Menu

Monthly Archives: October 2025

* bsc#1235237 Cross-References: * CVE-2024-55553

UK government says digital ID won’t be compulsory – honest
Oracle tells Clop-targeted EBS users to apply July patch, problem solved
IBM launches Granite 4.0 to cut AI infra costs with hybrid Mamba-transformer models
What is an internal developer platform? IDP explained
The JavaScript code won’t write itself
Who stops wasteful cloud spending?
Criminals take Renault UK customer data for a joyride
Microsoft unveils framework for building agentic AI apps

New upstream release (143.0.3)

CVE-2025-7493: host to admin escalation prevention: https://www.freeipa.org/release-notes/4-12-5.html Update FreeIPA to latest fixes from ipa-4-12 branch

Update to 7.1.2.

cve fixes

Security update for path traversal CVE-2025-59825 / GHSA-3wgq-wrwc-vqmv.

https://security-tracker.debian.org/tracker/DSA-6018-1

https://security-tracker.debian.org/tracker/DSA-6017-1

Chainguard offers malware-resistant JavaScript libraries
Subpoena tracking platform blames outage on AWS social engineering attack

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Clop-linked crims shake down Oracle execs with data theft claims
EU funds are flowing into spyware companies, and politicians are demanding answers
Why Software Supply Chain Security Matters in Linux Systems

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Cybercrims claim raid on 28,000 Red Hat repos, say they have sensitive customer files
How to deploy machine learning models with AWS Lambda
Using Microsoft’s Data API builder for Azure databases
Why observability needs Apache Iceberg
Claude Sonnet 4.5 coding model improves agentic capabilities

https://security-tracker.debian.org/tracker/DSA-6016-1

Smashing Security podcast #437: Salesforce’s trusted domain of doom
Your favourite phone apps might be leaking your company’s secrets
US gov shutdown leaves IT projects hanging, security defenders a skeleton crew
‘Delightful’ root-access bug in Red Hat OpenShift AI allows full cluster takeover
Air Force admits SharePoint privacy issue as reports trickle out of possible breach
Microsoft .NET Aspire backs .NET 10 file-based apps
3.7M breach notification letters set to flood North America’s mailboxes
AI agent hypefest crashing up against cautious leaders, Gartner finds
Imgur yanks Brit access to memes as parent company faces fine
Spotlight report: Securing the cloud
Explain digital ID or watch it fizzle out, UK PM Starmer told
PDM: A smarter way to manage Python packages
Intro to Nitro: The server engine built for modern JavaScript
Why we need junior developers
Schools are swotting up on security yet still flunk recovery when cyberattacks strike

Several security issues were fixed in the Linux kernel.

An issue was found in open-vm-tools, a set of tools for VMs hosted on VMware. The issue is related to a local privilege escalation in combination with the get-versions.sh script, shipped with the service

Beijing-backed burglars master .NET to target government web servers

BIRD 3.1.4 (2025-09-22) BGP: Fixed crash on Notification with a message, CVE-2025-59688 BGP: Fixed invalid memory access in pending TX flush BGP: Fixed a rare bug with listening socket delay Pipe: Disabled statisticts for stopping pipe

Update to version 1.6.2. Includes fixes for CVE-2025-58066 (potential DoS in the ntpd-rs server) and CVE-2025-58160 (potential tracing log pollution).

Update to 2.0.1 to CVE-2025-30187

Update the ammonia crate to version 4.1.2 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071.

https://security-tracker.debian.org/tracker/DSA-6015-1