Menu

Category Archives: All

Everything

* bsc#1240416 Cross-References: * CVE-2025-31344

Net::EasyTCP Perl module includes encryption functionality that requires a secure random number generator. Until and including the version 0.26, this module used a random number generator without any such guarantees. The reason for this was that it relied on Crypt::Random, a Perl module

Russian bots hard at work spreading political unrest on Romania’s internet
Visual Studio Code stabilizes agent mode

Prior to version 0.008, the Perl module Data::Entropy relied on Perl’s builtin rand function to choose an entropy source. Version 0.008 does away with this need.

As CISA braces for more cuts, threat intel sharing takes a hit
Warning to developers: Stay away from these 10 VSCode extensions
Oracle says its cloud was in fact compromised

https://security-tracker.debian.org/tracker/DSA-5897-1

Cloudflare unveils agentic AI development tools
Kotlin, Swift, and Ruby losing popularity – Tiobe index
That massive GitHub supply chain attack? It all started with a stolen SpotBugs token
Alleged Scattered Spider SIM-swapper must pay back $13.2M to 59 victims
Chrome to patch decades-old flaw that let sites peek at your history
UK’s attempt to keep details of Apple ‘backdoor’ case secret… denied
King Bob pleads guilty to Scattered Spider-linked cryptocurrency thefts from investors

* bsc#1236217 * bsc#1239182 * bsc#1240550 Cross-References:

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

* bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029

AI demands more software developers, not less
Language models in generative AI – does size matter?
10 Java-based tools and frameworks for generative AI
What native cloud security tools won’t catch
Asian tech players react to US tariffs with delays, doubts, deal-making
Signalgate solved? Report claims journalist’s phone number accidentally saved under name of Trump official

5.0.0

Update to 0.4.8; Fixes: RHBZ#2237964, RHBZ#2282129

Fix CVE-2024-12905.

Address CVE-2025-30093 – rhbz#2355671

5.0.0

Fix CVE-2024-12905.

Red Hat OpenShift and zero trust: Securing workloads with cert-manager and OpenShift Service Mesh

Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions

Backport fixes from v1.127.1

This is an update fixing CVE 2025-30232.

Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions

CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355026) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355024) CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow

This is an update fixing CVE 2025-30232.

https://security-tracker.debian.org/tracker/DSA-5893-1

https://security-tracker.debian.org/tracker/DSA-5894-1

https://security-tracker.debian.org/tracker/DSA-5895-1

https://security-tracker.debian.org/tracker/DSA-5896-1

https://security-tracker.debian.org/tracker/DSA-5892-1

Critical deserialization bug in Apache Parquet allows RCE
Google Cloud Next ’25: What to expect
Trump fires NSA boss, deputy

Imagine waking up one day to find that someone has stolen your identity, opened credit cards in your name, or even withdrawn money from your bank accounts. It’s something that can easily happen if your personal data falls into the hands of cybercriminals. In our interconnected world, data breaches and identity theft are a constant […]

* bsc#1229122 * bsc#1240550 Cross-References: * CVE-2025-22871

30 minutes to pwn town: Are speedy responses more important than backups for recovery?
Enterprises are getting worse at multicloud
Basking in JavaScript refinements
Alan Turing Institute: UK can’t handle a fight against AI-enabled crims
Ex-ASML, NXP staffer accused of stealing chip secrets, peddling them to Moscow
Retirement funds reportedly raided after unexplained portal probes and data theft

Upgrade to 2.48.0: Move tile rendering to worker threads when rendering with the GPU. Fix preserve-3D intersection rendering. Added new function for creating Promise objects to the JavaScriptCore GLib API. The MediaRecorder backend gained WebM support (requires at least GStreamer

Signalgate: Pentagon watchdog probes Defense Sec Hegseth
Sonatype warns of 18,000 open source malware packages

Several security issues were fixed in the Linux kernel.

For flux sake: CISA, annexable allies warn of hot DNS threat

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. (CVE-2024-56161)

Rust language adds trait upcasting

* bsc#1228012 * bsc#1228578 * bsc#1233023 Cross-References:

Suspected Chinese spies right now hijacking buggy Ivanti gear – for third time in 3 years
Hyperlight Wasm points to the future of serverless
GitHub upgrades tooling to help developers stop leaking secrets
When disaster strikes, proper preparation prevents poor performance
Accelerate cloud infrastructure initiatives with Lucid Software
HellCat ransomware: what you need to know
Why is someone mass-scanning Juniper and Palo Alto Networks products?

* bsc#1238591 * bsc#1239625 * bsc#1239637 Cross-References:

* bsc#1239302 * bsc#1239676 Cross-References: * CVE-2024-56337

* bsc#1240075 * bsc#1240077 * bsc#1240080 * bsc#1240081

EU: These are scary times – let’s backdoor encryption!
Heterogeneous stacks, ransomware, and ITaaS: A DR nightmare
How to use guard clauses in C#
Customer info allegedly stolen from Royal Mail, Samsung via compromised supplier

https://security-tracker.debian.org/tracker/DSA-5890-1

https://security-tracker.debian.org/tracker/DSA-5891-1

Smashing Security podcast #411: The fall of Troy, and whisky barrel scammers
Raw Deel: Corporate spy admits role in espionage at HR software biz Rippling
Django 5.2 release touts automatic model importing
Crimelords at Hunters International tell lackeys ransomware too ‘risky’
Informatica readies new Claire Copilot capabilities for IDMC
Oracle’s masterclass in breach comms: Deny, deflect, repeat
Don’t let cyberattacks keep you down
Google fixes GCP flaw that could expose sensitive container images
3 key features in Kong AI Gateway 3.10

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

* bsc#1234452 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5

* bsc#1219437 * bsc#1234089 * bsc#1237367 * bsc#1239185 * bsc#1239322

* bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029