received specially crafted input.

A couple of vulnerabilities have been fixed in ClamAV, an anti-virus utility for Unix. CVE-2025-20128

* bsc#1246058 * bsc#1246059 Cross-References: * CVE-2025-32023

* bsc#1225905 Cross-References: * CVE-2024-35221

* bsc#1248810 Cross-References: * CVE-2025-57833

Enterprises sticking with Windows 10 could shell out billions for continued support
Security beyond the model: Introducing AI system cards
Learn about confidential clusters
Neo4j unveils Infinigraph to merge OLTP and OLAP for Agentic AI
Vibe coding with GitHub Spark
Databot: AI-assisted data analysis in R or Python
Sainsbury’s eyes up shoplifters with live facial recognition
France fines Google, SHEIN for undercooked cookie policies that led to crummy privacy
US puts $10M bounty on three Russians accused of attacking critical infrastructure
Congressional panel throws cyber threat intel-sharing, funding a lifeline
Smashing Security podcast #433: How hackers turned AI into their new henchman
Android drops mega patch bomb – 120 fixes, two already exploited
Zoneless Angular arrives in Angular 20.2
Crims claim HexStrike AI penetration tool makes quick work of Citrix bugs
It looks like you’re ransoming data. Would you like some help?
FBI warns seniors are being targeted in three-phase Phantom Hacker scams
The AI Fix #66: OpenAI and Anthropic test each other, and everyone fails the apocalypse test
Matrix.org homeserver grinds to a halt after RAID meltdown

* bsc#1246088 Affected Products: * HPC Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7

OpenAI acquires Statsig to speed up generative AI-based product launches
What is the JVM? Introducing the Java virtual machine
Native UI vs. web UI: How to choose
Seven little habits for writing better code
Internet mapping and research outfit Censys reveals state-based abuse, harassment

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Senior developers let AI do more of the coding — survey
How big will this Drift get? Cloudflare cops to Salesloft Drift breach
Who watches the watchmen? Surveillanceware firms make bank, avoid oversight

Two vulnerabilities have been fixed in the audio data read/write library libsndfile.

Zscaler latest victim of Salesloft Drift attacks, customer data exposed
Google to add developer verification requirement for Android apps
Stolen OAuth tokens expose Palo Alto customer data

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

Exploring Open Source Intelligence (OSINT) Techniques And Tools For Cybersecurity Applications
Huawei counts cost of Western bans as UK business withers
Frostbyte10 bugs put thousands of refrigerators at major grocery chains at risk
How to build a production-grade agentic AI platform – lessons from Gravity
Overseas enterprises and US sovereign clouds
Reg readers have spoken: 93% back move away from Microsoft in UK public sector
Europe Putin the blame on Russia after GPS jamming disrupts president’s plane
In the rush to adopt hot new tech, security is often forgotten. AI is no exception

Several security issues were fixed in ImageMagick.

Microsoft signals shift from OpenAI with launch of first in-house AI models for Copilot
Norway’s £10B UK frigate deal could delay Royal Navy ships
DDoS is the neglected cybercrime that’s getting bigger. Let’s kill it off
Spotlight report: IT careers in the AI era
LegalPwn: Tricking LLMs by burying badness in lawyerly fine print

DoS with large SAML responses has been fixed in ruby-saml, a library implementing the client side of SAML authorization for the Ruby interpreter.

Why DocumentDB can be a win for MongoDB

* bsc#1244270 * bsc#1244272 Cross-References: * CVE-2025-5914

Hacker suspected of trying to cheat his way into university is arrested in Spain
Traffic to government domains often crosses national borders, or flows through risky bottlenecks
A guide to the multicloud strategies of AWS, Azure, and Google Cloud
WhatsApp warns of ‘attack against specific targeted users’

Update to release v0.27.0 Resolves: rhvz#2388453, rhbz#2384137, rhbz#2384154 Upstream new features and fixes

Exiv2 0.28.6 + patch to fix silent abi breakage Exiv2 v0.28.6 (Fixes two low severity CVEs)

Update to 139.0.7258.154 CVE-2025-9478: Use after free in ANGLE