Menu

Category Archives: All

Everything

US defense contractor cops to sloppy security, settles after infosec lead blows whistle
Files stolen from NSW court system, including restraining orders for violence
Credible nerd says stop using atop, doesn’t say why, everyone panics
Critical RCE flaws put Kubernetes clusters at risk of takeover

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239460 Cross-References: * CVE-2025-24049

Databricks’ TAO method to allow LLM training with unlabeled data
NCSC taps influencers to make 2FA go viral
Open-source Styrolite project aims to simplify container runtime security
What you need to know about Go, Rust, and Zig
Intro to Alpine.js: A JavaScript framework for minimalists
Vibe coding is groovy

https://security-tracker.debian.org/tracker/DSA-5887-1

Oracle releases ML-optimized GraalVM for JDK 24
Warning for developers, web admins: update Next.js to prevent exploit
There are perhaps 10,000 reasons to doubt Oracle Cloud’s security breach denial
The AI Fix #43: I, for one, welcome our new robot overlords!
Infosec pro Troy Hunt HasBeenPwned in Mailchimp phish

This upload fixes two security issues in the version of nginx shipped in bullseye. CVE-2024-7347

Fauna to shut down FaunaDB service in May
Google acquires Wiz: A win for multicloud security
Cosmonic uses WebAssembly to manage apps
GenAI tools for R: New tools to make R programming easier
You know that generative AI browser assistant extension is probably beaming everything to the cloud, right?

* bsc#1239465 Cross-References: * CVE-2025-27363

VanHelsing ransomware emerges to put a stake through your Windows heart
Hm, why are so many DrayTek routers stuck in a bootloop?

Several security issues were fixed in SmartDNS.

Public-facing Kubernetes clusters at risk of takeover thanks to Ingress-Nginx flaw

Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens

0.9.30, rebuild due golang CVE-2025-22870

OTF, which backs Tor, Let’s Encrypt and more, sues to save funding from Trump cuts
Top Trump officials text classified Yemen airstrike plans to journo in Signal SNAFU
FCC on the prowl for Huawei and other blocked Chinese makers in America
As nation-state hacking becomes ‘more in your face,’ are supply chains secure?

https://security-tracker.debian.org/tracker/DSA-5885-1

Ivan Fratric discovered two use-after-free vulnerabilities in libxslt, an XSLT processing runtime library, which may result in the execution of arbitrary code if a specially crafted files are processed.

AI agents swarm Microsoft Security Copilot
23andMe’s genes not strong enough to avoid Chapter 11
Anatomy of Linux Ransomware Attacks and Protection Strategies
Is Washington losing its grip on crypto, or is it a calculated pivot to digital dominance?

Two use-after-free vulnerabilities have been fixed in the XSLT processing library libxslt. CVE-2024-55549

Microsoft tastes the unexpected consequences of tariffs on time
OpenTofu becomes the real deal
Prompt engineering courses and certifications tech companies want
Learning AI governance lessons from SaaS and Web2
Mobsters now overlap with cybercrime gangs and use AI for evil, Europol warns

Several security issues were fixed in NLTK.

Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens

China bans compulsory facial recognition and its use in private spaces like hotel rooms
Oracle Cloud says it’s not true someone broke into its login servers and stole data

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-44192

An update that fixes two vulnerabilities is now available.

Ex-NSA boss: Election security focus helped dissuade increase in Russian meddling with US
Mitigating threats against telco networks in the cloud

Update to 4.3.6 (rhbz#2352545)

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

Update to 4.3.6 (rhbz#2352545)

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

Backported fix for CVE-2024-12361 .

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

https://security-tracker.debian.org/tracker/DSA-5884-1

A cross-site scripting vulnerability was discovered in hgweb, the integrated stand-alone web interface of the Mercurial version control system.

Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes

Kotlin bolsters K2 compiler plugin support, WebAssembly debugging

https://security-tracker.debian.org/tracker/DSA-5883-1

OpenSilver extends to iOS and Android

* bsc#1197331 * bsc#1203769 * bsc#1235441 * bsc#1237768 * bsc#1238271

* bsc#1239750 Cross-References: * CVE-2022-49737

https://security-tracker.debian.org/tracker/DSA-5882-1

go-gh could be made to expose sensitive information over the network.

* bsc#1239547 Cross-References: * CVE-2025-24201

* bsc#1239547 Cross-References: * CVE-2025-24201

* bsc#1237363 * bsc#1237370 * bsc#1237418 Cross-References:

Nvidia launches AgentIQ toolkit to connect disparate AI agents
Bridging the digital skills gap
Everyone needs a genAI strategy now
AdTech CEO whose products detected fraud jailed for financial fraud
Paragon spyware deployed against journalists and activists, Citizen Lab claims
Capital One cracker could be sent back to prison after judges rule she got off too lightly
Developers: apply these 10 mitigations first to prevent supply chain attacks
Dept of Defense engineer took home top-secret docs, booked a fishing trip to Mexico – then the FBI showed up
Microsoft .NET 10 Preview 2 shines on C#, runtime, encryption
BlackLock ransomware: What you need to know
Infoseccers criticize Veeam over critical RCE vulnerability and a failing blacklist
Ex-Sun CEO Scott McNealy reflects on Java’s founding
What OpenInfra Joining Linux Foundation Means for Cloud Security Posture Management
Smashing Security podcast #409: Peeping perverts and FBI phone calls
Too many software supply chain defense bibles? Boffins distill advice
The post-quantum cryptography apocalypse will be televised in 10 years, says UK’s NCSC

Several security issues were fixed in Valkey.