Menu

Category Archives: All

Everything

Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management

https://security-tracker.debian.org/tracker/DSA-5847-1

The OpenJDK’s plans for Java in 2025
SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix
Meta’s pay-or-consent model under fire from EU consumer group
FortiGate config leaks: Victims’ email addresses published online
Google BigQuery gets metadata service with Iceberg support

OpenJPEG could be made to crash or run programs if it opened a specially crafted file.

Django could be made to cause a denial of service if it received a specially crafted IPv6 string.

In FRR, the internet routing protocol suite software, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket’s buffer size, default 4K on most OSes.

Who is DDoSing you? Rivals, probably, or cheesed-off users
Biz tax rises, inflation and high interest. Why fewer UK tech firms started in 2024
Stratoshark analyzes cloud applications at a syscall level
How to use resource-based authorization in ASP.NET Core

Multiple vulnerabilities have been discovered in PHP, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to arbitrary code execution.

Asus lets processor security fix slip out early, AMD confirms patch in progress
Kazakhstan’s SOS 102: Redefining Public Safety Through Innovation
Oracle emits 603 patches, names one it wants you to worry about soon
Smashing Security podcast #401: Hacks on the high seas, and how your home can be stolen under your nose

https://security-tracker.debian.org/tracker/DSA-5848-1

Trump ‘waved a white flag to Chinese hackers’ as Homeland Security axed cyber advisory boards
Supply chain attack hits Chrome extensions, could expose millions
Give users confidence in your digital infrastructure
Microsoft issues out-of-band fix for Windows Server 2022 NUMA glitch
Stargate Project launched for OpenAI AI infrastructure
Silk Road’s Dread Pirate Roberts walks free as Trump pardons dark web kingpin
Infosec was literally the last item in Trump’s policy plan, yet major changes are likely on his watch
A Sysadmin’s Guide to Securing the Linux Kernel
EMEA blog [DUTCH] | Red Hat closes Master Agreement with SLM Rijk to strengthen digital autonomy within Dutch government
Introducing confidential containers on bare metal
Half a million hotel guests at risk after hackers accessed sensitive data
Perplexity launches Sonar API, enabling enterprise AI search integration
Ransomware scum make it personal for Reg readers by impersonating tech support
How to deal with a Big Pile of Mud
State of JavaScript: Highlights of the JavaScript developer survey
3 Python web frameworks for beautiful front ends

Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

* bsc#1232762 * jsc#PED-10545 Affected Products: * Containers Module 15-SP6

Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

Software bill-of-materials docs eyed for Python packages
PowerSchool theft latest: Decades of Canadian student records, data from 40-plus US states feared stolen
Patch procrastination leaves 50,000 Fortinet firewalls vulnerable to zero-day
The AI Fix #34: Fake Brad Pitt and why AI means we will lose our jobs

Cybercriminals are becoming increasingly sophisticated, agile, and fast. For managed service providers (MSPs) supporting small and medium-sized businesses (SMBs) with cybersecurity services, staying ahead of these adversaries is crucial. One of the most effective ways to do so is through round-the-clock threat hunting. In this blog, we’ll explore why constant threat hunting is essential, the […]

HPE probes IntelBroker’s bold data theft boasts
Medusa ransomware: what you need to know
The AI security tsunami
The bitter lesson for generative AI adoption
Breaking free from reactive security
Banks must keep ahead of risks and reap AI rewards

https://security-tracker.debian.org/tracker/DSA-5846-1

Hackers game out infowar against China with the US Navy
How to leave the submarine cable cutters all at sea – go Swedish
A Linux Admin’s Guide to Ensuring Data Privacy in 2025
Ransomware attack forces Brit high school to shut doors
Passwords: a thin line between love and hate
Are 10% of your software engineers lazy?
5 new features in EDB Postgres AI
From devops to CTO: 5 things to start doing now
Sage Copilot grounded briefly to fix AI misbehavior
Datacus extractus: Harry Potter publisher breached without resorting to magic
When food delivery apps reached Indonesia, everyone put on weight
Donald Trump proposes US government acquire half of TikTok, which thanks him and restores service
OpenAI’s ChatGPT crawler can be tricked into DDoSing sites, answering your queries
Node.js set to stabilize type stripping

Important: thunderbird security update

Important: raptor2 security update

Important: rsync security update

Secure AI? Dream on, says AI red team
FCC to telcos: By law you must secure your networks from foreign spies. Get on it

https://security-tracker.debian.org/tracker/DSA-5843-2

Biden signs sweeping cybersecurity order, just in time for Trump to gut it
Fortinet: FortiGate config leaks are genuine but misleading
Clock ticking for TikTok as US Supreme Court upholds ban
Six vulnerabilities in ubiquitous rsync tool announced and fixed in a day
Migrating from .NET Framework to .NET Core: Security and Open Source Benefits
Medusa ransomware group claims attack on UK’s Gateshead Council
No, Brad Pitt isn’t in love with you
Federated learning: The killer use case for generative AI
Python eats the world
Microsoft eggheads say AI can never be made secure – after testing Redmond’s own products
Here’s how Google is using LLMs for complex internal code migrations
Just as your LLM once again goes off the rails, Cisco, Nvidia are at the door smiling
Google rolls out Vertex AI RAG Engine
GM parks claims that driver location data was given to insurers, pushing up premiums

https://security-tracker.debian.org/tracker/DSA-5845-1

The update for rsync announced in DSA 5843-1 introduced a regression when using the -H option to preserve hard links. Updated packages are now available to correct this issue.

* bsc#1235856 Cross-References: * CVE-2024-56374

* bsc#1220145 * bsc#1221302 * bsc#1222882 * bsc#1223059 * bsc#1223363

USN-7206-1 caused some regression in rsync.

Russia’s Star Blizzard phishing crew caught targeting WhatsApp accounts
Enzo Biochem settles lawsuit over 2023 ransomware attack for $7.5M
Cybersecurity rethink – from reaction to resilience