Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 – here’s some of what made the headlines this month
Three security vulnerabilities were discovered in libexif, a library to reads and writes EXIF metainformation from and to images files, that can causes crashes or information leaks. CVE-2026-32775 If the exif_mnote_data_get_value function in MakerNotes gets passed
Important: libtiff security update
Important: xorg-x11-server-Xwayland security update
Important: yggdrasil-worker-package-manager security update
Important: yggdrasil security update
Important: vim security update
https://security-tracker.debian.org/tracker/DSA-6239-1
https://security-tracker.debian.org/tracker/DSA-6197-3
https://security-tracker.debian.org/tracker/DSA-6240-1
https://security-tracker.debian.org/tracker/DSA-6242-1
https://security-tracker.debian.org/tracker/DSA-6243-1
Important: vim security update
Important: PackageKit security update
Important: xorg-x11-server security update
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or sandbox escape. For Debian 11 bullseye, these problems have been fixed in version 140.10.1esr-1~deb11u1.
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in OpenSSH.
An update that solves two vulnerabilities and has one security fix can now be installed.
Multiple vulnerabilities where identified in polkit, a toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes. CVE-2021-4115 Kevin Backhouse of GitHub Security Lab (GHSL) found that there is a
PackageKit could be made to install packages as the administrator.
An update that solves 14 vulnerabilities and has five security fixes can now be installed.
An update that solves 14 vulnerabilities and has five security fixes can now be installed.
https://security-tracker.debian.org/tracker/DSA-6237-1
https://security-tracker.debian.org/tracker/DSA-6236-1
https://security-tracker.debian.org/tracker/DSA-6231-1
Important: gdk-pixbuf2 security update
Important: firefox security update
Important: kernel security update
Important: sudo security update
Important: grafana security update
Important: firefox security update
https://security-tracker.debian.org/tracker/DSA-6232-1
https://security-tracker.debian.org/tracker/DSA-6233-1
https://security-tracker.debian.org/tracker/DSA-6234-1
https://security-tracker.debian.org/tracker/DSA-6235-1
Several security issues were fixed in nginx.
Pillow could be made to crash if it opened a specially crafted file.
HAProxy could be made to expose sensitive information over the network.
Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile.
ClamAV could be made to crash if it opened a specially crafted HTML file.
Several security issues were fixed in strongSwan.
