Menu

Monthly Archives: November 2025

Smashing Security podcast #443: Tinder’s camera roll and the Buffett deepfake

https://security-tracker.debian.org/tracker/DSA-6055-1

Microsoft releases ‘AI-native’ Visual Studio 2026
Google sues 25 China-based scammers behind Lighthouse ‘phishing for dummies’ kit

https://security-tracker.debian.org/tracker/DSA-6053-1

https://security-tracker.debian.org/tracker/DSA-6052-1

Attackers turned Citrix, Cisco 0-day exploits into custom-malware hellscape
Why shadow AI could be your biggest security blind spot

From unintentional data leakage to buggy code, here’s why you should care about unsanctioned AI use in your company

Leading AI companies accidentally leak their passwords and digital keys on GitHub – what you need to know
Keylogging in Linux (Part 1): Understanding Attacks and Defenses

* bsc#1229825 * bsc#1241880 * bsc#1243331 * bsc#1243486 * bsc#1243611

* bsc#1251198 * bsc#1251199 Cross-References: * CVE-2025-61984

An update that solves two vulnerabilities can now be installed.

* bsc#1253092 * bsc#1253093 * bsc#1253095 Cross-References:

An update that solves three vulnerabilities can now be installed.

* bsc#1253126 * bsc#1253132 Cross-References: * CVE-2024-25621

Malicious npm package sneaks into GitHub Actions builds
Kernel Panic in Linux: Causes, Diagnosis & Fixes (2025 Guide)
Meta’s SPICE framework pushes AI toward self-learning without human supervision
Bitcoin bandit’s £5B bubble bursts as cops wrap seven-year chase
UK’s Cyber Security and Resilience Bill makes Parliamentary debut
Russian hacker admits helping Yanluowang ransomware infect companies
Aviation watchdog says organized drone attacks will shut UK airports ‘sooner or later’
Node.js tutorial: Get started with Node
Revisiting Mojo: A faster Python?
The economics of the software development business
China hates crypto and scams, but is now outraged USA acquired bitcoin from a scammer
Australia’s spy boss says authoritarian nations ready to commit ‘high-impact sabotage’
Snowflake to acquire Datometry to bolster its automated migration tools
North Korean spies turn Google’s Find Hub into remote-wipe weapon
The AI Fix #76: AI self-awareness, and the death of comedy
Microsoft’s .NET 10 arrives with AI, runtime, and language improvements
EU’s reforms of GDPR, AI slated by privacy activists for ‘playing into Big Tech’s hands’
OWASP Top 10: Broken access control still tops app security list
Hitachi-owned GlobalLogic admits data stolen on 10k current and former staff
UK asks cyberspies to probe whether Chinese buses can be switched off remotely
Cyber insurers paid out over twice as much for UK ransomware attacks last year
UK’s Ajax fighting vehicle arrives – years late and still sending crew to hospital
The dawn of the AI-native database
Agentic coding with Google Jules
Breaking Europe’s cloud deadlock

An update that solves five vulnerabilities and has one security fix can now be installed.

* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208 * bsc#1249847

* bsc#1248631 * bsc#1249207 * bsc#1249208 * bsc#1249847 * bsc#1252946

An update that solves four vulnerabilities and has one security fix can now be installed.

How GlassWorm wormed its way back into developers’ code — and what it says about open source security

This is the October 2025 release of .NET 8. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.21/8.0.121.md Runtime: https://github.com/dotnet/core/blob/main/release-

Update to 141.0.7390.122 High CVE-2025-12036 chromium: Inappropriate implementation in V8 High CVE-2025-11756: Use after free in Safe Browsing High CVE-2025-11458: Heap buffer overflow in Sync High CVE-2025-11460: Use after free in Storage

LLM side-channel attack could allow snoops to guess what you’re talking about
C# rises in Tiobe language popularity index
Critical federal cybersecurity funding set to resume as government shutdown draws to a close – for now
Phishers try to lure 5K Facebook advertisers with fake business pages

An update that solves one vulnerability can now be installed.

* bsc#1249473 Cross-References: * CVE-2025-48041

* bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057

* bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057

An update that solves two vulnerabilities can now be installed.

An update that solves five vulnerabilities and has one security fix can now be installed.

Russian broker pleads guilty to profiting from Yanluowang ransomware attacks
Runtime bugs break container walls, enabling root on Docker hosts
Allianz UK joins growing list of Clop’s Oracle E-Business Suite victims
Hack halts Dutch broadcaster, forcing radio hosts back to LPs
As AI enables bad actors, how are 3,000+ teams responding?
The hidden skills behind the AI engineer
AI is all about inference now
Cisco creating new security model using 30 years of data describing cyber-dramas and saves
Microsoft teases agents that become ‘independent users within the workforce’

https://security-tracker.debian.org/tracker/DSA-6051-1

Data breach at Chinese infosec firm reveals cyber-weapons and target list
Louvre’s pathetic passwords belong in a museum, just not that one

MGASA-2025-0271 – Updated opencontainers-runc packages fix security vulnerabilities

MGASA-2025-0270 – Updated xen packages fix security vulnerabilities

MGASA-2025-0269 – Updated libxml2 & libxslt packages fix security vulnerabilities

MGAA-2025-0092 – Updated qarte packages fix bug

This is the October 2025 release of .NET 9, updating the SDK to version 9.0.111 and runtime to version to 9.0.10. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.10/9.0.111.md

Add CVE and bug fixes to bundled mbedtls in dolphin-emu

In memoriam: David Harley

Former colleagues and friends remember the cybersecurity researcher, author, and mentor whose work bridged the human and technical sides of security

The who, where, and how of APT attacks in Q2 2025–Q3 2025

ESET Chief Security Evangelist Tony Anscombe highlights some of the key findings from the latest issue of the ESET APT Activity Report

Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map
What is generative AI? How artificial intelligence creates content
Microsoft lets shopping bots loose in a sandbox

Rebuild with the latest golang in repos

New upstream stable version 1.22.5

Rebuild with the latest golang in repos

Upgrade to 4.3.4 upstream version. Build with Go 1.24.9 fixes multiple Go CVEs BZ#2408093 BZ#2408688 BZ#2409563 BZ#2410514 BZ#2411412

New version 3.0.2 (rhbz#2407048) Fixes CVE-2025-11232 (rhbz#2407228)

New upstream stable version 1.22.5

Kong Insomnia 12 bolsters AI, MCP tools
Previously unknown Landfall spyware used in 0-day attacks on Samsung phones
ESET APT Activity Report Q2 2025–Q3 2025

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q2 2025 and Q3 2025

Cybercrims plant destructive time bomb malware in industrial .NET extensions

Several security issues were fixed in the Linux kernel.

An update that solves one vulnerability can now be installed.

* bsc#1252749 Cross-References: * CVE-2025-62594

* bsc#1239119 Cross-References: * CVE-2025-30258

An update that solves one vulnerability can now be installed.

Microsoft’s data sovereignty: Now with extra sovereignty!
AWS launches ‘Capabilities by Region’ to simplify planning for cloud deployments
Bank of England says JLR’s cyberattack contributed to UK’s unexpectedly slower GDP growth

The system could be made to expose sensitive information.