Menu

Category Archives: All

Everything

US infrastructure could crumble under cyberattack, ex-NSA advisor warns

Several vulnerabilities were discovered in modsecurity-apache, an Apache module to tighten the Web application security, which may result in denial of service (high memory consumption).

New libvpx packages are available for Slackware 15.0 and -current to fix security issues.

Enterprises are getting stuck in AI pilot hell, say Chatterbox Labs execs

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data.

Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump. (CVE-2025-4598) References:

Security constraint bypass for CGI scripts. (CVE-2025-46701) References: – https://bugs.mageia.org/show_bug.cgi?id=34332 – https://openwall.com/lists/oss-security/2025/05/29/4

Update to version 4.21.6

Add patch for double free

Fix CVE-2025-23016

Marks & Spencer’s ransomware nightmare – more details emerge
US offers $10 million reward for tips about state-linked RedLine hackers

Update to Samba 4.22.2 – Security fix for CVE-2025-0620

Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink

This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.

Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink

This update includes mod_security version 2.9.9 which addresses CVE-2025-47947 and includes various bug fixes. See https://github.com/owasp- modsecurity/ModSecurity/releases/tag/v2.9.9 for more information on the changes in this release.

ChatGPT used for evil: Fake IT worker resumes, misinfo, and cyber-op assist
BladedFeline: Whispering in the dark

ESET researchers analyzed a cyberespionage campaign conducted by BladedFeline, an Iran-aligned APT group with likely ties to OilRig

Fresh strain of pro-Russian wiper flushes Ukrainian critical infrastructure
Smashing Security podcast #420: Fake Susies, flawed systems, and fruity fixes for anxiety
Uncle Sam moves to seize $7.7M laundered by North Korean IT worker ring

* bsc#1243268 Cross-References: * CVE-2025-47287

* bsc#1236826 * bsc#1239671 * bsc#1241012 Cross-References:

* bsc#1240392 Cross-References: * CVE-2025-2704

* bsc#1236974 Cross-References: * CVE-2024-12243

Your ransomware nightmare just came true – now what?

Several security issues were fixed in the Linux kernel.

Decentralized mesh cloud: A promising concept
JavaScript innovation and the culture of programming

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-24223

https://security-tracker.debian.org/tracker/DSA-5937-1

https://security-tracker.debian.org/tracker/DSA-5938-1

https://security-tracker.debian.org/tracker/DSA-5939-1

Uncle Sam puts $10M bounty on RedLine dev and Russia-backed cronies
AT&T not sure if new customer data dump is déjà vu
Adobe adds Product Support Agent for AI-assisted troubleshooting
Cellebrite buys Corellium to help cops bust phone encryption
Trump’s cyber czar pick grilled over CISA cuts: ‘If we have a cyber 9/11, you’re the guy’
Snowflake: Latest news and insights
BidenCash busted as Feds nuke stolen credit card bazaar
Workday’s new dev tools help enterprises connect with external agents
More than a hundred backdoored malware repos traced to single GitHub user
HMRC: Crooks broke into 100k accounts, stole £43M from British taxpayer in late 2024

Several security issues were fixed in Bootstrap.

Automating devops with Azure SRE Agent
How to test your Java applications with JUnit 5

Several security issues were fixed in the Linux kernel.

* bsc#1243332 * bsc#1243422 * bsc#1243423 Cross-References:

* bsc#1243313 Cross-References: * CVE-2025-47273

* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References:

AI kept 15-year-old zombie vuln alive, but its time is drawing near
China accuses Taiwan of running five feeble APT gangs, with US help
IBM Cloud login breaks for second time this week and Big Blue isn’t saying why

https://security-tracker.debian.org/tracker/DSA-5936-1

Play ransomware crims exploit SimpleHelp flaw in double-extortion schemes
AI is powering enterprise development, GitHub says
Ukraine strikes Russian bomber-maker with hack attack
Ransomware scum leak patient data after disrupting chemo treatments at Kettering
Snowflake customers must choose between performance and flexibility
Fake IT support calls hit 20 orgs, end in stolen Salesforce data and extortion, Google warns
The AI Fix #53: An AI uses blackmail to save itself, and threats make AIs work better
Crims stole 40,000 people’s data from our network, admits publisher Lee Enterprises
UK CyberEM Command to spearhead new era of armed conflict
Naming is easy! A guide for developers
New to Rust? Don’t make these common mistakes
JavaScript promises: 4 gotchas and how to avoid them
Ukraine war spurred infosec vet Mikko Hyppönen to pivot to drones
‘Deliberate attack’ deletes shopping app’s AWS and GitHub resources

https://security-tracker.debian.org/tracker/DSA-5935-1

Meta pauses mobile port tracking tech on Android after researchers cry foul
Kotlin cozies up to Spring Framework
You say Cozy Bear, I say Midnight Blizzard, Voodoo Bear, APT29 …

https://security-tracker.debian.org/tracker/DSA-5934-1

Snowflake acquires Crunchy Data for enterprise-grade PostgreSQL to counter Databricks’ Neon buy
Google quietly pushes emergency fix for Chrome 0-day as exploit runs wild
Snowflake takes aim at legacy data workloads with SnowConvert AI migration tools
X’s new ‘encrypted’ XChat feature seems no more secure than the failure that came before it

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to “*.example.com”, a request to “[::1%25.example.com]:80` will incorrectly match and not be proxied – CVE-2025-22870.

Crooks fleece The North Face accounts with recycled logins
Don’t let dormant accounts become a doorway for cybercriminals

Do you have online accounts you haven’t used in years? If so, a bit of digital spring cleaning might be in order.

C# 14 introduces file-based apps
Snowflake’s Cortex AISQL aims to simplify unstructured data analysis

Several security issues were fixed in the Linux kernel.

Microsoft patches the patch that put Windows 11 in a coma
Snowflake launches Openflow to tackle AI-era data ingestion challenges
The Hidden Security Risks of Open-Source AI
Illicit crypto-miners pouncing on lazy DevOps configs that leave clouds vulnerable

Open VM Tools could be made to overwrite files as the administrator.

The high cost of misconfigured DevOps: Global cryptojacking hits enterprises
Bling slinger Cartier tells customers to be wary of phishing attacks after intrusion
Real-time analytics with StarTree Cloud and Apache Pinot
3 cloud migration secrets

Several security issues were fixed in MariaDB.

The month of June is a time for fun in the sun and a break from the school year, but did you know it’s also the perfect time to step up your family’s online security? June is Internet Safety Month, a yearly reminder to strengthen your defenses against online threats. In today’s hyper-connected world, we […]

Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Various other fixes

Two security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2025-47779

Ukrainians smuggle drones hidden in cabins on trucks to strike Russian airfields