Menu

Category Archives: All

Everything

That ‘angry guest’ email from Booking.com? It’s a scam, not a 1-star review
CISA: We didn’t fire red teams, we just unhired a bunch of them
Medusa ransomware: FBI and CISA urge organisations to act now to mitigate threat
DeepSeek can be gently persuaded to spit out malware code

* bsc#1239197 Cross-References: * CVE-2025-22868

* bsc#1208995 * bsc#1220946 * bsc#1225742 * bsc#1232472 * bsc#1232919

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Speeding up .NET application development with Uno Studio
How DeepSeek innovated large language models
Medusa ransomware affiliate tried triple extortion scam – up from the usual double demand
Google unveils Gemma 3 multi-modal AI models
Get off that old Firefox by Friday or you’ll be sorry, says Moz
Smashing Security podcast #408: A gag order backfires, and a snail mail ransom demand
GitHub to unbundle Advanced Security
At long last, OpenStack (now known as OpenInfra Foundation) joins Linux Foundation
OpenAI takes on rivals with new Responses API, Agents SDK
Man found guilty of planting infinite loop logic bomb on ex-employer’s system

Our digital lives are filled with essential personal information, and it’s easy to forget how vulnerable all that data can be. But if your hard drive crashes, your laptop gets stolen, or you fall victim to cybercrime, the loss can be devastating. Your financial records, your work files, and even years of family photos can […]

Expired Juniper routers find new life – as Chinese spy hubs
The Security-Conscious Sysadmin’s Guide to Choosing the Right Linux Distro
This is the FBI, open up. China’s Volt Typhoon is on your network

* bsc#1237377 Cross-References: * CVE-2025-0633

Several security issues were fixed in Jinja2.

UK must pay cyber pros more than its Prime Minister, top civil servant says
Why Wasm fascinates me
Designing a dynamic web application with Astro
Airgapped Python: Setting up Python without a net(work)

Several security issues were fixed in opensc.

.NET could be made to elevate privileges.

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings. (CVE-2025-26699)

Jinja sandbox breakout through attr filter selecting format method. (CVE-2025-27516) References: – https://bugs.mageia.org/show_bug.cgi?id=34081

CISA worker says 100-strong red team fired after DOGE cancelled contract
Choose your own Patch Tuesday adventure: Start with six zero-day fixes, or six critical flaws
JavaOne 2025 heralds Java’s 30th birthday

https://security-tracker.debian.org/tracker/DSA-5877-1

‘Uber for nurses’ exposes 86k+ medical records, PII in open S3 bucket for months
FTC’s $25.5M scam refund treats victims to $34 each
The AI Fix #41: Can AIs be psychopaths, and why we should be AI optimists
Go-based TypeScript to dramatically improve speed, scalability

* bsc#1208995 * bsc#1220946 * bsc#1225742 * bsc#1232472 * bsc#1232919

* bsc#1208995 * bsc#1220946 * bsc#1224700 * bsc#1225742 * bsc#1232905

* bsc#1050081 * bsc#1051510 * bsc#1065729 * bsc#1100823 * bsc#1101669

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Weaviate adds agents to its tech stack to ease gen AI app development
Has AWS lost its edge?
3 of the best LLM integration tools for R
MINJA sneak attack poisons AI models for other chatbot users
Allstate Insurance sued for delivering personal info on a platter, in plaintext, to anyone who went looking for it
Fortran, Delphi rise in Tiobe popularity index
Google begs owners of crippled Chromecasts not to hit factory reset
Webinar: Credential security in the age of AI: Insights for IT leaders
Sidewinder goes nuclear, charts course for maritime mayhem in tactics shift
Enhancing Cybersecurity Quality Assurance with AI & Machine Learning
Rhysida pwns two US healthcare orgs, extracts over 300K patients’ data
Consumer Reports calls out slapdash AI voice-cloning safeguards
Databricks’ new updates aim to ease gen AI app and agent development
How NOT to f-up your security incident response

* bsc#1237681 Cross-References: * CVE-2025-27144

* bsc#1237681 Cross-References: * CVE-2025-27144

* bsc#1236531 * bsc#1237681 Cross-References: * CVE-2023-45288

The NHS security culture problem is a crisis years in the making
Building generative AI? Get ready for generative UI
Vibes won’t make your software successful
10 things developers love about JavaScript – and 10 things they don’t
Strap in, get ready for more Rust drivers in Linux kernel
Microsoft admits GitHub hosted malware that infected almost a million devices
India wants backdoors into clouds, email, SaaS, for tax inspectors

Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles

Unbundle libxml2.

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in

Microsoft previews AI chat template for .NET
Kernel saunters – How Apple rearranged its XNU kernel with exclaves

Two vulnerabilities were discovered in openvpn, a virtual private network application which could result in authentication bypass or data injection.

High CVE-2025-1914: Out of bounds read in V8. Medium CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools. Medium CVE-2025-1916: Use after free in Profiles. Medium CVE-2025-1917: Inappropriate Implementation in Browser UI.

Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles

The newest upstream commit Security fix for CVE-2025-27423

update to version 2.25.1, CVE-2025-27154

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2. (CVE-2023-5520) Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV. (CVE-2024-0321) Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

Developer sabotaged ex-employer with kill switch activated when he was let go

https://security-tracker.debian.org/tracker/DSA-5876-1

Microsoft reportedly struggling to build its own reasoning models to rival OpenAI
JFrog unveils JFrog ML for MLOps

https://security-tracker.debian.org/tracker/DSA-5875-1

Uncle Sam charges alleged Garantex admins after crypto-exchange web seizures
Alleged cyber scalpers Swiftly cuffed over $635K Taylor ticket heist
Anthropic’s upgraded Console targets more collaboration among developers
Like whitebox servers, rent-a-crew crime ‘affiliates’ have commoditized ransomware

Several security issues were fixed in the Linux kernel.

When to choose a bare-metal cloud
JavaScript tools and frameworks we’re watching now

Updated to latest upstream (136.0)