Menu

Category Archives: All

Everything

Russian hackers debut simple ransomware service, but store keys in plain text
Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece

Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.

Google fixes super-secret 8th Chrome 0-day
LastPass hammered with £1.2M fine for 2022 breach fiasco
AI vendors move to tackle the hidden cost of inefficient enterprise code
Researcher claims Salt Typhoon spies attended Cisco training scheme
Slash VM provisioning time on Red Hat Openshift Virtualization using Red Hat Ansible Automation Platform
Don’t just automate, validate: How to measure and grow your return on investment

An out-of-bounds read flaw was found in libsndfile’s FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with

10K Docker images spray live cloud creds across the internet

version update security update

1.282 – Sanitize all user-supplied values before inserting into HTTP headers; Fixed CVE-2025-40927.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, same-origin policy bypass or privilege escalation.

Users report chaos as Legal Aid Agency stumbles back online after cyberattack
Microsoft’s Dev Proxy puts APIs to the test
Document databases – understanding your options

Several security issues were fixed in libpng.

Qt could be made to crash or run programs as your login if it opened a specially crafted file.

It’s everyone but Meta in a new AI standards group
Did your npm pipeline break today? Check your ‘classic’ tokens
Smashing Security podcast #447: Grok the stalker, the Louvre heist, and Microsoft 365 mayhem
700+ self-hosted Gits battered in 0-day attacks with no fix imminent
US extradites Ukrainian woman accused of hacking meat processing plant for Russia
Microsoft won’t fix .NET RCE bug affecting slew of enterprise apps, researchers say
The big catch: How whaling attacks target top executives

Is your organization’s senior leadership vulnerable to a cyber-harpooning? Learn how to keep them safe.

Ransomware may have extorted over $2.1 billion between 2022-2024, but it’s not all bad news, claims FinCEN report
Protecting value at risk – the role of a risk operations center

* bsc#1251198 * bsc#1251199 Cross-References: * CVE-2025-61984

* bsc#1238879 Cross-References: * CVE-2025-27516

* bsc#1254132 Cross-References: * CVE-2025-9820

Crisis in Icebergen: How NATO crafts stories to sharpen cyber skills
Four years later, Irish health service offers €750 to victims of ransomware attack

Insufficient validation of incoming notifies over TCP in PDNS Recursor, a resolving name server, could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 5.2.7-0+deb13u1. We recommend that you upgrade your pdns-recursor packages.

Why AI agents are so good at coding
PythoC: A new way to generate C code from Python
Is vibe coding the new gateway to technical debt?

Several vulnerabilities were reported in the libpng PNG library, which could lead to information leaks, denial of service or potentially the execution of arbitrary code if a specially crafted image is processed. For the oldstable distribution (bookworm), these problems have been fixed in version 1.6.39-2+deb12u1.

* bsc#1244485 * bsc#1245878 * bsc#1254227 * bsc#1254430 * bsc#1254431

GitHub Action Secrets aren’t secret anymore: exposed PATs now a direct path into cloud environments
Linux Foundation launches Agentic AI Foundation

https://security-tracker.debian.org/tracker/DSA-6075-1

https://security-tracker.debian.org/tracker/DSA-6076-1

https://security-tracker.debian.org/tracker/DSA-6077-1

https://security-tracker.debian.org/tracker/DSA-6078-1

https://security-tracker.debian.org/tracker/DSA-6079-1

Microsoft reports 7.8-rated zero day, plus 56 more in December Patch Tuesday
How to answer the door when the AI agents come knocking
Porsche panic in Russia as pricey status symbols forget how to car
Privacy concerns raised as Grok AI found to be a stalker’s best friend
California man admits role in $263 million cryptocurrency theft that funded lavish lifestyle
The AI Fix #80: DeepSeek’s cheap GPT-5 rival, Antigravity fails, and why being rude to AI makes it smarter
As humanoid robots enter the mainstream, security pros flag the risk of botnets on legs
AWS is still chasing a cohesive enterprise AI story after re:Invent

Several security issues were fixed in radare2.

* bsc#1241772 * bsc#1250683 * bsc#1253181 * bsc#1253185 * bsc#1253186

UK to Europe: The time to counter Russia’s information war machine is now

python-apt could be made to crash if it opened a specially crafted file.

UK finally vows to look at 35-year-old Computer Misuse Act
Whitehall rejects £1.8B digital ID price tag – but won’t say what it will cost
The hidden cost of Amazon Nova 2
Amazon Q Developer: Everything you need to know

* bsc#1254132 Cross-References: * CVE-2025-9820

An update that solves one vulnerability can now be installed.

* bsc#1250497 Cross-References: * CVE-2025-10922

Researchers spot 700 percent increase in hypervisor ransomware attacks
IBM to buy Confluent to extend its data and automation portfolio

https://security-tracker.debian.org/tracker/DSA-6074-1

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), this problem has been fixed in version 7:7.1.3-0+deb13u1.

AWS takes aim at the PoC-to-production gap holding back enterprise AI
193 cybercrims arrested, accused of plotting ‘violence-as-a-service’
UK moves to strengthen undersea cable defenses as Russian snooping ramps up
Home Office kept police facial recognition flaws to itself, UK data watchdog fumes
Barts Health seeks High Court block after Clop pillages NHS trust data
AI memory is really a database problem
10 MCP servers for devops
Block all AI browsers for the foreseeable future: Gartner
China’s first reusable rocket explodes, but its onboard Ethernet network flew
Apache warns of 10.0-rated flaw in Tika metadata ingestion tool

Multiple vulnerabilties have been found in libpng, the official PNG reference library, allowing information disclosure via out-of-bounds read, denial of service via application crash, or heap corruption with potential for arbitrary code execution.

Update to 2.9.7

Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287

Update to 2.9.7

https://security-tracker.debian.org/tracker/DSA-6073-1

Solving tool overload, one automation step at a time
Red Hat OpenShift sandboxed containers 1.11 and Red Hat build of Trustee 1.0 accelerate confidential computing across the hybrid cloud
CIS publishes hardening guidance for Red Hat OpenShift Virtualization
AI ambitions meet automation reality: The case for a unified automation platform
From vision to reality: A 5-step playbook for unified automation and AI
Death to one-time text codes: Passkeys are the new hotness in MFA

Loading a manipulated TGA file in krita, an image manipulation program, could result in a heap-based buffer overflow in KisTgaImport.

Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials

Fix CVE-2025-12744

Update to cef-142.0.17+g60aac24 & chromium 142.0.7444.175 (rhbz#2413981) High CVE-2025-13223: Type Confusion in V8 High CVE-2025-13224: Type Confusion in V8

Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials

Fix CVE-2025-12744

Crims using social media images, videos in ‘virtual kidnapping’ scams
Novel clickjacking attack relies on CSS and SVG
Cloudflare blames Friday outage on borked fix for React2shell vuln

https://security-tracker.debian.org/tracker/DSA-6072-1

https://security-tracker.debian.org/tracker/DSA-6071-1