Menu

Monthly Archives: December 2025

Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287

upstream stable upgrade from 2.41.1 to 2.41.3 (CVE-2025-14104 and other issues)

Backport fix for CVE-2025-11277

China’s Ink Dragon hides out in European government networks
Azul acquires enterprise Java middleware provider Payara
Analytics provider: We didn’t expose smut site data to crims
Browser ‘privacy’ extensions have eye on your AI, log all your chats
SantaStealer stuffs credentials, crypto wallets into a brand new bag
The AI Fix #81: ChatGPT is the last AI you’ll understand, and your teacher is a deepfake
From pr0n to playlists and paperclips, trio of breaches spills data of millions
MI6 chief: We’ll be as fluent in Python as we are in Russian
Harden your AI systems: Applying industry standards in the real world
5 key agenticops practices to start building now
AWS AI Factories: Innovation or complication?
PwC on using AI to turn cybersecurity risk into competitive advantage
No, SoundCloud hasn’t started tuning out VPNs. It’s mopping up after a cyberattack
Nvidia bets on open infrastructure for the agentic AI era with Nemotron 3
Amazon security boss blames Russia’s GRU for years-long energy-sector hacks

https://security-tracker.debian.org/tracker/DSA-6082-1

China, Iran are having a field day with React2Shell, Google warns
Delay to European Central Bank messaging project cost the Bank of England £23M
JLR: Payroll data stolen in cybercrime that shook UK economy
Apple, Google forced to issue emergency 0-day patches
Denmark takes a Viking swing at VPN-enabled piracy
Man jailed for teaching criminals how to use malware
Legal protection for ethical hacking under Computer Misuse Act is only the first step
InfoWorld’s 2025 Technology of the Year Award winners
Before you build your first enterprise AI app
Starlink claims Chinese launch came within 200 meters of broadband satellite

Fixed aarch64 crashes Updated to latest upstream (146.0)

Fixed aarch64 crashes Updated to latest upstream (146.0)

Update to 143.0.7499.109 * High: Under coordination * Medium CVE-2025-14372: Use after free in Password Manager * Medium CVE-2025-14373: Inappropriate implementation in Toolbar

ruby-sidekiq, a simple, efficient background processing for Ruby, had a couple of vulnerabilities as follows: CVE-2021-30151 Sidekiq allows XSS via the queue name of the live-poll feature when Internet Explorer is used.

A couple of vulnerabilities were reported against ruby-git, a Ruby interface to the Git revision control system, that could lead to a command injection and execution of an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product.

Honeypots can help defenders, or damn them if implemented badly

Multiple vulnerabilities were discovered in the VLC media player, which could result in denial of service or potentially the execution of arbitrary code if a malformed video file is opened. For the oldstable distribution (bookworm), this problem has been fixed in version 3.0.22-0+deb12u1.

An update that solves 5 vulnerabilities can now be installed.

Moderate: grafana security update

Introducing the Red Hat Ansible Lightspeed intelligent assistant
From incident responder to security steward: My journey to understanding Red Hat’s open approach to vulnerability management

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed in version 1:140.6.0esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in

xkbcomp 1.5.0 (CVE-2018-15853, CVE-2018-15859, CVE-2018-15861, CVE-2018-15863)

Fixed CVE-2025-66293 (high severity): Out-of-bounds read in png_image_read_composite. Fixed the Paeth filter handling in the RISC-V RVV implementation. Improved the performance of the RISC-V RVV implementation.

Latest version This build with the latest golang should also fix all the Go CVEs, although I did verify how/if this package is affected by these CVEs.

https://security-tracker.debian.org/tracker/DSA-6081-1

Black Hat Europe 2025: Was that device designed to be on the internet at all?

Behind the polished exterior of many modern buildings sit outdated systems with vulnerabilities waiting to be found

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.6.0esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.

MGASA-2025-0326 – Updated golang packages fix security vulnerabilities

MGAA-2025-0104 – Updated codeblocks packages fix bug

Apply fuse2fs patches that were accidentally empty Update to upstream 1.4.5, including a fix for CVE-2025-65105

Apply fuse2fs patches that were accidentally empty Update to upstream 1.4.5, including a fix for CVE-2025-65105

Apply fuse2fs patches that were accidentally empty Update to upstream 1.4.5, including a fix for CVE-2025-65105

Visual Studio Code adds multi-agent orchestration
Microsoft RasMan DoS 0-day gets unofficial patch – and a working exploit
OpenAI launches GPT-5.2 as it battles Google’s Gemini 3 for AI model supremacy
New React vulns leak secrets, invite DoS attacks
Black Hat Europe 2025: Reputation matters – even in the ransomware economy

Being seen as reliable is good for ‘business’ and ransomware groups care about ‘brand reputation’ just as much as their victims

Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity

If you don’t look inside your environment, you can’t know its true state – and attackers count on that

Microsoft promises more bug payouts, with or without a bounty program
Uncle Sam sues ex-Accenture manager over Army cloud security claims
Gartner tells businesses to block AI browsers now
UK watchdog urged to probe GDPR failures in Home Office eVisa rollout

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. An additional CVE (that has yet to be assigned) is fixed in this release; Google is aware of an expoit in the wild for that issue. For the oldstable distribution (bookworm), these problems have […]

Half of exposed React servers remain unpatched amid active exploitation

This update includes the latest changes to the leap second list, including an update to its expiry date, which was set for the end of December.

PythoC: An alternative to Cython
AWS finally listened to its customers
Rust 1.92 touts deny-by-default never type lints

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

Crypto-crasher Do Kwon jailed for 15 years over $40bn UST bust

https://security-tracker.debian.org/tracker/DSA-6080-1

JetBrains discontinues Fleet IDE
Russian hackers debut simple ransomware service, but store keys in plain text
Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece

Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.

Google fixes super-secret 8th Chrome 0-day
LastPass hammered with £1.2M fine for 2022 breach fiasco
AI vendors move to tackle the hidden cost of inefficient enterprise code
Researcher claims Salt Typhoon spies attended Cisco training scheme
Slash VM provisioning time on Red Hat Openshift Virtualization using Red Hat Ansible Automation Platform
Don’t just automate, validate: How to measure and grow your return on investment

An out-of-bounds read flaw was found in libsndfile’s FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with

10K Docker images spray live cloud creds across the internet

version update security update

1.282 – Sanitize all user-supplied values before inserting into HTTP headers; Fixed CVE-2025-40927.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, same-origin policy bypass or privilege escalation.

Users report chaos as Legal Aid Agency stumbles back online after cyberattack
Document databases – understanding your options
Microsoft’s Dev Proxy puts APIs to the test

Several security issues were fixed in libpng.

Qt could be made to crash or run programs as your login if it opened a specially crafted file.

It’s everyone but Meta in a new AI standards group
Did your npm pipeline break today? Check your ‘classic’ tokens
Smashing Security podcast #447: Grok the stalker, the Louvre heist, and Microsoft 365 mayhem
700+ self-hosted Gits battered in 0-day attacks with no fix imminent
US extradites Ukrainian woman accused of hacking meat processing plant for Russia
Microsoft won’t fix .NET RCE bug affecting slew of enterprise apps, researchers say
The big catch: How whaling attacks target top executives

Is your organization’s senior leadership vulnerable to a cyber-harpooning? Learn how to keep them safe.