Menu

Category Archives: Security

Articles about security

Britain eyes satellite laser warning system and carrier-launched jet drones

* bsc#1250715 Cross-References: * CVE-2025-11226

* bsc#1249036 Cross-References: * CVE-2025-9375

* bsc#1230028 Affected Products: * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7

* bsc#1243701 Cross-References: * CVE-2025-48708

* bsc#1243701 Cross-References: * CVE-2025-48708

* bsc#1250452 Affected Products: * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7

UK Home Office opens wallet for £60M automated number plate project
Credential stuffing: £2.31 million fine shows passwords are still the weakest link
Scattered Lapsus$ Hunters offering $10 in Bitcoin to ‘endlessly harass’ execs

poppler could be made to crash if it opened a specially crafted file.

Squid could be made to crash if it received specially crafted network traffic.

Discord users’ data stolen by hackers in third-party data breach

Several security issues were fixed in MySQL.

Radiant Group won’t touch kids’ data now, but apparently hospitals are fair game
Thieves steal IDs and payment info after data leaks from Discord support vendor

CVE-2025-27613 With Gitk, the Git history browser, when a user clones an untrusted repository and runs gitk without additional command arguments,

Optimizing queries by using observability
Jaguar Land Rover engines ready to roar again after weeks-long cyber stall
Clop crew hits Oracle E-Business Suite users with fresh zero-day
AI’s biggest supply chain shortage is people
How self-learning AI agents will reshape operational workflows
13 clever APIs for capturing every kind of data
Leak suggests US government is fibbing over FEMA security failings

jupyterlab 4.4.9 fixing CVE-2025-59842.

jupyterlab 4.4.9 fixing CVE-2025-59842.

Update to latest upstream version.

Resolve CVE-2025-47910

Updated to latest upstream (143.0.3)

Update to latest upstream version.

https://security-tracker.debian.org/tracker/DSA-6019-1

Multiple vulnerabilities were discovered in log4cxx, a logging library for C++ that is compatible with the JAVA log4j framework. CVE-2025-54812

How Red Hat can support your journey to a standard operating environment
Security update: Incident related to Red Hat Consulting GitLab instance

4.0.6.3221

fix rhbz#2397702

fix rhbz#2397703

4.0.6.3221

Important: pcs security update

Important: perl-File-Find-Rule security update

Japan running dry: Ransomware attack leaves nation days away from Asahi beer shortage
Red Hat fesses up to GitLab breach after attackers brag of data theft
Apple ices ICE agent tracker app under government heat
Munich Airport chaos after drone sightings spook air traffic control

* bsc#1235237 Cross-References: * CVE-2024-55553

UK government says digital ID won’t be compulsory – honest
Oracle tells Clop-targeted EBS users to apply July patch, problem solved
IBM launches Granite 4.0 to cut AI infra costs with hybrid Mamba-transformer models
Who stops wasteful cloud spending?
The JavaScript code won’t write itself
What is an internal developer platform? IDP explained
Criminals take Renault UK customer data for a joyride
Microsoft unveils framework for building agentic AI apps

New upstream release (143.0.3)

CVE-2025-7493: host to admin escalation prevention: https://www.freeipa.org/release-notes/4-12-5.html Update FreeIPA to latest fixes from ipa-4-12 branch

Update to 7.1.2.

cve fixes

Security update for path traversal CVE-2025-59825 / GHSA-3wgq-wrwc-vqmv.

https://security-tracker.debian.org/tracker/DSA-6017-1

https://security-tracker.debian.org/tracker/DSA-6018-1

Chainguard offers malware-resistant JavaScript libraries
Subpoena tracking platform blames outage on AWS social engineering attack

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Clop-linked crims shake down Oracle execs with data theft claims
EU funds are flowing into spyware companies, and politicians are demanding answers
Why Software Supply Chain Security Matters in Linux Systems

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Cybercrims claim raid on 28,000 Red Hat repos, say they have sensitive customer files
Why observability needs Apache Iceberg
Using Microsoft’s Data API builder for Azure databases
How to deploy machine learning models with AWS Lambda
Claude Sonnet 4.5 coding model improves agentic capabilities

https://security-tracker.debian.org/tracker/DSA-6016-1

Smashing Security podcast #437: Salesforce’s trusted domain of doom
Your favourite phone apps might be leaking your company’s secrets
US gov shutdown leaves IT projects hanging, security defenders a skeleton crew
‘Delightful’ root-access bug in Red Hat OpenShift AI allows full cluster takeover
Air Force admits SharePoint privacy issue as reports trickle out of possible breach
Microsoft .NET Aspire backs .NET 10 file-based apps
3.7M breach notification letters set to flood North America’s mailboxes
AI agent hypefest crashing up against cautious leaders, Gartner finds
Imgur yanks Brit access to memes as parent company faces fine
Spotlight report: Securing the cloud
Explain digital ID or watch it fizzle out, UK PM Starmer told
PDM: A smarter way to manage Python packages
Why we need junior developers
Intro to Nitro: The server engine built for modern JavaScript
Schools are swotting up on security yet still flunk recovery when cyberattacks strike

Several security issues were fixed in the Linux kernel.

An issue was found in open-vm-tools, a set of tools for VMs hosted on VMware. The issue is related to a local privilege escalation in combination with the get-versions.sh script, shipped with the service

Beijing-backed burglars master .NET to target government web servers

BIRD 3.1.4 (2025-09-22) BGP: Fixed crash on Notification with a message, CVE-2025-59688 BGP: Fixed invalid memory access in pending TX flush BGP: Fixed a rare bug with listening socket delay Pipe: Disabled statisticts for stopping pipe

Update to version 1.6.2. Includes fixes for CVE-2025-58066 (potential DoS in the ntpd-rs server) and CVE-2025-58160 (potential tracing log pollution).

Update to 2.0.1 to CVE-2025-30187

Update the ammonia crate to version 4.1.2 and rebuild python-nh3 to apply fixes for RUSTSEC-2025-0071.

https://security-tracker.debian.org/tracker/DSA-6015-1