Menu

Monthly Archives: December 2025

Ransomware may have extorted over $2.1 billion between 2022-2024, but it’s not all bad news, claims FinCEN report
Protecting value at risk – the role of a risk operations center

* bsc#1251198 * bsc#1251199 Cross-References: * CVE-2025-61984

* bsc#1238879 Cross-References: * CVE-2025-27516

* bsc#1254132 Cross-References: * CVE-2025-9820

Crisis in Icebergen: How NATO crafts stories to sharpen cyber skills
Four years later, Irish health service offers €750 to victims of ransomware attack

Insufficient validation of incoming notifies over TCP in PDNS Recursor, a resolving name server, could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 5.2.7-0+deb13u1. We recommend that you upgrade your pdns-recursor packages.

Is vibe coding the new gateway to technical debt?
PythoC: A new way to generate C code from Python
Why AI agents are so good at coding

Several vulnerabilities were reported in the libpng PNG library, which could lead to information leaks, denial of service or potentially the execution of arbitrary code if a specially crafted image is processed. For the oldstable distribution (bookworm), these problems have been fixed in version 1.6.39-2+deb12u1.

* bsc#1244485 * bsc#1245878 * bsc#1254227 * bsc#1254430 * bsc#1254431

GitHub Action Secrets aren’t secret anymore: exposed PATs now a direct path into cloud environments
Linux Foundation launches Agentic AI Foundation

https://security-tracker.debian.org/tracker/DSA-6079-1

https://security-tracker.debian.org/tracker/DSA-6078-1

https://security-tracker.debian.org/tracker/DSA-6077-1

https://security-tracker.debian.org/tracker/DSA-6076-1

https://security-tracker.debian.org/tracker/DSA-6075-1

Microsoft reports 7.8-rated zero day, plus 56 more in December Patch Tuesday
How to answer the door when the AI agents come knocking
Porsche panic in Russia as pricey status symbols forget how to car
Privacy concerns raised as Grok AI found to be a stalker’s best friend
California man admits role in $263 million cryptocurrency theft that funded lavish lifestyle
The AI Fix #80: DeepSeek’s cheap GPT-5 rival, Antigravity fails, and why being rude to AI makes it smarter
As humanoid robots enter the mainstream, security pros flag the risk of botnets on legs
AWS is still chasing a cohesive enterprise AI story after re:Invent

Several security issues were fixed in radare2.

* bsc#1241772 * bsc#1250683 * bsc#1253181 * bsc#1253185 * bsc#1253186

UK to Europe: The time to counter Russia’s information war machine is now

python-apt could be made to crash if it opened a specially crafted file.

UK finally vows to look at 35-year-old Computer Misuse Act
Whitehall rejects £1.8B digital ID price tag – but won’t say what it will cost
Amazon Q Developer: Everything you need to know
The hidden cost of Amazon Nova 2

* bsc#1254132 Cross-References: * CVE-2025-9820

An update that solves one vulnerability can now be installed.

* bsc#1250497 Cross-References: * CVE-2025-10922

Researchers spot 700 percent increase in hypervisor ransomware attacks
IBM to buy Confluent to extend its data and automation portfolio

https://security-tracker.debian.org/tracker/DSA-6074-1

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), this problem has been fixed in version 7:7.1.3-0+deb13u1.

AWS takes aim at the PoC-to-production gap holding back enterprise AI
193 cybercrims arrested, accused of plotting ‘violence-as-a-service’
UK moves to strengthen undersea cable defenses as Russian snooping ramps up
Home Office kept police facial recognition flaws to itself, UK data watchdog fumes
Barts Health seeks High Court block after Clop pillages NHS trust data
10 MCP servers for devops
AI memory is really a database problem
Block all AI browsers for the foreseeable future: Gartner
China’s first reusable rocket explodes, but its onboard Ethernet network flew
Apache warns of 10.0-rated flaw in Tika metadata ingestion tool

Multiple vulnerabilties have been found in libpng, the official PNG reference library, allowing information disclosure via out-of-bounds read, denial of service via application crash, or heap corruption with potential for arbitrary code execution.

Update to 2.9.7

Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287

Update to 2.9.7

https://security-tracker.debian.org/tracker/DSA-6073-1

Solving tool overload, one automation step at a time
Red Hat OpenShift sandboxed containers 1.11 and Red Hat build of Trustee 1.0 accelerate confidential computing across the hybrid cloud
CIS publishes hardening guidance for Red Hat OpenShift Virtualization
AI ambitions meet automation reality: The case for a unified automation platform
From vision to reality: A 5-step playbook for unified automation and AI
Death to one-time text codes: Passkeys are the new hotness in MFA

Loading a manipulated TGA file in krita, an image manipulation program, could result in a heap-based buffer overflow in KisTgaImport.

Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials

Fix CVE-2025-12744

Update to cef-142.0.17+g60aac24 & chromium 142.0.7444.175 (rhbz#2413981) High CVE-2025-13223: Type Confusion in V8 High CVE-2025-13224: Type Confusion in V8

Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials

Fix CVE-2025-12744

Crims using social media images, videos in ‘virtual kidnapping’ scams
Novel clickjacking attack relies on CSS and SVG
Cloudflare blames Friday outage on borked fix for React2shell vuln

https://security-tracker.debian.org/tracker/DSA-6072-1

https://security-tracker.debian.org/tracker/DSA-6071-1

Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture

Identity is effectively the new network boundary. It must be protected at all costs.

Asus supplier hit by ransomware attack as gang flaunts alleged 1 TB haul
Beijing-linked hackers are hammering max-severity React bug, AWS warns
AI in CI/CD pipelines can be tricked into behaving badly
UK pushes ahead with facial recognition expansion despite civil liberties backlash

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Bots, bias, and bunk: How can you tell what’s real on the net?
All I want for Christmas is a server-side JavaScript framework
Local clouds shape Europe’s AI future
Secure Boot: Strengthening Linux System Integrity from the Firmware Up

Update to security release 4.3.5a

Rebuilt with latest patched stb_image: memory-safety fixes

An AI for an AI: Anthropic says AI agents require AI defense
PRC spies Brickstormed their way into critical US networks and remained hidden for years
Hegseth needs to go to secure messaging school, report says

https://security-tracker.debian.org/tracker/DSA-6069-1

Twins who hacked State Dept hired to work for gov again, now charged with deleting databases
‘Futuristic’ Unison functional language debuts
Why the record-breaking 30 Tbps DDoS attack should concern every business
OpenAI to acquire AI training tracker Neptune
Microsoft quietly shuts down Windows shortcut flaw after years of espionage abuse
FBI warns of surge in account takeover (ATO) fraud schemes – what you need to know