Menu

Monthly Archives: December 2025

Spy turned startup CEO: ‘The WannaCry of AI will happen’
Hacktivists scrape 86M Spotify tracks, claim their aim is to preserve culture
Conman and wannabe MI6 agent must repay £125k to romance scam victim
Cursor owner Anysphere agrees to buy Graphite code review tool
Explore 2026 Secure Linux Distros for Enhanced Privacy and Security
Around 1,000 systems compromised in ransomware attack on Romanian water agency
Turning automation spend into a measurable advantage
Attestation vs. integrity in a zero-trust world
8 old programming languages developers won’t quit
6 AI breakthroughs that will define 2026
Building AI agents the safe way

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

There’s so much stolen data in the world, South Korea will require face scans to buy a SIM

It was discovered that usbmuxd, USB multiplexor daemon for iPhone and iPod Touch devices, incorrectly handled certain paths received with the SavePairRecord command. A local attacker could possibly use this issue to delete and write files named *.plist in arbitrary locations. For Debian 11 bullseye, this problem has been fixed in version

Erik Krogh Kristensen and Rasmus Petersen from the GitHub Security Lab discovered a ReDoS (Regular Expression Denial of Service) vulnerability in python-mechanize, a library to automate interaction with websites modeled after the Perl module WWW::Mechanize, which could lead to Denial of Service when parsing a malformed authentication header.

Fixes CVE-2025-58188, unretire package and update to 3.8.2.

Update to pgadmin-9.11, fixes CVE_2025-13780.

Through gritted teeth, Apple and Google allow alternative app stores in Japan
Google sends Dark Web Report to its dead services graveyard
NIST tried to pull the pin on NTP servers after blackout caused atomic clock drift

MGASA-2025-0331 – Updated webkit2 packages fix security vulnerabilities

MGASA-2025-0330 – Updated php packages fix security vulnerabilities

32.0.3 release, fixes RHBZ# 2420196 RHBZ# 2420197 RHBZ# 2420198 RHBZ# 2421368

Update to cef-143.0.10+g8aed01b + chromium-143.0.7499.146 (rhbz#2423482) High CVE-2025-14765: Use after free in WebGPU High CVE-2025-14766: Out of bounds read and write in V8 High CVE-2025-13630: Type Confusion in V8 High CVE-2025-13631: Inappropriate implementation in Google Updater

Update to uriparser-1.0.0, fixes CVE-2025-67899.

fix setpwnam() buffer use [CVE-2025-14104] libblkid: use snprintf() instead of sprintf()

https://security-tracker.debian.org/tracker/DSA-6091-1

https://security-tracker.debian.org/tracker/DSA-6090-1

https://security-tracker.debian.org/tracker/DSA-6089-1

https://security-tracker.debian.org/tracker/DSA-6088-1

https://security-tracker.debian.org/tracker/DSA-6087-1

https://security-tracker.debian.org/tracker/DSA-6086-1

https://security-tracker.debian.org/tracker/DSA-6085-1

SNMP: CACTI Command Execution Risk Advisory for Linux Administrators

Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on

Update to 0.2.8

Update to 2.22.11

Update to 17.0.0 version (#2412270) Update fonttools 4.61.0

Update to 17.0.0 version (#2412270) Update fonttools 4.61.0

Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on

ATM jackpotting gang accused of unleashing Ploutus malware across US
WatchGuard sounds alarm as critical Firebox flaw comes under active attack
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions

Sydney Uni data goes walkabout after criminals raid code repo
Snowflake software update caused 13-hour outage across 10 regions
Enterprise automation resilience with EDB and Red Hat Ansible Automation Platform
Red Hat to acquire Chatterbox Labs: Frequently Asked Questions
Accelerating NetOps transformation with Ansible Automation Platform
HPE tells customers to patch fast as OneView RCE bug scores a perfect 10

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Ministers confirm breach at UK Foreign Office but details remain murky
Faith in the internet is fading among young Brits
AI and cybersecurity: Two sides of the same coin

An update that solves four vulnerabilities can now be installed.

PHP version 8.4.16 (18 Dec 2025) Core: Sync all boost.context files with release 1.86.0. (mvorisek) Fixed bug GH-20435 (SensitiveParameter doesn’t work for named argument passing to variadic parameter). (ndossche)

China turns on a vast experimental network it says is an heir to ARPANET
Amazon blocked 1,800 suspected North Korean scammers seeking jobs
Your car’s web browser may be on the road to cyber ruin
Python type checker ty now in beta
Crypto crooks co-opt stolen AWS creds to mine coins
Kim’s crypto thieving reached a record $2B in 2025
Another bad week for SonicWall as SMA 1000 zero-day under active exploit
FBI dismantles alleged $70M crypto laundering operation

It was discovered that c-ares, a library that performs DNS requests and name resolution asynchronously, does not properly handle termination of queries which may result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 1.34.5-1+deb13u1.

NHS tech supplier probes cyberattack on internal systems
React2Shell exploitation spreads as Microsoft counts hundreds of hacked machines
DVSA’s clapped-out booking system gets bot slapped as new boss rides in
UK surveillance law still full of holes, watchdog warns
Designing the agent-ready data stack
High-performance programming with Java streams
What’s next for Azure infrastructure

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

JetBrains releases Kotlin 2.3.0
Smashing Security podcast #448: The Kindle that got pwned

https://security-tracker.debian.org/tracker/DSA-6084-1

https://security-tracker.debian.org/tracker/DSA-6083-1

Attacks pummeling Cisco AsyncOS 0-day since late November
CEO spills the Tea about massive token farming campaigns
ESET Threat Report H2 2025

A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts

Blockchain company Nomad to repay users under FTC deal after $186M cyberattack
PwC on securing AI: building trust, compliance and confidence at scale
NATO’s battle for cloud sovereignty: Speed is existential
Microsoft security updates breaks MSMQ on older Win systems
England keeping pen and paper exams despite limited digital expansion
What developers call themselves
Surveillance at sea: Cruise firm bans smart glasses to curb covert recording
Django tutorial: Get started with Django 6
Spring Boot tutorial: Get started with Spring Boot

An update that solves one vulnerability, contains one feature and has one security fix can now be installed.

Microsoft deprecates IntelliCode for Visual Studio Code

This update includes the latest upstream release of mod_md, with various bug fixes and enhancements. See https://github.com/icing/mod_md/releases for more information. A fix for the security vulnerability CVE-2025-55753 is also included.

Update to 25.4.0