Menu

Category Archives: All

Everything

New Supply Chain Attack Targets Telegram Bots

Multiple vulnerabilities have been fixed in the fig2dev utilities for converting XFig figure files. CVE-2025-31162

What GitHub can tell us about the future of open source
Understanding application modernization
Data mesh vs. data fabric vs. data virtualization: There’s a difference

Mishandling of semicolons in the userinfo subcomponent of a URI has been fixed in GNU Wget, a utility for retrieving files over HTTP, HTTPS, FTP and FTPS.

USN-6200-2 introduced a regression in ImageMagick.

Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB

rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered. See https://www.arin.net/announcements/20250116-tal/ rpki-client reports Certification Authorities that do not meaningfully participate in the RPKI as non-functional CAs. By definition, a CA is non-

release v1.16.0

By the numbers: Security insights from Red Hat and IBM

Several vulnerabilities were discovered in the Erlang/OTP implementation of the SSH protocol, which may result in denial of service or the execution of arbitrary code.

Fix bz2358011

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.

https://security-tracker.debian.org/tracker/DSA-5906-1

Dems fret over DOGE feeding sensitive data into random AI
Hacking US crosswalks to talk like Zuck is as easy as 1234

https://security-tracker.debian.org/tracker/DSA-5905-1

https://security-tracker.debian.org/tracker/DSA-5904-1

Several vulnerabilities were discovered in the shadow suite of login tools. An attacker may extract a password from memory in limited situations, and confuse an administrator inspecting /etc/passwd from within a terminal.

New libxml2 packages are available for Slackware 15.0 and -current to fix security issues.

CapCut copycats are on the prowl

Cybercriminals lure content creators with promises of cutting-edge AI wizardry, only to attempt to steal their data or hijack their devices instead

They’re coming for your data: What are infostealers and how do I stay safe?

Here’s what to know about malware that raids email accounts, web browsers, crypto wallets, and more – all in a quest for your sensitive data

Oracle hopes talk of cloud data theft dies off. CISA just resurrected it for Easter
Google previews Gemini 2.5 Flash hybrid reasoning model

* bsc#1241150 Cross-References: * CVE-2025-32460

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

CVE fallout: The splintering of the standard vulnerability tracking system has begun
JetBrains IDEs now include AI tools by subscription
How U.S. tariffs could impact cloud computing
Learning how to measure genAI’s impact
Krebs throws himself on the grenade, resigns from SentinelOne after Trump revokes clearances
Onehouse opens up the lakehouse with Open Engines

* bsc#1240958 * bsc#1240961 * bsc#1240962 * bsc#1240963 * bsc#1240964

* bsc#1240893 Cross-References: * CVE-2025-31492

* bsc#1240971 Cross-References: * CVE-2025-32464

* bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364

Expired US Funding Threatened to Disrupt Security Flaw Tracking
Brit soldiers tune radio waves to fry drone swarms for pennies
Headlamp: A multicluster management UI for Kubernetes
Enter the parallel universe of Java’s Vector API
Whistleblower describes DOGE IT dept rampage at America’s labor watchdog

https://security-tracker.debian.org/tracker/DSA-5903-1

Smashing Security podcast #413: Hacking the hackers… with a credit card?
Gleam 1.10 improves compiler, JavaScript codegen
Free Blue Screens of Death for Windows 11 24H2 users
Signalgate chats vanish from CIA chief phone
Identifying the cyber risks that matter
CVE program gets last-minute funding from CISA – and maybe a new home
Attacks on the education sector are surging: How can cyber-defenders respond?

Academic institutions have a unique set of characteristics that makes them attractive to bad actors. What’s the right antidote to cyber-risk?

Law firm ‘didn’t think’ data theft was a breach, says ICO. Now it’s nursing a £60K fine

* bsc#1239826 * jsc#MSQA-936 Cross-References: * CVE-2025-23392

* bsc#1240893 Cross-References: * CVE-2025-31492

* bsc#1239863 * bsc#1239864 * bsc#1240958 * bsc#1240961 * bsc#1240962

* bsc#1224295 * bsc#1234840 * bsc#1239308 Cross-References:

* bsc#1239649 Cross-References: * CVE-2024-12088

Russians lure European diplomats into malware trap with wine-tasting invite
Insurance firm Lemonade warns of breach of thousands of driving license numbers
The programming language wars
6 languages you can deploy to WebAssembly right now
Guess what happens when ransomware fiends find ‘insurance’ ‘policy’ in your files
Uncle Sam abruptly turns off funding for CVE program. Yes, that CVE program
JRuby 10 brings faster startup times
Now 1.6M people had SSNs, life chapter and verse stolen from insurance IT biz
4chan, the ‘internet’s litter box,’ appears to have been pillaged by rival forum
China names alleged US snoops over Asian Winter Games attacks
All right, you can have one: DOGE access to Treasury IT OK’d judge
OpenAI GPT-4.1 models promise improved coding and instruction following
RansomHouse ransomware: what you need to know
The AI Fix #46: AI can read minds now, and is your co-host a clone?
Chinese snoops use stealth RAT to backdoor US orgs – still active last week

* bsc#1065729 * bsc#1179878 * bsc#1180814 * bsc#1185762 * bsc#1195823

* bsc#1240971 Cross-References: * CVE-2025-32464

* bsc#1240958 * bsc#1240961 * bsc#1240962 * bsc#1240963 * bsc#1240964

* bsc#1228714 * bsc#1232818 * bsc#1235218 * bsc#1238788 * bsc#1238790

ActiveX blocked by default in Microsoft 365 because remote code execution is bad, OK?
Where it Hertz: Customer data driven off in Cleo attacks
Google’s bold step toward hybrid AI integration
Measuring success in dataops, data governance, and data security
EU gives staff ‘burner phones, laptops’ for US visits
Don’t delete that mystery empty folder. Windows put it there as a security fix
Microsoft .NET Aspire adds resource graph, publishers
New SSL/TLS certs to each live no longer than 47 days by 2029
Cyber congressman demands answers before CISA gets cut down to size

Perl could be made to crash or run programs if it processed specially crafted data.