Menu

Monthly Archives: October 2025

Will JavaFX return to Java?

https://security-tracker.debian.org/tracker/DSA-6047-1

https://security-tracker.debian.org/tracker/DSA-6046-1

Russia finally bites the cybercrooks it raised, arresting suspected Meduza infostealer devs
Attackers dig up $11M in Garden Finance crypto exploit

* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268

* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208

OpenAI launches Aardvark to detect and patch hidden bugs in code
Resilience, not sovereignty, defines OpenStack’s next chapter
Agentic AI: What now, what next?

This upload fixes a few of security issues in the Python standard library included with PyPy, an alternative implementation of the Python 3 language. CVE-2024-6232

* bsc#1248631 * bsc#1249207 * bsc#1249208 Cross-References:

* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208

* bsc#1247737 * bsc#1248176 * bsc#1248631 * bsc#1249207 * bsc#1249208

NHS left with sick PCs as suppliers resist Windows 11 treatment
Europe preps Digital Euro to enter circulation in 2029
Rust 1.91 promotes Windows on Arm64 to Tier 1 target
Visual Studio October update adds Claude coding models

https://security-tracker.debian.org/tracker/DSA-6045-1

Suspected Chinese snoops weaponize unpatched Windows flaw to spy on European diplomats
Proton trains new service to expose corporate infosec cover-ups
Docker Compose vulnerability opens door to host-level writes – patch pronto
Spam text scammer fined £200,000 for targeting people in debt, after sending nearly one million messages
The human cost of the UK Government’s Afghan data leak
Invisible npm malware pulls a disappearing act – then nicks your tokens

The system could be made to expose sensitive information.

Netty could be made to send emails as your login if it received specially crafted input.

Cyberpunks mess with Canada’s water, energy, and farm systems
Postcode Lottery’s lucky dip turns into data slip as players draw each other’s info

Several security issues were fixed in AMD Microcode.

France jacks into the Matrix for state messaging – and pays too

Several security issues were fixed in GNU binutils.

Unit testing Spring MVC applications with JUnit 5
Key principles of a successful internal developer platform
Run Azure DevOps on premises
LinkedIn gives you until Monday to stop AI from training on your profile
Google adds tiered storage to NoSQL Bigtable to reduce complexity, costs

Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

Cursor 2.0 adds coding model, UI for parallel agents
Smashing Security podcast #441: Inside the mob’s million-dollar poker hack, and a Formula 1 fumble

https://security-tracker.debian.org/tracker/DSA-6043-1

This security hole can crash billions of Chromium browsers, and Google hasn’t patched it yet
EY exposes 4TB+ SQL database to open internet for who knows how long
Linux: Tee.Fail Moderate TEE Side-Channel Attack for 2024-001

Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.

Marketing giant Dentsu warns staff after Merkle data raid
Sole trader dispatched almost 1M spam texts to hard-up Brits, says watchdog
Introducing Red Hat’s STIG-hardened UBI for NVIDIA GPUs on Red Hat OpenShift
GitHub launches Agent HQ to bring order to AI-powered coding
UK government on the lookout for bargain-priced CTO
What’s the Go language really good for?
The top 4 JVM languages and why developers love them
The quiet glory of REST and JSON
9 in 10 Exchange servers in Germany still running out-of-support software

Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.

MGASA-2025-0251 – Updated poppler packages fix security vulnerability

MGASA-2025-0250 – Updated tomcat packages fix security vulnerabilities

Australian police building AI to translate emoji used by ‘crimefluencers’

Multiple vulnerabilities have been found in python-authlib, a Python library for OAuth and OpenID Connect servers.

Update to latest version (#2404637) Fix CVE-2025-47910, CVE-2025-47906, CVE-2025-26625

Eclipse LMOS AI platform integrates Agent Definition Language

https://security-tracker.debian.org/tracker/DSA-6044-1

TypeScript rises to the top on GitHub
The Linux Command Line: Bridging Security Awareness for Sysadmins
The AI Fix #74: AGI, LLM brain rot, and how to scam an AI browser
Clearview AI faces criminal heat for ignoring EU data fines
AI browsers face a security flaw as inevitable as death and taxes

* bsc#1251941 Cross-References: * CVE-2025-62291

* bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References:

Beatings, killings, and lasting fear: The human toll of MoD’s Afghan data breach

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43272 Big Bear discovered that processing maliciously crafted web content may lead to an unexpected process crash.

Google says reports of a Gmail breach have been greatly exaggerated
Chatbots parrot Putin’s propaganda about the illegal invasion of Ukraine
How to vibe code for free, or almost free
How to deploy an AI agent that actually solves help desk tickets
It takes an AWS outage to prioritize diversification

* bsc#1019074 * bsc#1227577 * bsc#1229825 * bsc#1243331 * bsc#1243611

* bsc#1019074 * bsc#1227577 * bsc#1229825 * bsc#1237495 * bsc#1243331

* bsc#1227577 * bsc#1231150 * bsc#1231157 * bsc#1246277 * bsc#1246421

Marks & Spencer swaps out TCS for fresh helpdesk deal
Azul, Cast AI join forces on Java performance

https://security-tracker.debian.org/tracker/DSA-6042-1

WSUS attacks hit ‘multiple’ orgs as Google and other infosec sleuths ring Redmond’s alarm bell
Meta releases PyTorch inference framework for edge devices

Moderate: kernel security update

Important: thunderbird security update

Moderate: kernel-rt security update

Moderate: kernel security update

PAM: Important Risks in Linux Authentication Trust Chain
Breach at Iran’s cyberspy factory results in leak of student data
You have one week to opt out or become fodder for LinkedIn AI training
Researchers exploit OpenAI’s Atlas by disguising prompts as URLs
X says passkey reset isn’t about a security issue – it’s to finally kill off twitter.com
Ex-CISA head thinks AI might fix code so fast we won’t need security teams
Maximizing speed: How continuous batching unlocks unprecedented LLM throughput
Taming the Java cold-start beast: A practical guide to high-performance serverless with GraalVM and Spring
Do programming certifications still matter?
Building a golden path to AI
UN Cybercrime Treaty wins dozens of signatories, to go with its many critics