Menu

Category Archives: All

Everything

BlackSuit ransomware crew loses servers, domains, and $1m in global shakedown
Devops, SRE and platform engineering: What’s the difference?

An update that fixes 9 vulnerabilities is now available.

* bsc#1221107 Cross-References: * CVE-2024-2236

* bsc#1246296 Cross-References: * CVE-2025-7425

Oh, great.Three notorious cybercrime gangs appear to be collaborating
Hyundai: Want cyber-secure car locks? That’ll be £49, please
The rise of AI model-as-a-service ecosystems
A developer’s guide to code generation

* bsc#1219386 Cross-References: * CVE-2023-5992

The White House could end UK’s decade-long fight to bust encryption
Poisoned telemetry can turn AIOps into AI Oops, researchers show
Rust 1.89 underscores arguments to const generics

https://security-tracker.debian.org/tracker/DSA-5972-1

https://security-tracker.debian.org/tracker/DSA-5973-1

Russia’s RomCom among those exploiting a WinRAR 0-day in highly-targeted attacks
WinRAR zero-day exploited in espionage attacks against high-value targets

The attacks used spearphishing campaigns to target financial, manufacturing, defense, and logistics companies in Europe and Canada, ESET research finds

US scrambles to recoup $1M+ nicked by NORKs
Red teams are safe from robots for now, as AI makes better shield than spear
Wikimedia Foundation loses first court battle to swerve Online Safety Act regulation
Intel chief Lip-Bu Tan to visit White House after Trump calls for him to step down
Deepfake detectors are slowly coming of age, at a time of dire need
UK retail giant M&S restores Click & Collect months after cyber attack, some services still down
Your CV is not fit for the 21st century – time to get it up to scratch
Who does the unsexy but essential work for open source?
Multi-agent AI workflows: The next evolution of AI coding
The advantages of stack-based internal developer platforms

* bsc#1246318 * bsc#1246388 Cross-References: * CVE-2025-52520

* bsc#1233791 * bsc#1233834 Cross-References: * CVE-2024-22117

* bsc#1247519 * bsc#1247520 * bsc#1247522 Cross-References:

Trend Micro offers weak workaround for already-exploited critical vuln in management console
Black Hat USA 2025: Is a high cyber insurance premium about your risk, or your insurer’s?

A sky-high premium may not always reflect your company’s security posture

Android adware: What is it, and how do I get it off my device?

Is your phone suddenly flooded with aggressive ads, slowing down performance or leading to unusual app behavior? Here’s what to do.

DEF CON hackers plug security holes in US water systems amid tsunami of threats
The inside story of the Telemessage saga, and how you can view the data

update to xen-4.19.3 includes patches for x86: Incorrect stubs exception handling for flags recovery [XSA-470, CVE-2025-27465] x86: Transitive Scheduler Attacks [XSA-471, CVE-2024-36350,

New release of Incus. Release information: https://github.com/lxc/incus/releases/tag/v6.15.0

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

What is a CSRF Vulnerability?
Chinese biz using AI to hit US politicians, influencers with propaganda
Black Hat USA 2025: Policy compliance and the myth of the silver bullet

Who’s to blame when the AI tool managing a company’s compliance status gets it wrong?

Black Hat USA 2025: Does successful cybersecurity today increase cyber-risk tomorrow?

Success in cybersecurity is when nothing happens, plus other standout themes from two of the event’s keynotes

Star leaky app of the week: StarDict
Ex-White House cyber, counter-terrorism guru: Microsoft considers security an annoyance, not a necessity

* bsc#1246090 Affected Products: * openSUSE Leap 15.4

* bsc#1245573 Cross-References: * CVE-2025-6297

* bsc#1244925 Cross-References: * CVE-2025-50181

Infosec hounds spot prompt injection vuln in Google Gemini apps
Hashcat 7.0.0: Redefining Password Recovery & Security on Linux
Critical NestJS Vulnerability Exposes Developers to RCE Risk
How to Build a Ransomware Kill Chain Strategy for Linux Security
UK secretly allows facial recognition scans of passport, immigration databases
UK proxy traffic surges as users consider VPN alternatives amid Online Safety Act
TeaOnHer copies everything from Tea – including the data breaches
Should public clouds enforce government policies?
Prohibition never works, but that didn’t stop the UK’s Online Safety Act
What Is a SQLi Vulnerability?
Google rolls out AI coding tool for GitHub repos
Why blow up satellites when you can just hack them?

https://security-tracker.debian.org/tracker/DSA-5971-1

German security researchers say ‘Windows Hell No’ to Microsoft biometrics for biz
Microsoft, CISA warn yet another Exchange server bug can lead to ‘total domain compromise’
Black Hat’s network ops center brings rivals together for a common cause
CISA releases malware analysis for Sharepoint Server attack
Ukraine claims to have hacked secrets from Russia’s newest nuclear submarine
KLM, Air France latest major organizations looted for customer data
Meta training AI on social media posts? Only 7% in Europe think it’s OK

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

Introducing OpenShift Service Mesh 3.1

Several security issues were fixed in cifs-utils.

Anthropic targets DevSecOps with Claude Code update as AI rivals gear up
Getting started with A2A in .NET
The Claude party is almost over
Amnesty slams Elon Musk’s X for ‘central role’ in fueling 2024 UK riots

* bsc#1221107 * bsc#1246934 Cross-References: * CVE-2024-2236

Could agentic AI save us from the cybercrisis?
Microsoft researchers bullish on AI security agent even though it let 74% of malware slip through
Google updates agents in BigQuery to further automate analytics tasks
Google says the group behind last year’s Snowflake attack slurped data from one of its Salesforce instances
ESET Threat Report H1 2025: ClickFix, infostealer disruptions, and ransomware deathmatch

Threat actors are embracing ClickFix, ransomware gangs are turning on each other – toppling even the leaders – and law enforcement is disrupting one infostealer after another