Menu

Category Archives: All

Everything

https://security-tracker.debian.org/tracker/DSA-5985-1

Bug bounties: The good, the bad, and the frankly ridiculous ways to do it

Security fixes Bumped the minimum github.com/go-viper/mapstructure/v2 version to 2.3.0 for GHSA-fv92-fjc5-jj9h or GO-2025-3787 Bumped the minimum github.com/NVIDIA/nvidia-container-toolkit version to 1.17.8 for CVE-2025-23266 and CVE-2025-23267

How RingReaper Linux Malware Exploits io_uring to Evade EDR Systems

https://security-tracker.debian.org/tracker/DSA-5984-1

“What happens online stays online” and other cyberbullying myths, debunked

Separating truth from fiction is the first step towards making better parenting decisions. Let’s puncture some of the most common misconceptions about online harassment.

The need for speed: Why organizations are turning to rapid, trustworthy MDR

How top-tier managed detection and response (MDR) can help organizations stay ahead of increasingly agile and determined adversaries

Blue Locker ransomware hits critical infrastructure – is your organisation ready?

Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix

Update to release v1.33.4 Resolves: rhbz#2388412 Fixes CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Update to 1.67.0 Update to 1.66.0

Update to release v1.31.12 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fix

Update to release v1.32.7 Resolves: rhbz#2388412 Resolves: CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference Upstream fixes

Microsoft adds MCP support to Visual Studio to boost development of agentic applications
Short circuit: Electronics supplier to tech giants suffers ransomware shutdown
Kidney dialysis giant DaVita tells 2.4M people they were snared in ransomware data theft nightmare
Criminal background checker APCS faces data breach
Fake CAPTCHA tests trick users into running malware
Europol says Telegram post about 50,000 Qilin ransomware award is fake
Interpol bags 1,209 suspects, $97M in cybercrime operation focused on Africa

* bsc#1248006 Cross-References: * CVE-2025-55159

Several security issues were fixed in PHP.

From cloud migration to cloud optimization
Generative AI dos, don’ts, and ‘undos’

* bsc#1248006 Cross-References: * CVE-2025-55159

Anthropic adds Claude Code to its Claude enterprise plans

Several security issues were fixed in Python.

Update to version 0.4.11. This version includes a fix for CVE-2025-55159, but there are zero packages in Fedora or EPEL that use the affected API, so no rebuilds are necessary.

Update to v1.136.0 Update to 1.135.2 Update to 1.135.0

Developer jailed for taking down employer’s network with kill switch malware

https://security-tracker.debian.org/tracker/DSA-5983-1

Anthropic scanning Claude chats for queries about DIY nukes for some reason
Microsoft reportedly cuts China’s early access to bug disclosures, PoC exploit code
‘Impersonation as a service’ the next big thing in cybercrime
Honey, I shrunk the image and now I’m pwned
Congressman proposes bringing back letters of marque for cyber privateers
Orange Belgium mega-breach exposes 850K customers to serious fraud
US cops wrap up RapperBot, one of world’s biggest DDoS-for-hire rackets
Apple rushes out fix for active zero-day in iOS and macOS
Colt changes tune, admits data theft as Warlock gang begins auction
Google yet to take down ‘screenshot-grabbing’ Chrome VPN extension

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or bypass of the same-origin policy.

AI crawlers and fetchers are blowing up websites, with Meta and OpenAI the worst offenders

poppler could be made to denial of service if it received a specially crafted PDF file.

Up and running with Azure Linux 3.0
The shift from AI code generation to true development partnership
How to upload files using minimal APIs in ASP.NET Core

* bsc#1245218 * bsc#1247350 * bsc#1247351 Cross-References:

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

GitHub launches Copilot agents panel on GitHub.com
China cut itself off from the global internet for an hour on Wednesday

https://security-tracker.debian.org/tracker/DSA-5981-1

https://security-tracker.debian.org/tracker/DSA-5982-1

Microsoft stays mum about M365 Copilot on-demand security bypass
Smashing Security podcast #431: How to mine millions without paying the bill
Amazon quietly fixed Q Developer flaws that made AI agent vulnerable to prompt injection, RCE
JRebel Enterprise speeds configuration, code updates for cloud-based Java development
FBI: Russian spies exploiting a 7-year-old Cisco bug to slurp configs from critical infrastructure
Commvault releases patches for two nasty bug chains after exploits proven
‘Limited’ data leak at Aussie telco turns out to be 280K customer details
Warlock ransomware: What you need to know
The AI Fix #64: AI can be vaccinated against evil, and the “Rumble in the Silicon Jungle”

* bsc#1244270 * bsc#1244272 * bsc#1244273 * bsc#1244279 * bsc#1244336

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

Several security issues were fixed in Apache HTTP Server.

AWS blames bug for Kiro pricing glitch that drained developer limits

Several security issues were fixed in libxml2.

Is the generative AI bubble about to burst?
PyApp: An easy way to package Python apps as executables
Your code is more strongly coupled than you think

* bsc#1012628 * bsc#1139073 * bsc#1204142 * bsc#1210025 * bsc#1211226

McDonald’s not lovin’ it when hacker exposes nuggets of rotten security

https://security-tracker.debian.org/tracker/DSA-5980-1

.NET 10 Preview 7 adds XAML generator
Don’t want drive-by Ollama attackers snooping on your local chats? Patch now
Like burglars closing a door, Apache ActiveMQ attackers patch critical vuln after breaking in
Investors beware: AI-powered financial scams swamp social media

Can you tell the difference between legitimate marketing and deepfake scam ads? It’s not always as easy as you may think.

Speed cameras knocked out after cyber attack
Casino tech outfit Bragg cops to intrusion but says data jackpot untouched

* bsc#1242666 * bsc#1243428 Cross-References: * CVE-2025-3416

* bsc#1244631 * bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

US spy chief claims UK backed down over Apple backdoor demand
IBM can’t afford an unreliable cloud
Retrieval-augmented generation with Nvidia NeMo Retriever
The successes and challenges of AI agents
More customers asking for Google’s Data Boundary, says Cloud Experience boss
Browser wars are back, predicts Palo Alto, thanks to AI

https://security-tracker.debian.org/tracker/DSA-5979-1