Menu

Category Archives: All

Everything

Cloud and IT strategies in a time of global upheaval
Scammers are deepfaking voices of senior US government officials, warns FBI
DoorDash scam used fake drivers, phantom deliveries to bilk $2.59M
Uno Platform introduces unified rendering engine

https://security-tracker.debian.org/tracker/DSA-5919-1

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Cyber fiends battering UK retailers now turn to US stores
Coinbase extorted for $20M. Support staff bribed. Customers scammed. One hell of a breach disclosure…
Socket buys Coana to tell you which security alerts you can ignore
Snowflake CISO on the power of ‘shared destiny’ and ‘yes and’
LiteLLM: An open-source gateway for unified LLM access
Accessibility in Microsoft Edge with ARIA and ARIA Notify

* bsc#1218424 * bsc#1236045 * bsc#1236046 * bsc#1236801 * jsc#SLE-18320

Here’s what we know about the DragonForce ransomware that hit Marks & Spencer

Update to 1.9.9 to fix CVE-2025-30194

Update to 1.9.9 to fix CVE-2025-30194

Databricks to acquire open-source database startup Neon to build the next wave of AI agents

https://security-tracker.debian.org/tracker/DSA-5920-1

.NET 10 Preview 4 enhances Zip processing, JIT compilation, Blazor WebAssembly
Smashing Security podcast #417: Hello, Pervert! – Sextortion scams and Discord disasters
Metal maker meltdown: Nucor stops production after cyber-intrusion

It was discovered that insecure file handling in open-vm-tools, an open source implementation of VMware Tools, may allow an unprivileged local guest user to tamper local files to trigger insecure file operations within that VM.

* bsc#1230959 * bsc#1231748 * bsc#1232326 * bsc#1240366 * bsc#1240607

Why CVSS is failing us and what we can do about it
Uncle Sam pulls $2.4B Leidos deal to support CISA after rival alleges foul play
How can we counter online disinformation? | Unlocked 403 cybersecurity podcast (S2E2)

Ever wondered why a lie can spread faster than the truth? Tune in for an insightful look at disinformation and how we can fight one of the most pressing challenges facing our digital world.

Ivanti patches two zero-days under active attack as intel agency warns customers
Meta’s still violating GDPR rules with latest plan to train AI on EU user data, says noyb
VPN Secure parent company CEO explains why he had to axe thousands of ‘lifetime’ deals
Two years’ jail for down-on-his-luck man who sold ransomware online
Boomi launches agentic AI tools, announces AWS collaboration
Informatica adds agents to automate its Intelligent Data Management Cloud
Go ahead and ignore Patch Tuesday – it might improve your security
Everyone’s deploying AI, but no one’s securing it – what could go wrong?
How to use template strings in Python 3.14
The three refactorings every developer needs most

A vulnerability has been discovered in FreeType, which can lead to remote code execution.

Abseil could be made to crash if it received specially crafted input.

Ransomware scum have put a target on the no man’s land between IT and operations
Scala stabilizes named tuples

Update to 136.0.7103.92 CVE-2025-4372: Use after free in WebAudio

Apple patched one first, but Microsoft’s blasted five exploited flaws this Pa-Tu

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Intel’s data-leaking Spectre defenses scared off yet again
Qatar’s $400M jet for Trump is a gold-plated security nightmare
Commvault fixes critical Command Center issue after flaw finder alert
The AI Fix #50: AI brings dead man back for killer’s trial, and the judge loves it
‘We still have embeds in CISA’: CTO of Brit cyber agency talks post-Trump relationship with US counterpart
4 key capabilities of Kong’s Event Gateway for real-time event streams
Emerging ClickFix Attacks Are Now Targeting Linux Systems
Marks & Spencer admits cybercrooks made off with customer info
Google to unveil AI agent for developers at I/O, expand Gemini integration
As US vuln-tracking falters, EU enters with its own security bug database
Agentic mesh: The future of enterprise agent ecosystems
How to use genAI for requirements gathering and agile user stories
What ‘cloud first’ can teach us about ‘AI first’

* bsc#1242008 * bsc#1242009 Cross-References: * CVE-2025-31650

Several security issues were fixed in the Linux kernel.

Türkiye-linked spy crew exploited a messaging app zero-day to snoop on Kurdish army in Iraq

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5918-1

M365 apps on Windows 10 to get security fixes into 2028
C# 14 introduces extension members
CISA mutes own website, shifts routine cyber alerts to Musk’s X, RSS, email
Why aggregating your asset inventory leads to better security
Attackers pwn charter airline helping Trump’s deportation campaign

Unlimited output buffer for unauthenticated clients has been fixed in the key¢”value database Redis. For Debian 11 bullseye, this problem has been fixed in version

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

A vulnerability has been discovered in Orc, which can lead to arbitrary code execution

Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in arbitrary code execution.

Britain’s cyber agents and industry clash over how to tackle shoddy software
What software developers need to know about cybersecurity
How to build (real) cloud-native applications
MySQL at 30: Still important but no longer king
Unending ransomware attacks are a symptom, not the sickness
DOGE worker’s old creds found exposed in infostealer malware dumps
You think ransomware is bad now? Wait until it infects CPUs

PDF signature forgery with adbe.pkcs7.sha1 SubFilter. (CVE-2025-2866) References: – https://bugs.mageia.org/show_bug.cgi?id=34234 – https://lists.debian.org/debian-security-announce/2025/msg00070.html

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on

Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function. (CVE-2025-31162) Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.

https://deluge.readthedocs.io/en/deluge-2.2.0/changelog.html 2.2.0 (2025-04-28) Breaking changes Removed Python 3.6 support (Python >= 3.7) Core

5.22.9

Update to version 22.15.0

GenAI isn’t taking software engineering jobs, but it is reshaping leadership roles
Catching a phish with many faces

Here’s a brief dive into the murky waters of shape-shifting attacks that leverage dedicated phishing kits to auto-generate customized login pages on the fly

Feds disrupt proxy-for-hire botnet, indict four alleged net miscreants
UK Ministry of Defence is spending less with US biz, and more with Europeans
Visual Studio Code beefs up AI coding features

Update to 47.7 notably fixing CVE-2025-3839

xz 5.8.1

xz 5.8.1

xz 5.8.1