Menu

Category Archives: All

Everything

Google links Android’s Quick Share to Apple’s AirDrop, without Cupertino’s help
PHP 8.5 enables secure URI and URL parsing

New gnutls packages are available for Slackware 15.0 and -current to fix security issues.

SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere
F# 10 features scoped warning suppression

ImageMagick could be made to crash or run programs as your login if it opened a specially crafted file.

https://security-tracker.debian.org/tracker/DSA-6060-1

Salesforce-linked data breach claims 200+ victims, has ShinyHunters’ fingerprints all over it
LLM-generated malware is improving, but don’t expect autonomous attacks tomorrow
PlushDaemon compromises network devices for adversary-in-the-middle attacks

ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks

How pairing SAST with AI dramatically reduces false positives in code security
UK’s new cybersecurity bill takes aim at ransomware gangs and state-backed hackers
Fired techie admits sabotaging ex-employer, causing $862K in damage
TP-Link accuses rival Netgear of ‘smear campaign’ over alleged China ties
Education boards left gates wide open for PowerSchool mega-breach, say watchdogs

An update that solves two vulnerabilities can now be installed.

* bsc#1250353 * bsc#1250354 Cross-References: * CVE-2025-59798

Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood
Wind farm worker sentenced after turning turbines into a secret crypto mine
Smashing Security podcast #444: We’re sorry. Wait, did a company actually say that?
Azure HorizonDB: Microsoft goes big with PostgreSQL
Improving annotation quality with machine learning

An update that solves five vulnerabilities can now be installed.

* bsc#1252931 * bsc#1252932 * bsc#1252933 * bsc#1252934 * bsc#1252935

Palo Alto CEO tips nation-states to weaponize quantum computing by 2029
US, UK, Australia sanction Lockbit gang’s hosting provider
Microsoft rolls out Agent 365 ‘control plane’ for AI agents

New openvpn packages are available for Slackware 15.0 and -current to fix security issues.

Fortinet ‘fesses up to second 0-day within a week

Several security issues were fixed in the Linux kernel.

Amazon security boss: Hostile countries use cyber targeting for physical military strikes
Microsoft Fabric IQ adds ‘semantic intelligence’ layer to Fabric
Researchers claim ‘largest leak ever’ after uncovering WhatsApp enumeration flaw
Enhance workload security with confidential containers on Azure Red Hat OpenShift
Introducing OpenShift Service Mesh 3.2 with Istio’s ambient mode
Microsoft touts scalability of its new PostgreSQL-compatible managed database
Google releases Gemini 3 with new reasoning and automation features
Tens of thousands more ASUS routers pwned by suspected, evolving China operation
Building a scalable document management system: Lessons from separating metadata and content
Selling technology investments to the board: a strategic guide for CISOs and CIOs
A developer’s guide to avoiding the brambles
Clojure for Java developers: What you need to know
Hands-on with Zed: The IDE built for AI
China recruiting spies in the UK with fake headhunters and ‘sites like LinkedIn’
Google unveils Gemini 3 AI model, Antigravity agentic development tool

MGASA-2025-0305 – Updated thunderbird packages fix security vulnerabilities

MGASA-2025-0304 – Updated cups-filters packages fix security vulnerabilities

MGASA-2025-0303 – Updated flatpak & bubblewrap packages fix security vulnerability

C# 14 touted for extension properties declaration

Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8

Updated to latest upstream (145.0) Added fix for mzbz#1990430 (crashes) Updated to latest upstream (144.0)

New libarchive packages are available for Slackware 15.0 and -current to fix security issues.

Self-replicating botnet attacks Ray clusters
Go team to improve support for AI assistants
FCC looks to torch Biden-era cyber rules sparked by Salt Typhoon mess
Take fight to the enemy, US cyber boss says
Google Chrome bug exploited as an 0-day – patch now or risk full system compromise
What if your romantic AI chatbot can’t keep a secret?

Does your chatbot know too much? Think twice before you tell your AI companion everything.

The AI Fix #77: Genome LLM makes a super-virus, and should AI decide if you live?
Zoomers are officially worse at passwords than 80-year-olds
A miracle: A company says sorry after a cyber attack – and donates the ransom to cybersecurity research
How to automate the testing of AI agents
Why context engineering will define the next era of enterprise AI
Do you really need all those GPUs?
What is A2A? How the agent-to-agent protocol enables autonomous collaboration

* bsc#1103203 * bsc#1149841 * bsc#1230998 * bsc#1231204 * bsc#1231676

MGASA-2025-0302 – Updated postgresql15 & postgresql13 packages fix security vulnerabilities

MGASA-2025-0301 – Updated apache packages fix security vulnerabilities

Several security issues were fixed in Freeglut.

Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8

FVWM3 ver. 1.1.4

‘Largest-ever’ cloud DDoS attack pummels Azure with 3.64B packets per second
Pentagon and soldiers let too many secrets slip on social networks, watchdog says
Security researcher calls BS on Coinbase breach disclosure timeline
Red Hat Advanced Cluster Security 4.9: Security built with your workflows in mind
Selling your identity to North Korean IT scammers isn’t a sustainable side hustle
Game over: Europol storms gaming platforms in extremist content sweep
Overconfidence is the new zero-day as teams stumble through cyber simulations
Eurofiber admits crooks swiped data from French unit after cyberattack
UK prosecutors seize £4.11M in crypto from Twitter mega-hack culprit
North Korea’s ‘Job Test’ trap upgrades to JSON malware dropboxes
The rebellion against robot drivel
Why software development slows to a crawl
10 JavaScript-based tools and frameworks for AI and machine learning

An update that solves 173 vulnerabilities, contains two features and has 19 security fixes can now be installed.

* bsc#1065729 * bsc#1205128 * bsc#1206893 * bsc#1207612 * bsc#1207619

An update that solves two vulnerabilities can now be installed.

* bsc#1251198 * bsc#1251199 Cross-References: * CVE-2025-61984

An update that solves two vulnerabilities can now be installed.

* bsc#1247850 * bsc#1249076 Cross-References: * CVE-2025-8732

Jaguar Land Rover hack cost India’s Tata Motors around $2.4 billion and counting
Logitech leaks data after zero-day attack

https://security-tracker.debian.org/tracker/DSA-6058-1

Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8

Update to 9.21.14 (rhbz#2394406) Security Fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

New upstream release v10 Fix: CVE-2025-11568

Update to 9.21.14 (rhbz#2394406) Security Fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

New upstream release v10 Fix: CVE-2025-11568

https://security-tracker.debian.org/tracker/DSA-6059-1

New xpdf packages are available for Slackware 15.0 and -current to fix security issues.