Menu

Category Archives: All

Everything

GitHub hit by a sophisticated malware campaign as ‘Banana Squad’ mimics popular repos
IBM combines governance and security tools to solve the AI agent oversight crisis
Attack on Oxford City Council exposes 21 years of election worker data
Qilin offers “Call a lawyer” button for affiliates attempting to extort ransoms from victims who won’t pay
The hyperscalers disrupt the sovereign cloud disruptors
Developers set the pace for genAI tools adoption

https://security-tracker.debian.org/tracker/DSA-5944-1

Boffins devise voice-altering tech to jam ‘vishing’ schemes
Uncle Sam seeks time in tower dump data grab case after judge calls it ‘unconstitutional’
Glazed and confused: Hole lotta highly sensitive data nicked from Krispy Kreme

It was discovered that an Out Of Memory error may occur when attempting to initialize a huge byte array, even when maxFrameSize is set. For Debian 11 bullseye, this problem has been fixed in version

* bsc#1234415 * bsc#1234450 * bsc#1234453 * bsc#1234455 * bsc#1234456

UK gov asks university boffins to pinpoint cyber growth areas where it should splash cash

Several security issues were fixed in Samba.

Updates to Red Hat Advanced Cluster Security for Kubernetes Cloud Service strengthen your security posture
Taking advantage of Microsoft Edge’s built-in AI
Firecrawl: Easy web data extraction for AI applications

Several security issues were fixed in Express.

* bsc#1238681 * bsc#1239192 Cross-References: * CVE-2025-22868

Sneaky Serpentine#Cloud slithers through Cloudflare tunnels to inject orgs with Python-based malware
Iran’s internet goes offline for hours amid claims of ‘enemy abuse’
Google previews Gemini 2.5 Flash-Lite
Parasoft C/C++test adds AI assistant
Smashing Security podcast #422: The curious case of the code copier
Minecraft cheaters never win … but they may get malware

https://security-tracker.debian.org/tracker/DSA-5943-1

Ransomware gang busted in Thailand hotel raid
Retail versus finance: How genAI coding strategies diverge
Asana’s cutting-edge AI feature ran into a little data leakage problem
Veeam patches third critical RCE bug in Backup & Replication in space of a year

* bsc#1154353 * bsc#1156395 * bsc#1170891 * bsc#1173139 * bsc#1184350

* bsc#1244039 Cross-References: * CVE-2024-47081

* bsc#1244039 Cross-References: * CVE-2024-47081

* bsc#1244039 Cross-References: * CVE-2024-47081

OpenAI’s o3 price plunge changes everything for vibe coders
Better together: Developing web apps with Astro and Alpine
Get started with Python type hints
How to bridge the MFA gap
Amazon CISO: Iranian hacking crews ‘on high alert’ since Israel attack
Trump administration set to waive TikTok sell-or-die deadline for a third time
AWS locks down cloud security, hits 100% MFA enforcement for root users
Sitecore CMS flaw let attackers brute-force ‘b’ for backdoor
The AI Fix #55: Atari beats ChatGPT at chess, and Apple says AI “thinking” is an illusion
Redefining identity security in the age of agentic AI

Ready, set, pack! Summer travel season is here and that means family road trips, beach vacations, international adventures and more. While summertime is prime time for getaways, did you know it’s also prime time for online fraud? Scammers are targeting the travel industry, putting millions of travelers at increased risk. Research shows that the travel […]

23andMe hit with £2.3M fine after exposing genetic data of millions
Malicious PyPI package targets Chimera users to steal AWS tokens, CI/CD secrets

* bsc#1223096 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

Secure RHEL Clones Chart Diverging Paths

Django could be made to log injection if received specially crafted input.

Amazon Bedrock faces revamp pressure amid rising enterprise demands
Navigating the rising costs of AI inferencing
A developer’s guide to AI protocols: MCP, A2A, and ACP
Design a better customer experience with agentic AI

Update to 128.11.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/

Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags() Fixes CVE-2025-48432: Potential log injection via unescaped request path

Rebuild for CVE-2024-12224, CVE-2025-4574

Rebuild against idna 1.0+ for CVE-2024-12224

Java 25 to change Windows file operation behaviors
Scattered Spider has moved from retail to insurance
Remorseless extortionists claim to have stolen thousands of files from Freedman HealthCare
Canada’s WestJet says ‘expect interruptions’ online as it navigates cybersecurity turbulence
Eurocops arrest suspected Archetyp admin, shut down mega dark web drug shop
Salesforce study finds LLM agents flunk CRM and confidentiality tests
Microsoft adds export option to Windows Recall in Europe

* bsc#1215935 * bsc#1215936 * bsc#1233606 * bsc#1233608 * bsc#1233609

* bsc#1242015 Cross-References: * CVE-2025-3891

Databricks Data + AI Summit 2025: Five takeaways for data professionals, developers
Spy school dropout: GCHQ intern jailed for swiping classified data

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The key to Oracle’s AI future
Understanding how data fabric enhances data security and governance
Top 6 multicloud management solutions
Rethinking the dividing lines between containers and VMs

Several security issues were fixed in ModSecurity.

How collaborative security can build you a better business
Armored cash transport trucks allegedly hauled money for $190 million crypto-laundering scheme
Optimizing Linux Security in 2025: Key Strategies & Best Practices
Dems demand audit of CVE program as Federal funding remains uncertain

A stack-based buffer overflow has been fixed in ICU, a C++ and C library for Unicode and Globalization support. For Debian 11 bullseye, this problem has been fixed in version

Two vulnerabilities have been fixed in cJSON, a C library for parsing JSON. CVE-2023-26819

An input sanitization flaw in Konsole might allow remote attackers to execute commands via a malicious URL

An integer overflow vulnerability has been found in sysstat which could result in arbitrary code execution.

Fix CVE-2025-49112 Fix CVE-2025-49112

Security update

New version 4.4.7 Ignoring potential error when using udevadm in %post scriptlet

Update to 137.0.7151.103 CVE-2025-5958: Use after free in Media CVE-2025-5959: Type Confusion in V8

Bert ransomware: what you need to know
Why Denmark is breaking up with Microsoft

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574

Update to 3.12.11. gh-135034: [CVE 2024-12718] [CVE 2025-4138] [CVE 2025-4330] [CVE 2025-4435] [CVE 2025-4517] Fixes multiple issues that allowed tarfile extraction filters (filter=”data” and filter=”tar”) to be bypassed using crafted symlinks and hard links.

Fix CVE-2025-49466 (fedora#2370375)

Cyber weapons in the Israel-Iran conflict may hit the US
SmartBear unveils AI-driven test automation for iOS and Android apps