Menu

Category Archives: All

Everything

Oracle tells Clop-targeted EBS users to apply July patch, problem solved
IBM launches Granite 4.0 to cut AI infra costs with hybrid Mamba-transformer models
Who stops wasteful cloud spending?
The JavaScript code won’t write itself
What is an internal developer platform? IDP explained
Criminals take Renault UK customer data for a joyride
Microsoft unveils framework for building agentic AI apps

New upstream release (143.0.3)

CVE-2025-7493: host to admin escalation prevention: https://www.freeipa.org/release-notes/4-12-5.html Update FreeIPA to latest fixes from ipa-4-12 branch

Update to 7.1.2.

cve fixes

Security update for path traversal CVE-2025-59825 / GHSA-3wgq-wrwc-vqmv.

https://security-tracker.debian.org/tracker/DSA-6017-1

https://security-tracker.debian.org/tracker/DSA-6018-1

Chainguard offers malware-resistant JavaScript libraries
Subpoena tracking platform blames outage on AWS social engineering attack

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Clop-linked crims shake down Oracle execs with data theft claims
EU funds are flowing into spyware companies, and politicians are demanding answers
Why Software Supply Chain Security Matters in Linux Systems

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Cybercrims claim raid on 28,000 Red Hat repos, say they have sensitive customer files
How to deploy machine learning models with AWS Lambda
Why observability needs Apache Iceberg
Using Microsoft’s Data API builder for Azure databases
Claude Sonnet 4.5 coding model improves agentic capabilities

https://security-tracker.debian.org/tracker/DSA-6016-1

Smashing Security podcast #437: Salesforce’s trusted domain of doom
Your favourite phone apps might be leaking your company’s secrets
US gov shutdown leaves IT projects hanging, security defenders a skeleton crew
‘Delightful’ root-access bug in Red Hat OpenShift AI allows full cluster takeover
Air Force admits SharePoint privacy issue as reports trickle out of possible breach
Microsoft .NET Aspire backs .NET 10 file-based apps
3.7M breach notification letters set to flood North America’s mailboxes
AI agent hypefest crashing up against cautious leaders, Gartner finds
Imgur yanks Brit access to memes as parent company faces fine
Spotlight report: Securing the cloud
Explain digital ID or watch it fizzle out, UK PM Starmer told
Why we need junior developers
Intro to Nitro: The server engine built for modern JavaScript
PDM: A smarter way to manage Python packages
Schools are swotting up on security yet still flunk recovery when cyberattacks strike

Several security issues were fixed in the Linux kernel.

An issue was found in open-vm-tools, a set of tools for VMs hosted on VMware. The issue is related to a local privilege escalation in combination with the get-versions.sh script, shipped with the service

Beijing-backed burglars master .NET to target government web servers

BIRD 3.1.4 (2025-09-22) BGP: Fixed crash on Notification with a message, CVE-2025-59688 BGP: Fixed invalid memory access in pending TX flush BGP: Fixed a rare bug with listening socket delay Pipe: Disabled statisticts for stopping pipe

Update to version 1.6.2. Includes fixes for CVE-2025-58066 (potential DoS in the ntpd-rs server) and CVE-2025-58160 (potential tracing log pollution).

Update to 2.0.1 to CVE-2025-30187

Update the ammonia crate to version 4.1.2 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071.

https://security-tracker.debian.org/tracker/DSA-6015-1

Fake North Korean IT workers sneaking into healthcare, finance, and AI
Tile trackers are a stalker’s dream, say Georgia Tech researchers
Google bolts AI into Drive to catch ransomware, but crooks not shaking yet
From fake lovers to sextortionists: 260 scammers arrested in Africa
Safe C++ proposal for memory safety flames out
Warnings about Cisco vulns under active exploit are falling on deaf ears
TMI: How cloud collaboration suites drive oversharing and unmanaged access
The AI Fix #70: AI behaves… until it knows you’re watching
Supply Chain Attacks Are Spreading: NPM, PyPI, and Docker Hub All Hit in 2025
Dutch teens recruited on Telegram, accused of Russia-backed hacking plot
Britain’s policing minister punts facial recog nationwide
£5.5B Bitcoin fraudster pleads guilty after years on the run
When personal ambitions undermine enterprise security
‘Blame the intern’ is not an agentic AI security strategy
Model Context Protocol (MCP) certification: When will it arrive and what will it mean?
Greg Kroah-Hartman explains the Cyber Resilience Act for open source developers

Multiple vulnerabilities were fixed in tiff, a library and tools providing support for the Tag Image File Format (TIFF). CVE-2024-13978

31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815

31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815

31.0.9 release RHBZ#2388493 RHBZ#2389830 RHBZ#2389831 RHBZ#2389842 RHBZ#2389843 RHBZ#2389814 RHBZ#2389815

Feds cut funding to program that shared cyber threat info with local governments

A vulnerability has been discovered in python-internetarchive, a Python library and command-line interface for searching, downloading and uploading content to the Internet Archive.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

JavaFX 25 previews JavaFX controls in title bars
One line of malicious npm code led to massive Postmark email heist
Asahi runs dry as online attackers take down Japanese brewer
UK may already be at war with Russia, ex-MI5 head suggests

USN-7280-2 introduced a regression in Python 2.7

USN-7015-4 introduced a regression in Python 2.7

An update that solves one vulnerability can now be installed.

* bsc#1247674 Cross-References: * CVE-2025-54571

* bsc#1247674 Cross-References: * CVE-2025-54571

* bsc#1236658 * bsc#1236746 * bsc#1237208 * bsc#1237308 * bsc#1237585

UK minister suggests government could ditch ‘dangerous’ Elon Musk’s X
Harrods blames its supplier after crims steal 430k customers’ data in fresh attack
Jaguar Land Rover gets £1.5B government jump-start after cyber breakdown
Digital ID, same place, different time: In this timeline, the result might surprise us
How MCP is making AI agents actually do things in the real world
Smoothing out AI’s rough edges
A brief history of AI
Submarine cable security is all at sea, and UK govt ‘too timid’ to act, says report
When AI is trained for treachery, it becomes the perfect agent
Trump demands Microsoft fire its head of global affairs
Dutch teen duo arrested over alleged ‘Wi-Fi sniffing’ for Russia
Datacenter fire takes 647 South Korean government services offline

An update that solves 2 vulnerabilities can now be installed.