Menu

Monthly Archives: November 2025

FCC looks to torch Biden-era cyber rules sparked by Salt Typhoon mess
Take fight to the enemy, US cyber boss says
Google Chrome bug exploited as an 0-day – patch now or risk full system compromise
What if your romantic AI chatbot can’t keep a secret?

Does your chatbot know too much? Think twice before you tell your AI companion everything.

The AI Fix #77: Genome LLM makes a super-virus, and should AI decide if you live?
Zoomers are officially worse at passwords than 80-year-olds
A miracle: A company says sorry after a cyber attack – and donates the ransom to cybersecurity research
Why context engineering will define the next era of enterprise AI
How to automate the testing of AI agents
What is A2A? How the agent-to-agent protocol enables autonomous collaboration
Do you really need all those GPUs?

* bsc#1103203 * bsc#1149841 * bsc#1230998 * bsc#1231204 * bsc#1231676

MGASA-2025-0302 – Updated postgresql15 & postgresql13 packages fix security vulnerabilities

MGASA-2025-0301 – Updated apache packages fix security vulnerabilities

Several security issues were fixed in Freeglut.

Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8

FVWM3 ver. 1.1.4

‘Largest-ever’ cloud DDoS attack pummels Azure with 3.64B packets per second
Pentagon and soldiers let too many secrets slip on social networks, watchdog says
Security researcher calls BS on Coinbase breach disclosure timeline
Red Hat Advanced Cluster Security 4.9: Security built with your workflows in mind
Selling your identity to North Korean IT scammers isn’t a sustainable side hustle
Game over: Europol storms gaming platforms in extremist content sweep
Overconfidence is the new zero-day as teams stumble through cyber simulations
Eurofiber admits crooks swiped data from French unit after cyberattack
UK prosecutors seize £4.11M in crypto from Twitter mega-hack culprit
North Korea’s ‘Job Test’ trap upgrades to JSON malware dropboxes
10 JavaScript-based tools and frameworks for AI and machine learning
Why software development slows to a crawl
The rebellion against robot drivel

An update that solves 173 vulnerabilities, contains two features and has 19 security fixes can now be installed.

* bsc#1065729 * bsc#1205128 * bsc#1206893 * bsc#1207612 * bsc#1207619

An update that solves two vulnerabilities can now be installed.

* bsc#1251198 * bsc#1251199 Cross-References: * CVE-2025-61984

An update that solves two vulnerabilities can now be installed.

* bsc#1247850 * bsc#1249076 Cross-References: * CVE-2025-8732

Jaguar Land Rover hack cost India’s Tata Motors around $2.4 billion and counting
Logitech leaks data after zero-day attack

https://security-tracker.debian.org/tracker/DSA-6058-1

Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8

Update to 9.21.14 (rhbz#2394406) Security Fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

New upstream release v10 Fix: CVE-2025-11568

Update to 9.21.14 (rhbz#2394406) Security Fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

New upstream release v10 Fix: CVE-2025-11568

https://security-tracker.debian.org/tracker/DSA-6059-1

New xpdf packages are available for Slackware 15.0 and -current to fix security issues.

Keylogging in Linux (Part 3): Kernel Techniques for the Keyboard Driver Path

MGASA-2025-0298 – Updated stardict packages fix security vulnerability

MGASA-2025-0297 – Updated yelp & yelp-xsl packages fix security vulnerability

MGASA-2025-0296 – Updated apache-commons-fileupload packages fix security vulnerability

MGASA-2025-0295 – Updated botan2 packages fix security vulnerabilitiy

MGASA-2025-0294 – Updated spdlog packages fix security vulnerability

MGASA-2025-0293 – Updated apache-commons-lang3 & apache-commons-lang packages fix security vulnerability

Worm flooding npm registry with token stealers still isn’t under control
Red Hat Linux bolsters AI assistance

https://security-tracker.debian.org/tracker/DSA-6057-1

https://security-tracker.debian.org/tracker/DSA-6056-1

Fortinet finally cops to critical make-me-admin bug under active exploitation
How password managers can be hacked – and how to stay safe

Look no further to learn how cybercriminals could try to crack your vault and how you can keep your logins safe

Crims poison 150K+ npm packages with token-farming malware
FBI flags scam targeting Chinese speakers with bogus surgery bills
CISA flags imminent threat as Akira ransomware starts hitting Nutanix AHV
Improving modern software supply chain security: From AI models to container images
Prepare for a post-quantum future with RHEL 9.7
A deeper look at post-quantum cryptography support in Red Hat OpenShift 4.20 control plane
Keylogging in Linux (Part 2): Advanced Techniques in the Linux GUI and X Server
Copy-paste vulnerability hits AI inference frameworks at Meta, Nvidia, and Microsoft
Clop claims it hacked ‘the NHS.’ Which bit? Your guess is as good as theirs
Python vs. Mojo (and Java, Go, Rust, and .NET)
Tech mega-deals are a distraction, not a breakthrough

* bsc#1253092 * bsc#1253093 * bsc#1253094 * bsc#1253095

Google BigQuery gets managed AI functions to simplify unstructured data analysis
Visual Studio Code unifies UI for managing coding agents
Baidu launches new generation of Ernie AI

Update to 2.53.22

Update to v0.25.2 CVE-2025-58183; Resolves: rhbz#2412529 CVE-2025-58188; Resolves: rhbz#2412380, rhbz#2411476, rhbz#2410945 CVE-2025-58185; Resolves: rhbz#2410578, rhbz#2410299, rhbz#2410013 CVE-2025-61723; Resolves: rhbz#2409627, rhbz#2409349, rhbz#2409065

Update to release v1.3.3

Update to 2.83.0

Kubernetes overlords decide Ingress NGINX isn’t worth saving

Update to 2.9.0 Fixes CVE-2025-46705

Chinese spies told Claude to break into about 30 critical orgs. Some attacks succeeded

https://security-tracker.debian.org/tracker/DSA-6054-1

Google Agent Development Kit adds Go language support
Ransomed CTO falls on sword, refuses to pay extortion demand
Ubuntu 25.10’s Rusty sudo holes quickly welded shut
Extra, extra, read all about it: Washington Post clobbered in Clop caper
Rhadamanthys malware admin rattled as cops seize a thousand-plus servers
Databricks fires back at Snowflake with SQL-based AI document parsing
NHS supplier ends probe into ransomware attack that contributed to patient death
OpenAI rolls out GPT-5.1 to refine ChatGPT with adaptive reasoning and personalization

A security issue was discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Java Stream API tutorial: How to create and use Java streams
When will browser agents do real work?
Running managed Ray on Azure Kubernetes Service
Red Hat OpenShift 4.20 boosts AI workloads, security

Update to Rack 2.2.21

Update to WebKitGTK 2.50.1: Improve text rendering performance. Fix audio playback broken on instagram. Fix rendering of layers with fractional transforms. Fix several crashes and rendering issues.

Update to Rack 2.2.21

Security fix for CVE-2025-58189 and CVE-2025-61725

Updated to latest upstream (145.0)