Menu

Monthly Archives: November 2025

Version 0.18.1 Security Fixed critical issue where PKESK (public-key encrypted) session keys were generated as all-zero, allowing trivial decryption of messages encrypted with public keys only (CVE-2025-13402)

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 9 vulnerabilities can now be installed.

Update to 20251125: Revert “amdgpu: update GC 11.0.1 firmware” QCA: Add Bluetooth firmware for WCN685x uart interface qcom: Add ADSP firmware for qcs6490-thundercomm-rubikpi3 qcom: venus-5.4: update firmware binary for v5.4

Update to 4.19.0 Address CVEs by rebuilding with Go 1.24.10

https://security-tracker.debian.org/tracker/DSA-6066-1

* bsc#1253757 Cross-References: * CVE-2025-11563

* bsc#1245953 * bsc#1252930 * bsc#1252931 * bsc#1252932 * bsc#1252933

This month in security with Tony Anscombe – November 2025 edition

Data exposure by top AI companies, the Akira ransomware haul, Operation Endgame against major malware families, and more of this month’s cybersecurity news

Comprehending Fingerprinting Risks Faced by Linux Users Today

A race condition was discovered in Qt, a cross-platform C++ application framework. Code to make security-relevant decisions about an established HTTP2 connection may execute too early, because the encrypted() signal has not yet been emitted and processed.

What Is a Side-Channel Attack? A Linux Security Overview

* bsc#1249537 Cross-References: * CVE-2025-38616

New libxslt packages are available for Slackware 15.0 and -current to fix security issues.

Several security vulnerabilities were discovered in the server of the Tryton application platform, which could lead to information disclosure. For Debian 11 bullseye, these problems have been fixed in version

What parents should know to protect their children from doxxing

Online disagreements among young people can easily spiral out of control. Parents need to understand what’s at stake.

PostHog admits Shai-Hulud 2.0 was its biggest ever security bungle
The Ultimate Handbook for Linux Security Tools and Hardening Tips 2026
Brit telco Brsk confirms breach as bidding begins for 230K+ customer records
GrapheneOS bails on OVHcloud over France’s privacy stance

* bsc#1252110 * bsc#1252232 Cross-References: * CVE-2025-31133

* bsc#1215199 * bsc#1218644 * bsc#1230062 * bsc#1234634 * bsc#1234693

* bsc#1249191 * bsc#1249348 * bsc#1249367 * bsc#1253757

* bsc#1218644 * bsc#1238472 * bsc#1239206 * bsc#1241166 * bsc#1241637

* bsc#1253278 * bsc#1253642 * bsc#1253703 * jsc#PED-9265

* bsc#1252414 * bsc#1252417 * bsc#1252418 * jsc#PED-14233

TryHackMe races to add women to Christmas cyber challenge roster after backlash
AWS launches Flexible Training Plans for inference endpoints in SageMaker AI
Everything You Need to Know About Linux Proxy Servers (2026 Guide)
Full Disk Encryption: What It Is, How It Works, and Why It Matters for Linux Security in 2026
UNC2891 Hackers Use Linux Malware in Major Banking Security Heists
How Holiday Leave Exposes Linux Security Gaps in Docker and Kubernetes Environments
OBR drags in cyber bigwig after Budget leak blunder
UK digital ID plan gets a price tag at last – £1.8B
Spotlight: Making the most of multicloud
What is devops? Bringing dev and ops together to build better software
Python vs. Kotlin: Which loops do you like better?
Cloud fragility is costing us billions
Security researchers caution app developers about risks in using Google Antigravity

https://security-tracker.debian.org/tracker/DSA-6065-1

https://security-tracker.debian.org/tracker/DSA-6064-1

Korean web giant Naver acquired crypto exchange Upbit, which reported a $30m heist a day later
Zendesk users targeted as Scattered Lapsus$ Hunters spin up fake support sites
OpenAI cuts off Mixpanel after analytics leak exposes API users
Optimizing Linux Security 2026: Key Strategies for Modern Threats
OpenAI admits data breach after analytics partner hit by phishing attack
FCC sounds alarm after emergency tones turned into potty-mouthed radio takeover
Asahi admits ransomware gang may have spilled almost 2M people’s data
Scottish council still rebuilding systems two years after ransomware attack

Several vulnerabilities have been found in libssh, a tiny C SSH library. CVE-2025-4877

An update that solves 83 vulnerabilities and has 101 bug fixes can now be installed.

An update that solves one vulnerability and has one bug fix can now be installed.

State-backed spyware attacks are targeting Signal and WhatsApp users, CISA warns
Four important lessons about context engineering
Agentic cloud ops with the new Azure Copilot

FFmpeg could be made to crash if it opened a specially crafted file.

An update that solves two vulnerabilities can now be installed.

* bsc#1248672 * bsc#1249537 Cross-References: * CVE-2025-38500

https://security-tracker.debian.org/tracker/DSA-6062-1

https://security-tracker.debian.org/tracker/DSA-6061-1

Smashing Security podcast #445: The hack that brought back the zombie apocalypse
Google updates Gemini API for Gemini 3
Gainsight CEO downplays breach, says only a ‘handful’ of customers had data stolen
Botnet takes advantage of AWS outage to smack 28 countries
Influencers in the crosshairs: How cybercriminals are targeting content creators

Social media influencers can provide reach and trust for scams and malware distribution. Robust account protection is key to stopping the fraudsters.

Mobile industry warns patchwork cyber regs are driving up costs
Shadow AI security breaches will hit 40% of all companies by 2030, warns Gartner
CodeRED emergency alert system CodeDEAD after INC ransomware attack
US Navy scuttles Constellation frigate program for being too slow for tomorrow’s threats
London councils probe cyber incident as shared IT systems knocked offline

An update that solves 573 vulnerabilities and has 669 bug fixes can now be installed.

Several security issues were fixed in the Linux kernel.

Top five cybersecurity Black Friday deals for businesses 2025
Intro to Nest.js: Server-side JavaScript development on Node
Getting the enterprise data layer unstuck for AI
Writing code is so over

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that solves one vulnerability can now be installed.

* bsc#1251983 Cross-References: * CVE-2023-53673

Kotlin introduces checker for unused return values

https://security-tracker.debian.org/tracker/DSA-6063-1

Lifetime access to AI-for-evil WormGPT 4 costs just $220
Corporate predators get more than they bargain for when their prey runs SonicWall firewalls
Developers left large cache of credentials exposed on code generation websites
MDR is the answer – now, what’s the question?

Why your business needs the best-of-breed combination of technology and human expertise

HashJack attack shows AI browsers can be fooled with a simple ‘#’
Get ready for 2026, the year of AI-aided ransomware
The AI Fix #78: The big AI bubble, and robot Grandma in the cloud
Clop’s Oracle EBS rampage reaches Dartmouth College

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

An update that contains one feature can now be installed.

* bsc#1251305 * bsc#1252974 Cross-References: * CVE-2025-6075

An update that solves two vulnerabilities can now be installed.

* bsc#1252379 * bsc#1252380 Cross-References: * CVE-2025-40778

* bsc#1252931 * bsc#1252932 * bsc#1252933 * bsc#1252934 * bsc#1252935

CISA warns spyware crews are breaking into Signal and WhatsApp accounts
Russian spy ship theories sink after Orkney blackout traced to wind farm fault
ZTE, China Unicom Liaoning and Dalian Changhai Airport launch 5G-A ISAC private network to elevate low-altitude security and airport safety