Menu

Monthly Archives: December 2025

Aisuru botnet turns Q3 into a terabit-scale stress test for the entire internet

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

A proactive defense against npm supply chain attacks
Spring AI tutorial: Get started with Spring AI
The first building blocks of an agentic Windows OS

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43392

TLS 1.3 includes welcome improvements, but still allows long-lived secrets
Rust core library partly polished for industrial safety spec

Rebuilt with stb_image patched for two new security bugs.

Patch two newly-reported memory-safety bugs in stb_image: https://github.com/nothings/stb/issues/1860 https://github.com/nothings/stb/issues/1861

Microsoft steers native port of TypeScript to early 2026 release
Smashing Security podcast #446: A hacker doxxes himself, and social engineering-as-a-service
Developers urged to immediately upgrade React, Next.js

https://security-tracker.debian.org/tracker/DSA-6070-1

‘Exploitation is imminent’ as 39 percent of cloud environs have max-severity React hole

https://security-tracker.debian.org/tracker/DSA-6068-1

https://security-tracker.debian.org/tracker/DSA-6067-1

MuddyWater: Snakes by the riverbank

MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook

Mistral targets lightweight processors with its biggest open model yet
AWS introduces powers for AI-powered Kiro IDE
AWS offers new service to make AI models better at work

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

KDE Connect could allow authentication of impersonated devices.

Frequently asked questions about Red Hat Ansible Automation Platform 2.6
Confidential computing on AWS Nitro Enclave with Red Hat Enterprise Linux
Tracking event-driven automation with Red Hat Lightspeed and Red Hat Ansible Automation Platform 2.6
9 strategic articles defining the open hybrid cloud and AI future
Integrating Red Hat Lightspeed in 2025: From observability to actionable automation
Automation unleashed: Introducing the new Red Hat Certified Ansible Collection amazon.ai for generative AI

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The complete guide to Node.js frameworks
A first look at Google’s new Antigravity IDE
Seven coding domains no developer really understands
Here’s your worst nightmare: E-tailer can only resume partial sales 45 days after ransomware attack
Indian government reveals GPS spoofing at eight major airports
Get poetic in prompts and AI will break its guardrails
The AI Fix #79: Gemini 3, poetry jailbreaks, and do we even need safe robots?
AWS Transform now supports agentic modernization of custom code
Two Android 0-day bugs disclosed and fixed, plus 105 more to patch
Asahi cyber attack spirals into massive data breach impacting almost 2 million people
University of Pennsylvania joins list of victims from Clop’s Oracle EBS raid
Oversharing is not caring: What’s at stake if your employees post too much online

From LinkedIn to X, GitHub to Instagram, there are plenty of opportunities to share work-related information. But posting could also get your company into trouble.

AWS unveils Frontier AI agents for software development
Europol nukes Cryptomixer laundering hub, seizing €25M in Bitcoin
Kensington and Chelsea confirms IT outage was a data breach after all
FTC schools edtech outfit after intruder walked off with 10M student records
Why data contracts need Apache Kafka and Apache Flink
How to ensure your enterprise data is ‘AI ready’
The ripple effects of a VPN ban
Out-of-Bounds Read Bugs Add Quiet Pressure on Linux Security
India demands smartphone makers install a government app on every handset

Several security issues were fixed in CRaC JDK 17.

Several security issues were fixed in CRaC JDK 25.

Several security issues were fixed in CRaC JDK 21.

update to version 2.25.2

Update to 1.24.2 (rhbz#2417261) Additional fix for CVE-2025-11411 https://nlnetlabs.nl/projects/unbound/download/#unbound-1-24-2

Prevent unsafe URI schemes from participating in media playback. Make jsc_value_array_buffer_get_data() function introspectable. Fix logging in to Google accounts that have a WebAuthn second factor configured. Fix loading webkit://gpu when there are no threads configured for GPU rendering. Fix rendering gradients that use the CSS hue interpolation method.

Qdrant vector database adds tiered multitenancy
Stealthy browser extensions waited years before infecting 4.3M Chrome, Edge users with backdoors and spyware
Four arrested in South Korea over massive IP camera snooping spree
Contagious Interview attackers go ‘full stack’ to fool you
Dutch study finds teen cybercrime is mostly just a phase
South Korea’s answer to Amazon admits breach exposed 33.7M customers
French Football Federation faces own-goal after club software data breach
How to succeed as an independent software developer
How much will openness matter to AI?

A local file inclusion vulnerability has been discovered in mistral- dashboard, the OpenStack Workflow as a Service dashboard plugin, that may result in disclosure of arbitrary local files content through the

A local file inclusion vulnerability has been discovered in python- mistralclient, the OpenStack Workflow as a Service client, that may result in disclosure of arbitrary local files content through the

Google and Apple ordered to stop fake government TXTs

Multiple vulnerabilities have been discovered in Pagure, a Git-centered code hosting system (forge).

A possible remote code execution (RCE) vulnerability has been discovered in pytorch, an open source machine learning framework.

Update to pgadmin-9.10

Update to 2.86.2 Fix CVE-2025-13601 or #YWH-PGM9867-134

Swiss government says give M365, and all SaaS, a miss as it lacks end-to-end encryption