Menu

Monthly Archives: November 2025

Fresh ClickFix attacks use Windows Update trick-pics to steal credentials
Praise Amazon for raising this service from the dead
Ex-CISA officials, CISOs dispel ‘hacklore,’ spread cybersecurity truths
Key Linux Features Boosting Security Measures for the Year 2026
Years-old bugs in open source tool left every major cloud open to disruption
Intrusion at real estate finance biz sparks concern for big banks
Shai-Hulud worm returns, belches secrets to 25K GitHub repos

Several security issues were fixed in cups-filters.

FCC guts post-Salt Typhoon telco rules despite ongoing espionage risk

* bsc#1231032 * bsc#1231033 * bsc#1232855 * bsc#1236496 * bsc#1236497

An update that solves nine vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

* bsc#1237236 * bsc#1237240 * bsc#1237241 * bsc#1237242

* bsc#1065729 * bsc#1199304 * bsc#1205128 * bsc#1206893 * bsc#1210124

AWS open-sources Agent SOPs to simplify AI agent development
CISA orders feds to patch Oracle Identity Manager zero-day after signs of abuse
Championing cyber security: the national UK cyber team’s journey at the European Cyber Security Challenge
Anatomy of an AI agent knowledge base
7 ways AI is changing software testing
Software development has a ‘996’ problem
Operation Endgame disrupts Rhadamanthys information-stealing malware
Cryptology boffins’ association to re-run election after losing encryption key needed to count votes
70-hour work weeks no longer enough for Infosys founder, who praises China’s 996 culture
Weaponized file name flaw makes updating glob an urgent job

An update that solves 3 vulnerabilities can now be installed.

An update that solves 6 vulnerabilities can now be installed.

Update to release v1.32.10 Resolves: rhbz#2414539 Resolves: rhbz#2398587, rhbz#2398848, rhbz#2399249, rhbz#2399522 Resolves: rhbz#2399703, rhbz#2399721, rhbz#2407788, rhbz#2408058 Resolves: rhbz#2408315, rhbz#2408609, rhbz#2408672, rhbz#2408730

Update to the 3.8.11 release with a fix for CVE-2025-9820 and several enhancements.

MGASA-2025-0310 – Updated kernel-linus packages fix security vulnerabilities

MGASA-2025-0309 – Updated kernel, kmod-xtables-addons & kmod-virtualbox packages fix security vulnerabilities

Upstream linux-firmware 20251111 release: rtl_bt: Update RTL8922A BT USB firmware to 0x41C0_C905 add firmware for mt7987 internal 2.5G ethernet phy rtw88: 8822b: Update firmware to v30.20.0 rtl_nic: add firmware rtl8125k-1

This is the .NET 10 GA update Update .NET 10 to RC 2

Update to release v1.32.10 Resolves: rhbz#2414539 Resolves: rhbz#2398587, rhbz#2398848, rhbz#2399249, rhbz#2399522 Resolves: rhbz#2399703, rhbz#2399721, rhbz#2407788, rhbz#2408058 Resolves: rhbz#2408315, rhbz#2408609, rhbz#2408672, rhbz#2408730

Update to 1.6.0

Update to 1.16.0

Update to release v1.31.14 Resolves: rhbz#2398586, rhbz#2398847, rhbz#2399248, rhbz#2399521 Resolves: rhbz#2399702, rhbz#2399720, rhbz#2407787, rhbz#2408057 Resolves: rhbz#2408314, rhbz#2408608, rhbz#2408671, rhbz#2408729 Resolves: rhbz#2409236, rhbz#2409526, rhbz#2409787, rhbz#2410201

ShinyHunters ‘does not like Salesforce at all,’ claims the crew accessed Gainsight 3 months ago

Several security issues were fixed in cups-filters.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Several security issues were fixed in libcupsfilters.

The OSINT playbook: Find your weak spots before attackers do

Here’s how open-source intelligence helps trace your digital footprint and uncover your weak points, plus a few essential tools to connect the dots

Four charged over alleged plot to smuggle Nvidia AI chips into China
Russia-linked crooks bought a bank for Christmas to launder cyber loot
ZTE Launches ZXCSec MAF security solution for large model
It’s the end of vibe coding, already
Google links Android’s Quick Share to Apple’s AirDrop, without Cupertino’s help
PHP 8.5 enables secure URI and URL parsing

New gnutls packages are available for Slackware 15.0 and -current to fix security issues.

SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere
F# 10 features scoped warning suppression

ImageMagick could be made to crash or run programs as your login if it opened a specially crafted file.

https://security-tracker.debian.org/tracker/DSA-6060-1

Salesforce-linked data breach claims 200+ victims, has ShinyHunters’ fingerprints all over it
LLM-generated malware is improving, but don’t expect autonomous attacks tomorrow
PlushDaemon compromises network devices for adversary-in-the-middle attacks

ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks

How pairing SAST with AI dramatically reduces false positives in code security
UK’s new cybersecurity bill takes aim at ransomware gangs and state-backed hackers
Fired techie admits sabotaging ex-employer, causing $862K in damage
TP-Link accuses rival Netgear of ‘smear campaign’ over alleged China ties
Education boards left gates wide open for PowerSchool mega-breach, say watchdogs

An update that solves two vulnerabilities can now be installed.

* bsc#1250353 * bsc#1250354 Cross-References: * CVE-2025-59798

Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood
Wind farm worker sentenced after turning turbines into a secret crypto mine
Smashing Security podcast #444: We’re sorry. Wait, did a company actually say that?
Improving annotation quality with machine learning
Azure HorizonDB: Microsoft goes big with PostgreSQL

* bsc#1252931 * bsc#1252932 * bsc#1252933 * bsc#1252934 * bsc#1252935

An update that solves five vulnerabilities can now be installed.

Palo Alto CEO tips nation-states to weaponize quantum computing by 2029
US, UK, Australia sanction Lockbit gang’s hosting provider
Microsoft rolls out Agent 365 ‘control plane’ for AI agents

New openvpn packages are available for Slackware 15.0 and -current to fix security issues.

Fortinet ‘fesses up to second 0-day within a week

Several security issues were fixed in the Linux kernel.

Amazon security boss: Hostile countries use cyber targeting for physical military strikes
Microsoft Fabric IQ adds ‘semantic intelligence’ layer to Fabric
Researchers claim ‘largest leak ever’ after uncovering WhatsApp enumeration flaw
Enhance workload security with confidential containers on Azure Red Hat OpenShift
Introducing OpenShift Service Mesh 3.2 with Istio’s ambient mode
Microsoft touts scalability of its new PostgreSQL-compatible managed database
Google releases Gemini 3 with new reasoning and automation features
Tens of thousands more ASUS routers pwned by suspected, evolving China operation
Building a scalable document management system: Lessons from separating metadata and content
Selling technology investments to the board: a strategic guide for CISOs and CIOs
Hands-on with Zed: The IDE built for AI
Clojure for Java developers: What you need to know
A developer’s guide to avoiding the brambles
China recruiting spies in the UK with fake headhunters and ‘sites like LinkedIn’
Google unveils Gemini 3 AI model, Antigravity agentic development tool

MGASA-2025-0305 – Updated thunderbird packages fix security vulnerabilities

MGASA-2025-0304 – Updated cups-filters packages fix security vulnerabilities

MGASA-2025-0303 – Updated flatpak & bubblewrap packages fix security vulnerability

C# 14 touted for extension properties declaration

Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8

Updated to latest upstream (145.0) Added fix for mzbz#1990430 (crashes) Updated to latest upstream (144.0)

New libarchive packages are available for Slackware 15.0 and -current to fix security issues.

Self-replicating botnet attacks Ray clusters
Go team to improve support for AI assistants