Menu

Category Archives: All

Everything

Several security issues were fixed in mongo-c-driver.

Several security issues were fixed in logback.

https://security-tracker.debian.org/tracker/DSA-5956-1

https://security-tracker.debian.org/tracker/DSA-5957-1

Smashing Security podcast #424: Surveillance, spyware, and self-driving snafus
Cisco scores a perfect 10 – sadly for a critical flaw in its comms platform

CVE-2025-6424: A use-after-free in FontFaceSet resulted in a potentially exploitable crash. CVE-2025-6425: An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing

CISA warns the Signal clone used by natsec staffers is being attacked, so patch now
23andMe’s new owner says your DNA is safe this time
ESET Threat Report H1 2025: Key findings

ESET Chief Security Evangelist Tony Anscombe reviews some of the report’s standout findings and their implications for organizations in 2025 and beyond

ESET APT Activity Report Q4 2024–Q1 2025: Malware sharing, wipers and exploits

ESET experts discuss Sandworm’s new data wiper, UnsolicitedBooker’s relentless campaigns, attribution challenges amid tool-sharing, and other key findings from the latest APT Activity Report

Swiss government warns attackers have stolen sensitive data, after ransomware attack at Radix
CISA Warns of CVSS 9.3 MICROSENS NMP Web+ Flaws
US imposes sanctions on second Russian bulletproof hosting vehicle this year

* bsc#1230092 Cross-References: * CVE-2024-45310

Cl0p cybercrime gang’s data exfiltration tool found vulnerable to RCE attacks
Anonymity should not be free
How to use editable installs for Python packages
Meet Zig: The modern alternative to C
UK eyes new laws as cable sabotage blurs line between war and peace

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that an exploit for CVE-2025-6554 exists in the wild.

Australian airline Qantas reveals data theft impacting six million customers

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5955-1

Microsoft admits to Intune forgetfulness
International Criminal Court swats away ‘sophisticated and targeted’ cyberattack
The AI Fix #57: AI is the best hacker in the USA, and self-learning AI
The Rise of Rust-Based Malware: Memory Safetys Double-Edged Sword
50 customers of French bank hit after insider helped SIM swap scammers
Download the ‘AI-ready data centers’ spotlight report
Terrible tales of opsec oversights: How cybercrooks get themselves caught
The private cloud comeback
How to shift left on finops, and why you need to
Proton bashes Apple and joins antitrust suit that seeks to throw the App Store wide open

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

US shuts down a string of North Korean IT worker scams
British IT worker sentenced to seven months after trashing company network
Scattered Spider crime spree takes flight as focus turns to aviation sector
Sinaloa drug cartel hired a cybersnoop to identify and kill FBI informants

* bsc#1232908 * bsc#1232927 * bsc#1232929 * bsc#1233680 * bsc#1233708

Multiple vulnerabilities have been fixed in catdoc, a text extractor for MS-Office files. CVE-2024-48877

Cloud finally gets some new competition
Rewriting infrastructure as code for the AI data center
Three steps to boost Amazon S3 data security

USN-7582-1 introduced a regression in Samba.

Your browser has ad tech’s fingerprints all over it, but there’s a clean-up squad in town

* bsc#1243711 * bsc#1243712 Cross-References: * CVE-2025-48797

Canada orders Chinese CCTV biz Hikvision to quit the country ASAP
It’s 2025 and almost half of you are still paying ransomware operators

https://security-tracker.debian.org/tracker/DSA-5954-1

This month in security with Tony Anscombe – June 2025 edition

From Australia’s new ransomware payment disclosure rules to another record-breaking DDoS attack, June 2025 saw no shortage of interesting cybersecurity news

Resolves CVE-2024-38824 RHBZ#2372731 Resolves CVE-2024-38824 RHBZ#2372733 Resolves CVE-2025-22239 RHBZ#2372732 Resolves CVE-2025-22239 RHBZ#2372734 Resolves CVE-2025-22236 RHBZ#2372774

Update to release v1.32.6

4.4.9

Update to version 0.16.1 for various bugfixes. This also fixes CVE-2025-22872 in the bundled golang.org/x/net/html.

Resolves CVE-2024-38824 RHBZ#2372731 Resolves CVE-2024-38824 RHBZ#2372733 Resolves CVE-2025-22239 RHBZ#2372732 Resolves CVE-2025-22239 RHBZ#2372734 Resolves CVE-2025-22236 RHBZ#2372774

Update to release v1.32.6

https://security-tracker.debian.org/tracker/DSA-5953-1

ESET Threat Report H1 2025

A view of the H1 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts

Ex-NATO hacker: ‘In the cyber world, there’s no such thing as a ceasefire’
Red Hat Advanced Cluster Security 4.8 simplifies management, enhances workflows and offers deeper external IP visibility
BreachForums broken up? French police arrest five members of notorious cybercrime site

Update to 138.0.7204.49 CVE-2025-6555: Use after free in Animation CVE-2025-6556: Insufficient policy enforcement in Loader CVE-2025-6557: Insufficient data validation in DevTools

Automatic update for podman-5.5.2-1.fc41. security fix for CVE-2025-6032 Changelog for podman * Tue Jun 24 2025 Packit – 5:5.5.2-1 – Update to 5.5.2 upstream release

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

xorg-x11-server CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

Crims are posing as insurance companies to steal health records and payment info
Google touts Python client library for Data Commons

https://security-tracker.debian.org/tracker/DSA-5951-1

Cisco punts network-security integration as key for agentic AI
Aloha, you’ve been pwned: Hawaiian Airlines discloses ‘cybersecurity event’
So you CAN turn an entire car into a video game controller
Data spill in aisle 5: Grocery giant Ahold Delhaize says 2.2M affected after cyberattack

* bsc#1232908 * bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062

* bsc#1235231 Cross-References: * CVE-2024-56601

SafePay ransomware: What you need to know
Rust-powered: Two new Python tools to watch
Dumping mainframes for cloud can be a costly mistake

* bsc#1239948 * bsc#1244304 * bsc#1244503 Cross-References:

Rust 1.88 adds support for naked functions

https://security-tracker.debian.org/tracker/DSA-5952-1

https://security-tracker.debian.org/tracker/DSA-5950-1

FBI used bitcoin wallet records to peg notorious IntelBroker as UK national
What if Microsoft just turned you off? Security pro counts the cost of dependency
Cisco fixes two critical make-me-root bugs on Identity Services Engine components