Menu

Monthly Archives: November 2025

NVIDIA’s GTC 2025 A glimpse into our AI-powered future
How TeamViewer builds enterprise trust through security-first design
AI makes JavaScript programming fun again
We can’t ignore cloud governance anymore
More Django developers turning to AI – report
Malicious npm packages contain Vidar infostealer

https://security-tracker.debian.org/tracker/DSA-6050-1

Gootloader malware back for the attack, serves up ransomware
Google’s cheaper, faster TPUs are here, while users of other AI processors face a supply crunch
Tabnine launches ‘org-native’ AI agent platform
Cisco warns of ‘new attack variant’ battering firewalls under exploit for 6 months
The rising tide of cyber attacks against the UK water sector
“Pay up or we share the tapes”: Hackers target massage parlour clients in blackmail scheme
Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming

How a fast-growing scam is tricking WhatsApp users into revealing their most sensitive financial and other data

The AI Fix #75: Claude’s existential battery crisis, and why ChatGPT is a terrible therapist
You’ll never guess what the most common passwords are. Oh, wait, yes you will
Perplexity’s open-source tool to run trillion-parameter models without costly upgrades
Flaw in React Native CLI opens dev servers to attacks

* bsc#1248004 Cross-References: * CVE-2025-55159

* bsc#1250413 Cross-References: * CVE-2025-9900

* bsc#1252414 * bsc#1252417 * bsc#1252418 * bsc#1252758

* bsc#1252414 * bsc#1252417 * bsc#1252418 * bsc#1252758

An update that solves three vulnerabilities and has one security fix can now be installed.

* bsc#1251194 Cross-References: * CVE-2025-61962

SonicWall fingers state-backed cyber crew for September firewall breach
Google boosts Vertex AI Agent Builder with new observability and deployment tools
Databricks adds customizable evaluation tools to boost AI agent accuracy
Malware-pwned laptop gifts cybercriminals Nikkei’s Slack
Why UK businesses are paying ICO millions for password mistakes you’re probably making right now
Developers don’t care about Kubernetes clusters
Microsoft steers Aspire to a polyglot future
Smashing Security podcast #442: The hack that messed with time, and rogue ransom where negotiators
Mozilla.ai releases universal interface to LLMs

https://security-tracker.debian.org/tracker/DSA-6049-1

Uncle Sam lets Google take Wiz for $32B
How social engineering works | Unlocked 403 cybersecurity podcast (S2E6)

Think you could never fall for an online scam? Think again. Here’s how scammers could exploit psychology to deceive you – and what you can do to stay one step ahead

AMD red-faced over random-number bug that kills cryptographic security
Attackers abuse Gemini AI to develop ‘Thinking Robot’ malware and data processing agent for spying purposes
M&S pegs cyberattack cleanup costs at £136M as profits slump
Famed software engineer DJB tries Fil-C… and likes what he sees
UK agri dept spent hundreds of millions upgrading to Windows 10 – just in time for end of support
How multi-agent collaboration is redefining real-world problem solving
AI and machine learning outside of Python
Some thoughts on AI and coding
A fresh look at the Spring Framework

* bsc#1250413 Cross-References: * CVE-2025-9900

Update to 142.0.7444.59 * High CVE-2025-12428: Type Confusion in V8 * High CVE-2025-12429: Inappropriate implementation in V8 * High CVE-2025-12430: Object lifecycle issue in Media * High CVE-2025-12431: Inappropriate implementation in Extensions

New upstream development version 1.23.10 New upstream development version 1.23.9

add patch to remove dependency upper bound versions remove obsolete patches that updated upper bound versions clean up spec file formatting

uv / python-uv-build 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md Pydantic 2.12.3

uv / python-uv-build 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md Pydantic 2.12.3

Uncle Sam wants to scan your iris and collect your DNA, citizen or not

https://security-tracker.debian.org/tracker/DSA-6048-1

Russian spies pack custom malware into hidden VMs on Windows machines
Consumer Financial Protection Bureau’s security falls apart amid layoffs
Ground zero: 5 things to do after discovering a cyberattack

When every minute counts, preparation and precision can mean the difference between disruption and disaster

This month in security with Tony Anscombe – October 2025 edition

From the end of Windows 10 support to scams on TikTok and state-aligned hackers wielding AI, October’s headlines offer a glimpse of what’s shaping cybersecurity right now

Fraud prevention: How to help older family members avoid scams

Families that combine open communication with effective behavioral and technical safeguards can cut the risk dramatically

Cybersecurity Awareness Month 2025: When seeing isn’t believing

Deepfakes are blurring the line between real and fake and fraudsters are cashing in, using synthetic media for all manner of scams

Recruitment red flags: Can you spot a spy posing as a job seeker?

Here’s what to know about a recent spin on an insider threat – fake North Korean IT workers infiltrating western firms

How MDR can give MSPs the edge in a competitive market

With cybersecurity talent in short supply and threats evolving fast, managed detection and response is emerging as a strategic necessity for MSPs

Cybersecurity Awareness Month 2025: Cyber-risk thrives in the shadows

Shadow IT leaves organizations exposed to cyberattacks and raises the risk of data loss and compliance failures

Gotta fly: Lazarus targets the UAV sector

ESET research analyzes a recent instance of the Operation DreamJob cyberespionage campaign conducted by Lazarus, a North Korea-aligned APT group

SnakeStealer: How it preys on personal data – and how you can protect yourself

Here’s what to know about the malware with an insatiable appetite for valuable data, so much so that it tops this year’s infostealer detection charts

Cybersecurity Awareness Month 2025: Building resilience against ransomware

Ransomware rages on and no organization is too small to be targeted by cyber-extortionists. How can your business protect itself against the threat?

Minecraft mods: Should you ‘hack’ your game?

Some Minecraft mods don’t help build worlds – they break them. Here’s how malware can masquerade as a Minecraft mod.

IT service desks: The security blind spot that may put your business at risk

Could a simple call to the helpdesk enable threat actors to bypass your security controls? Here’s how your team can close a growing security gap.

Cybersecurity Awareness Month 2025: Why software patching matters more than ever

As the number of software vulnerabilities continues to increase, delaying or skipping security updates could cost your business dearly.

AI-aided malvertising: Exploiting a chatbot to spread scams

Cybercriminals have tricked X’s AI chatbot into promoting phishing scams in a technique that has been nicknamed “Grokking”. Here’s what to know about it.

How Uber seems to know where you are – even with restricted location permissions

Is the ride-hailing app secretly tracking you? Not really, but this iOS feature may make it feel that way.

Cybersecurity Awareness Month 2025: Passwords alone are not enough

Never rely on just a password, however strong it may be. Multi-factor authentication is essential for anyone who wants to protect their online accounts from intruders.

The case for cybersecurity: Why successful businesses are built on protection

Company leaders need to recognize the gravity of cyber risk, turn awareness into action, and put security front and center

Beware of threats lurking in booby-trapped PDF files

Looks can be deceiving, so much so that the familiar icon could mask malware designed to steal your data and money.

Manufacturing under fire: Strengthening cyber-defenses amid surging threats

Manufacturers operate in one of the most unforgiving threat environments and face a unique set of pressures that make attacks particularly damaging

New spyware campaigns target privacy-conscious Android users in the UAE

ESET researchers have discovered campaigns distributing spyware disguised as Android Signal and ToTok apps, targeting users in the United Arab Emirates

Cybersecurity Awareness Month 2025: Knowledge is power

We’re kicking off the month with a focus on the human element: the first line of defense, but also the path of least resistance for many cybercriminals

This month in security with Tony Anscombe – September 2025 edition

The past 30 days have seen no shortage of new threats and incidents that brought into sharp relief the need for well-thought-out cyber-resilience plans

Roblox executors: It’s all fun and games until someone gets hacked

You could be getting more than you bargained for when you download that cheat tool promising quick wins

DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception

Malware operators collaborate with covert North Korean IT workers, posing a threat to both headhunters and job seekers

Watch out for SVG files booby-trapped with malware

What you see is not always what you get as cybercriminals increasingly weaponize SVG files as delivery vectors for stealthy malware

Invasion of the message body snatchers! Teams flaw allowed crims to impersonate the boss
Cybercrooks getting violent more often to secure big payouts in Europe

* bsc#1248631 * bsc#1249207 * bsc#1249208 Cross-References:

An update that solves three vulnerabilities can now be installed.

* bsc#1206051 * bsc#1221829 * bsc#1233551 * bsc#1234480 * bsc#1234863

* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208

An update that solves four vulnerabilities can now be installed.

OpenAI API moonlights as malware HQ in Microsoft’s latest discovery

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

Agentic AI is complex, not complicated
10 top devops practices no one is talking about
What is vibe coding? AI writes the code so developers can think big
Diversifying cloud resources is essential
Google’s new query builder to tackle SQL complexity in cloud workload monitoring
China’s president Xi Jinping jokes about backdoors in Xiaomi smartphones
Anthropic experiments with AI introspection
AN0M, the backdoored ‘secure’ messaging app for criminals, is still producing arrests after four years
Google unveils Jules extension for Gemini CLI
MIT Sloan quietly shelves AI ransomware study after researcher calls BS
Ransomware negotiator, pay thyself!