Menu

Category Archives: All

Everything

If you thought China’s Salt Typhoon was booted off critical networks, think again
What Is a Privilege Escalation Vulnerability?

https://security-tracker.debian.org/tracker/DSA-5989-1

ChatGPT hates LA Chargers fans
Smashing Security podcast #432: Oops! I auto-filled my password into a cookie banner
Sting nails two front firms in Nork IT worker scam
Crims laud Claude to plant ransomware and fake IT expertise
Putin on the code: DoD reportedly relies on utility written by Russia-based Yandex dev
Nx NPM packages poisoned in AI-assisted supply chain attack
The intruder is in the house: Storm-0501 attacked Azure, stole data, demanded payment via Teams
Cephalus ransomware: What you need to know
Salesforce data missing? It might be due to Salesloft breach, Google says
Linux Rootkits: Detecting, Preventing, and Surviving an Attack

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Who are you again? Infosec experiencing ‘Identity crisis’ amid rising login attacks
The discipline of great code
Hands-on with Solid: Reactive programming with signals
BGP’s security problems are notorious. Attempts to fix that are a work in progress
Google issued ‘State-backed attack in progress’ warnings after spotting web hijack scheme
MariaDB buys back the company it sold two years ago

fix CVE-2025-9165: memory leak in tiffcmp (rhbz#2389608)

Update to upstream version 0.2.8 Update idna dependency to a version not affected by CVE-2024-12224

fix CVE-2025-8534: null pointer dereference in tiff2ps (rhbz#2386494) fix CVE-2024-13978: null pointer dereference in tiff2pdf (rhbz#2386201)

Microsoft unveils Proxy 4 library for polymorphic coding in C++
First AI-powered ransomware spotted, but it’s not active – yet
Critical Docker Desktop flaw allows container escape
Azure apparatchik shows custom silicon keeping everything locked down
DOGE accused of duplicating critical Social Security database on unsecured cloud
ZipLine attack uses ‘Contact Us’ forms, White House butler pic to invade sensitive industries
Citrix patches trio of NetScaler bugs – after attackers beat them to it
The AI Fix #65: Excel Copilot will wreck your data, and can AI fix social media?
Yemen Cyber Army hacker jailed after stealing millions of people’s data
Crypto thief earns additional prison time for assaulting witness
Broadcom launches VMware Tanzu Data Intelligence and Tanzu Platform 10.3 to drive agentic AI
Broadcom and Canonical expand partnership, promising accelerated innovation

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

* bsc#1248119 * bsc#1248120 * bsc#1248122 Cross-References:

* bsc#1248119 * bsc#1248120 * bsc#1248122 Cross-References:

Alleged mastermind behind K-Pop celebrity stock heist extradited to South Korea
Farmers Insurance harvests bad news: 1.1M customers snared in data breach
How does AI affect cloud attack vectors?
How to avoid the risks of rapidly deploying AI agents
A wake-up call for identity security in devops
Malware-ridden apps made it into Google’s Play Store, scored 19 million downloads

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5986-1

Visual Studio Code update auto-starts MCP servers

Americans aged 60 and older lost $4.8 billion in 2024 to scammers, according to a report released by the FBI. These figures represent real people, real families, and life-changing financial devastation. The impact extends beyond just the numbers. The average loss among people over the age of 60 was $83,000, more than four times the […]

Databricks buys Tecton to give context to AI agents

* bsc#1232234 * bsc#1246221 Cross-References: * CVE-2024-10041

* bsc#1232234 * bsc#1246221 Cross-References: * CVE-2024-10041

* bsc#1234018 * bsc#1234019 * bsc#1234020 * bsc#1245313 * bsc#1246790

* bsc#1239547 * bsc#1239863 * bsc#1239864 * bsc#1247562 * bsc#1247563

Securing AI workloads in Azure: A zero-trust architecture for MLOps
Enterprise essentials for generative AI
What alternative clouds are good for
Australian university used Wi-Fi location data to identify student protestors
AWS, Cloudflare, Digital Ocean, and Google helped Feds investigate alleged Rapper Bot DDoS perp

https://security-tracker.debian.org/tracker/DSA-5985-1

Bug bounties: The good, the bad, and the frankly ridiculous ways to do it

Security fixes Bumped the minimum github.com/go-viper/mapstructure/v2 version to 2.3.0 for GHSA-fv92-fjc5-jj9h or GO-2025-3787 Bumped the minimum github.com/NVIDIA/nvidia-container-toolkit version to 1.17.8 for CVE-2025-23266 and CVE-2025-23267

How RingReaper Linux Malware Exploits io_uring to Evade EDR Systems

https://security-tracker.debian.org/tracker/DSA-5984-1

“What happens online stays online” and other cyberbullying myths, debunked

Separating truth from fiction is the first step towards making better parenting decisions. Let’s puncture some of the most common misconceptions about online harassment.

The need for speed: Why organizations are turning to rapid, trustworthy MDR

How top-tier managed detection and response (MDR) can help organizations stay ahead of increasingly agile and determined adversaries

Blue Locker ransomware hits critical infrastructure – is your organisation ready?

Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix

Update to release v1.33.4 Resolves: rhbz#2388412 Fixes CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Update to 1.67.0 Update to 1.66.0

Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix

Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Microsoft adds MCP support to Visual Studio to boost development of agentic applications
Short circuit: Electronics supplier to tech giants suffers ransomware shutdown
Kidney dialysis giant DaVita tells 2.4M people they were snared in ransomware data theft nightmare
Criminal background checker APCS faces data breach
Fake CAPTCHA tests trick users into running malware
Europol says Telegram post about 50,000 Qilin ransomware award is fake
Interpol bags 1,209 suspects, $97M in cybercrime operation focused on Africa

* bsc#1248006 Cross-References: * CVE-2025-55159

Several security issues were fixed in PHP.

From cloud migration to cloud optimization
Generative AI dos, don’ts, and ‘undos’

* bsc#1248006 Cross-References: * CVE-2025-55159

Anthropic adds Claude Code to its Claude enterprise plans

Several security issues were fixed in Python.

Update to version 0.4.11. This version includes a fix for CVE-2025-55159, but there are zero packages in Fedora or EPEL that use the affected API, so no rebuilds are necessary.

Update to v1.136.0 Update to 1.135.2 Update to 1.135.0

Developer jailed for taking down employer’s network with kill switch malware

https://security-tracker.debian.org/tracker/DSA-5983-1