Menu

Category Archives: All

Everything

Ransomware plunges insurance company into bankruptcy

Multiple vulnerabilities have been discovered in Composer, the worst of which can lead to arbitrary code execution.

A vulnerability has been discovered in Spreadsheet-ParseExcel, which can lead to arbitrary code execution.

A vulnerability has been discovered in NSS, which can lead to the recovery of private data.

A vulnerability has been discovered in FontForge, which can lead to arbitrary code execution.

TypeScript 5.9 arrives with deferred module evaluation, expandable hovers
Google Spanner gets a columnar engine to unite OLTP and OLAP workloads
Hospital fined after patient data found in street food wrappers

Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which can lead to execution of arbitrary code.

Multiple vulnerabilities have been discovered in PAM, the worst of which could lead to privilege escalation.

How to measure coupled code
How to code sign binaries on Windows
Roo Code review: Autonomous AI-powered development in the IDE
Vibe coding tool Cursor’s MCP implementation allows persistent code execution
JetBrains previews no-code app builder
Patch now: Millions of Dell PCs with Broadcom chips vulnerable to attack
Study finds humans not completely useless at malware detection
Chained bugs in Nvidia’s Triton Inference Server lead to full system compromise
The AI Fix #62: AI robots can now pass CAPTCHAs, and punch you in the face
What Is a RCE Vulnerability?

* bsc#1245773 Cross-References: * CVE-2025-53367

* bsc#1247249 Cross-References: * CVE-2025-8194

* bsc#1247249 Cross-References: * CVE-2025-8194

Hacker summer camp: What to expect from BSides, Black Hat, and DEF CON
The problem with AI agent-to-agent communication protocols
Why benchmarks are key to AI progress
Python popularity boosted by AI coding assistants – Tiobe
Antivirus vendors fail to spot persistent, nasty, stealthy Linux backdoor
SonicWall investigates ‘cyber incidents,’ including ransomware targeting suspected 0-day
Python-powered malware snags hundreds of credit cards, 200K passwords, and 4M cookies
Mozilla flags phishing wave aimed at hijacking trusted Firefox add-ons
German phone repair biz collapses following 2023 ransomware attack
When hyperscalers can’t safeguard one nation’s data from another, dark clouds are ahead
Millions of age checks performed as UK Online Safey Act gets rolling
Erasing the trust gap in AI-driven development
9 habits of the highly ineffective vibe coder
Microsegmentation for developers

* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:

* bsc#1228645 * bsc#1235250 * bsc#1245771 * bsc#1245776 * bsc#1245793

* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:

* bsc#1235250 * bsc#1245776 * bsc#1245793 * bsc#1245797

* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:

China’s botched Great Firewall upgrade invites attacks on its censorship infrastructure
Lazarus Group rises again, this time with malware-laden fake FOSS
Silent Push CEO on cybercrime takedowns: ‘It’s an ongoing cat-and-mouse game’

Update to 138.0.7204.183 * CVE-2025-8292: Use after free in Media Stream

This update fixes CVE-2025-7345 and CVE-2025-6199.

This update fixes these CVEs: CVE-2025-32364 CVE-2025-32365 CVE-2024-56378

reposurgeon: update to 5.3 version

In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. References: – https://bugs.mageia.org/show_bug.cgi?id=34447

Stefan Buehler discovered a flaw in sope, the set of Objective-C frameworks powering SOGo, which may result in denial of service via a specially crafted POST request.

Is your phone spying on you? | Unlocked 403 cybersecurity podcast (S2E5)

Here’s what you need to know about the inner workings of modern spyware and how to stay away from apps that know too much

Why the tech industry needs to stand firm on preserving end-to-end encryption

Restricting end-to-end encryption on a single-country basis would not only be absurdly difficult to enforce, but it would also fail to deter criminal activity

CISA roasts unnamed critical national infrastructure body for shoddy security hygiene

A flaw was found in how GLib¢”s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn¢”t. As a result, data may be written […]

Backports patch to fix non-CVE 2025-8224

This update fixes these CVEs: CVE-2025-4948 CVE-2025-32908 CVE-2025-32907 CVE-2025-4969

What Is An XSS Vulnerability?

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Apache Flink integrates AI for real-time decision-making
OpenAI removes ChatGPT self-doxing option

https://security-tracker.debian.org/tracker/DSA-5970-1

Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks
China says US spies exploited Microsoft Exchange zero-day to steal military info
This month in security with Tony Anscombe – July 2025 edition

Here’s a look at cybersecurity stories that moved the needle, raised the alarm, or offered vital lessons in July 2025

Florida prison email blunder exposes visitor contact info to inmates

* bsc#1243855 Cross-References: * CVE-2024-12224

* bsc#1243868 Cross-References: * CVE-2024-12224

* bsc#1221107 Cross-References: * CVE-2024-2236

Google upgrades Agent2Agent protocol with gRPC and enterprise-grade security
Deploy sensitive workloads with OpenShift confidential containers
Confidential containers on Microsoft Azure with Red Hat OpenShift Sandboxed Containers 1.10 and Red Hat Build of Trustee

An update that fixes one vulnerability is now available.

Cybercrooks attached Raspberry Pi to bank network and drained ATM cash
Spotlight report: How AI is reshaping IT
.NET Aspire 9.4 boasts CLI core commands, AI integrations
Fun and profit with ECMAScript 2025: What’s new in JavaScript
Dedicated servers outpace public clouds for AI
Top spy says LinkedIn profiles that list defense work ‘recklessly invite attention of foreign intelligence services’
As ransomware gangs threaten physical harm, ‘I am afraid of what’s next,’ ex-negotiator says
Gene scanner pays $9.8 million to get feds off its back in security flap
Microsoft’s Azure AI Speech needs just seconds of audio to spit out a convincing deepfake
Beijing summons Nvidia over alleged backdoors in China-bound AI chips
Kremlin goons caught abusing ISPs to spy on Moscow-based diplomats, Microsoft says
Silk Typhoon spun a web of patents for offensive cyber tools, report says
Brit watchdog pushes to rein in Microsoft and AWS with ‘strategic market status’
Informatica enhances IDMC with AI-powered MDM, governance, and compliance tools

* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274