Menu

Category Archives: All

Everything

Feds want devs to stop coding ‘unforgivable’ buffer overflow vulnerabilities
Sophos sheds 6% of staff after swallowing Secureworks
Go 1.24 arrives with generic type aliases, boosted WebAssembly support
Smashing Security podcast #404: Podcast not found
Trump’s cyber chief pick has little experience in The Cyber
Arizona laptop farmer pleads guilty for funneling $17M to Kim Jong Un
Ransomware isn’t always about the money: Government spies have objectives, too
UK, US, Oz blast holes in LockBit’s bulletproof hosting provider Zservers
Russia’s Sandworm caught snarfing credentials, data from American and Brit orgs
Snowflake announces preview of Cortex Agent APIs to power enterprise data intelligence
Crimelords and spies for rogue states are working together, says Google

* bsc#1229644 * bsc#1230998 * bsc#1231993 Cross-References:

* bsc#1229644 * bsc#1229663 * bsc#1230998 * bsc#1231993

* bsc#1230998 * bsc#1231993 Cross-References: * CVE-2024-45016

Keep your code open to possibilities
Rust memory management explained
Dynamic web apps with HTMX, Python, and Django
February’s Patch Tuesday sees Microsoft offer just 63 fixes
Don’t use public ASP.NET keys (duh), Microsoft warns

https://security-tracker.debian.org/tracker/DSA-5864-1

https://security-tracker.debian.org/tracker/DSA-5865-1

Probe finds US Coast Guard has left maritime cybersecurity adrift
Yup, AMD’s Elba and Giglio definitely sound like they work corporate security
‘Key kernel maintainers’ still back Rust in the Linux kernel, despite the doubters
Triplestrength hits victims with triple trouble: Ransomware, cloud hijacks, crypto-mining

https://security-tracker.debian.org/tracker/DSA-5863-1

OpenText recently surveyed 255 MSPs to uncover key trends shaping the future of Managed Detection and Response (MDR). The findings reveal not only what cybersecurity professionals are prioritizing but also how MSPs can better meet the evolving demands of their small and midsize business (SMB) customers. One key takeaway from the survey: 81% of respondents […]

Man who SIM-swapped the SEC’s X account pleads guilty
I’m a security expert, and I almost fell for a North Korea-style deepfake job applicant …Twice

* bsc#1228165 * bsc#1236705 Cross-References: * CVE-2025-0938

* bsc#1227056 * bsc#1236483 Cross-References: * CVE-2023-45288

* bsc#1218879 * bsc#1218880 * bsc#1218881 * bsc#1218882 * bsc#1218883

The cloud giants stumble
Review: Zencoder has a vision for AI coding
Why the generative AI hype is good
C++, Go, and Rust gaining popularity – Tiobe
Apple warns ‘extremely sophisticated attack’ may be targeting iThings
All your 8Base are belong to us: Ransomware crew busted in global sting
What you need to know about Python 3.14’s faster interpreter
Toll booth bandits continue to scam via SMS messages

February is a great month to refresh your cyber awareness skills. February 11 marks Safer Internet Day, encouraging us to work together to make the internet a safer and better place. It’s the perfect time to learn more about cybersecurity risks and best practices for protecting yourself and your loved ones online. And while February […]

Secret Taliban records published online after hackers breach computer systems
Navigating AI-Driven Security Challenges in Linux Environments
US news org still struggling to print papers a week after ‘cybersecurity event’

* bsc#1236619 * jsc#PED-12018 Cross-References: * CVE-2025-24528

* bsc#1233760 Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6

How Secure Is Linux? Examining Features That Ensure Safety
Secure Your DevTools: Critical UAF Vulnerability Warning
Firefox 135 Released: Key Updates & Advanced Browser Protection Features
Tails 6.12: An Essential Privacy, Security, and Reliability Upgrade

USN-7206-3 caused some regression in rsync.

Google’s generative AI Toolbox for Databases to help connect agents with databases
UK armed forces fast-tracking cyber warriors to defend digital front lines
When LLMs become influencers
Are database administrators doomed?
Will Kubernetes ever get easier?

* bsc#1236596 Cross-References: * CVE-2024-11187

Judge says US Treasury ‘more vulnerable to hacking’ since Trump let the DOGE out
India’s banking on the bank.in domain cleaning up its financial services sector
DeepSeek’s iOS app is a security nightmare, and that’s before you consider its TikTok links

https://security-tracker.debian.org/tracker/DSA-5862-1

Huawei revenue growing fast, suggesting China’s scoffing at sanctions

https://security-tracker.debian.org/tracker/DSA-5861-1

Vulnerabilities were found in sssd, a set of daemons to manage access to remote directories and authentication mechanisms, which could lead to privilege escalation.

update to 1.33.0

Security fix for CVE-2023-52892, CVE-2024-27354

Add code to deal with sched_setattr() not being exported in glibc 2.41 Address CVE-2024-54159 denial of services via symlink attack

Update to 1.17.3 Fixes CVE-2024-0134 or GHSA-7jm9-xpwx-v999 Fixes CVE-2024-0135 or GHSA-9v84-cc9j-pxr6, CVE-2024-0136 or GHSA- vcfp-63cx-4h59, and CVE-2024-0137 or GHSA-frhw-w3wm-6cw4

New ASPA support is now always compiled in and available if enable-aspa is set. The aspa Cargo feature has been removed. (#990) If merging mutliple ASPA objects for a single customer ASN results in more than 16,380 provider ASNs, the ASPA is dropped. (Note that ASPA objects with more

Updated to latest upstream (135.0)

Update to 0.8.4

xrdp allows an infinite number of login attempts. (CVE-2024-39917) References: – https://bugs.mageia.org/show_bug.cgi?id=33985 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/FMYGECEBC7XEBNQ2ZHXYRQBLCMHHXKP5/

When an input DER data contains a large number of SEQUENCE OF or SET OF elements, decoding the data and searching a specific element in it take quadratic time to complete. This could be utilized for a remote DoS attack by presenting a crafted certificate to the network peer.

Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.

Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.

https://security-tracker.debian.org/tracker/DSA-5860-1

UK Home Office silent on alleged Apple backdoor order

* bsc#1236270 Cross-References: * CVE-2024-11218

UK industry leaders unleash hurricane-grade scale for cyberattacks
Data breaches at UK law firms are on the rise, research reveals

A vulnerability has been discovered in the OpenJDK Java runtime, which may result in authorisation bypass or information disclosure. For Debian 11 bullseye, this problem has been fixed in version

The hidden threat of neglected cloud infrastructure
Full-stack JavaScript leads the way
Apple missed screenshot-snooping malware in code that made it into the App Store, Kaspersky claims

Updated to latest upstream (135.0)

If Ransomware Inc was a company, its 2024 results would be a horror show

Fix CVE-2025-0781

Fix CVE-2025-0781

GitHub Copilot previews agent mode
Coordinates of millions of smartphones feared stolen, sparking yet another lawsuit against data broker
Federal judge tightens DOGE leash over critical Treasury payment system access