Menu

Monthly Archives: December 2025

An update that solves three vulnerabilities can now be installed.

European Space Agency hit again as cybercrims claim 200 GB data up for sale
Intro to Hotwire: HTML over the wire
Hong Kong’s newest anti-scam technology is over-the-counter banking

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

NSA: Managing Secure Boot for Linux Against Bootchain Attacks

An update that fixes one vulnerability is now available.

Cybersecurity pros admit to moonlighting as ransomware scum

Update to 1.1.97

Update to 5.8.0

New York’s incoming mayor bans Raspberry Pi at his inauguration party
An early end to the holidays: ‘Heartbleed of MongoDB’ is now under active exploit
This month in security with Tony Anscombe – December 2025 edition

As 2025 draws to a close, Tony looks back at the cybersecurity stories that stood out both in December and across the whole of this year

Nvidia licenses Groq’s inferencing chip tech and hires its leaders

A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file. For Debian 11 bullseye, this problem has been fixed in version

How to build RAG at scale
2026: The year we stop trusting any single cloud

An update that solves four vulnerabilities can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

An update that solves one vulnerability and has one security fix can now be installed.

Korean telco failed at femtocell security, exposed customers to snooping and fraud

Rebuild for CVEs

Rebuilt for CVE-2025-61723

Indian cops cuff ex-Coinbase rep over selling customer info to crims
Understanding AI-native cloud: from microservices to model-serving
Crims disconnect Wired subscribers from their privacy, publish deets online
React2Shell: Anatomy of a max-severity flaw that sent shockwaves through the web
Europe’s cloud challenge: Building an Airbus for the digital age
4 New Year’s resolutions for devops success
AI’s trust tax for developers
Accused data thief threw MacBook into a river to destroy evidence
Exploring AI Agents’ Influence on Linux Security Threats and Administration

Multiple vulnerabilities have been discovered in Kodi, a media-player and entertainment hub. CVE-2023-23082 A heap buffer overflow vulnerability in Kodi allows attackers to cause a denial of service due to an improper length of the value

Death, torture, and amputation: How cybercrime shook the world in 2025

Update to 2.5.2 Fix for CVE-2025-68617

Update to 1.4.6: fixes CVE-2025-13654

Update to 2.1.0. Update bundled libpng, libtiff, to latest versions. Built against TCL/TK 9. Fix FTBFS.

Update to 5.32.0

Update to 2.1.0. Update bundled libpng, libtiff, to latest versions. Built against TCL/TK 9. Fix FTBFS.

Update to 5.32.0

Upgrade to 4.3.6 upstream version.

Upgrade to 4.3.6 upstream version.

An update that fixes one vulnerability is now available.

MGAA-2025-0106 – Updated nvidia-current & ldetect-lst packages fix bug

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

High severity flaw in MongoDB could allow memory leakage
From AI to analog, cybersecurity tabletop exercises look a little different this year
From video games to cyber defense: If you don’t think like a hacker, you won’t win

Vulnerabilities were found in python-urllib3, an HTTP library with thread-safe connection pooling for Python, which could lead to denial of service or request forgery. CVE-2025-50181 Redirects were not disabled when retries are disabled on PoolManager

Reader picks: The most popular Python stories of 2025

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

A couple of vulnerabilities were discovered in postgresql-13, the widely-popular database management system: CVE-2025-12817 Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other

Update to 0.50.2

Update to release v0.26.3 Resolves CVE-2024-25621: rhbz#2419004, rhbz#2419033, rhbz#2419427 Upstream fix

Update to 2.68.1

A small language model blueprint for automation in IT and HR

Update to 1.22.0

Release 1.6.12 Support IPv6 in database DSN (#9937) Don’t force specific error_reporting setting Fix compatibility with PHP 8.5 regarding array_first() Remove X-XSS-Protection example from .htaccess file (#9875)

version update security update

Update to 1.22.0

Release 1.6.12 Support IPv6 in database DSN (#9937) Don’t force specific error_reporting setting Fix compatibility with PHP 8.5 regarding array_first() Remove X-XSS-Protection example from .htaccess file (#9875)

An update that solves 65 vulnerabilities and has nine security fixes can now be installed.

Pen testers accused of ‘blackmail’ after reporting Eurostar chatbot flaws
A brush with online fraud: What are brushing scams and how do I stay safe?

Have you ever received a package you never ordered? It could be a warning sign that your data has been compromised, with more fraud to follow.

Microsoft is not rewriting Windows in Rust
US shuts down phisherfolk’s $14.6M password-hoarding platform
AI power tools: 6 ways to supercharge your terminal
Get started with Python’s new native JIT
Microsoft wants to replace its entire C and C++ codebase, perhaps by 2030
Deno adds tool to run NPM and JSR binaries
Rust vision group seeks enumeration of language design goals
ServiceNow opens $7.7B ticket titled ‘Buy security company, make it Armis’

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component

A comprehensive analysis and assessment of a critical severity vulnerability with low likelihood of mass exploitation

21K Nissan customers’ data stolen in Red Hat raid
Microsoft rushes an out-of-band update for Message Queuing bug
The AI Fix #82: Santa Claus doesn’t exist (according to AI)
WhatsApp API worked exactly as promised, and stole everything
Linux Kernel Encryption Changes Prevent Physical Hardware Attacks
Why IPv6 Influences Linux Firewall Behavior and Exposure Risks
React2Shell: How a Framework Bug Drives Full Linux Compromise
When is an AI agent not really an agent?

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves 65 vulnerabilities and has 11 security fixes can now be installed.

An update that solves 65 vulnerabilities and has 11 security fixes can now be installed.

An update that solves eight vulnerabilities and has two security fixes can now be installed.

An update that solves eight vulnerabilities and has two security fixes can now be installed.

Stop letting ‘urgent’ derail delivery. Manage interruptions proactively
Microsoft previews C++ code editing tools for GitHub Copilot
Poisoned WhatsApp API package steals messages and accounts
Palo Alto’s new Google Cloud deal boosts AI integration, could save on cloud costs