* bsc#1065729 * bsc#1179878 * bsc#1180814 * bsc#1185762 * bsc#1195823
* bsc#1240971 Cross-References: * CVE-2025-32464
* bsc#1240958 * bsc#1240961 * bsc#1240962 * bsc#1240963 * bsc#1240964
* bsc#1228714 * bsc#1232818 * bsc#1235218 * bsc#1238788 * bsc#1238790
Perl could be made to crash or run programs if it processed specially crafted data.
* bsc#1065729 * bsc#1180814 * bsc#1183682 * bsc#1190336 * bsc#1190768
* bsc#1228714 * bsc#1232818 * bsc#1235218 * bsc#1238788 * bsc#1238790
* bsc#1228714 * bsc#1235218 Cross-References: * CVE-2024-41090
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, cross-site scripting or restriction bypass.
Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation
Update to 6.0.39 (CVE-2024-45700, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699)
Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation
https://security-tracker.debian.org/tracker/DSA-5901-1
https://security-tracker.debian.org/tracker/DSA-5902-1
Multiple vulnerabilities were found in wpa, a set of tools including the widely-used wpasupplicant client for authenticating with WPA and WPA2 wireless networks.
A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN. (CVE-2025-32364) Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. (CVE-2025-27795) References: – https://bugs.mageia.org/show_bug.cgi?id=34163
https://security-tracker.debian.org/tracker/DSA-5900-1
https://security-tracker.debian.org/tracker/DSA-5899-1
Update to 1.34.5. Fixes CVE-2025-31498.
Limit the data stored in session state. Remove the empty area below the title bar in Web Inspector when not docked. Fix various crashes and rendering issues
Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions
Update to 7.2.5 (CVE-2024-36469, CVE-2024-42325, CVE-2024-45700)
* bsc#1073014 Cross-References: * CVE-2017-17521
* bsc#1239618 * jsc#PED-12500 * jsc#SLE-21253 Cross-References:
For most of us, tax season is all about finding documents, filling out forms, and crossing your fingers you’re getting a refund. But while you’re busy trying to get your returns filed on time, tax scammers and identity thieves are busy trying to steal your precious personal information. During tax season, a vast amount of […]
Update to 2025.04 GA Update to 2025.04 RC5
Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/
https://security-tracker.debian.org/tracker/DSA-5898-1
Corporate data breaches are a gateway to identity fraud, but they’re not the only one. Here’s a lowdown on how your personal data could be stolen – and how to make sure it isn’t.
When a ruse puts on a familiar face, your guard might drop, making you an easy mark. Learn how to tell a friend apart from a foe.
The computer scientist and AI researcher shares her thoughts on the technology’s potential and pitfalls – and what may lie ahead for us
From an exploited vulnerability in a third-party ChatGPT tool to a bizarre twist on ransomware demands, it’s a wrap on another month filled with impactful cybersecurity news
ESET researchers also examine the growing threat posed by tools that ransomware affiliates deploy in an attempt to disrupt EDR security solutions
Once thought to be dormant, the China-aligned group has also been observed using the privately-sold ShadowPad backdoor for the first time
Your company’s ability to tackle the ransomware threat head-on can ultimately be a competitive advantage
Security awareness training doesn’t have to be a snoozefest – games and stories can help instill ‘sticky’ habits that will kick in when a danger is near
ESET researchers uncover the toolset used by the FamousSparrow APT group, including two undocumented versions of the group’s signature backdoor, SparrowDoor
ESET researchers detail a global espionage operation by FishMonger, the APT group run by I‑SOON
The group’s Operation AkaiRyū begins with targeted spearphishing emails that use the upcoming World Expo 2025 in Osaka, Japan, as a lure
Here’s what’s been hot on the AI scene over the past 12 months, how it’s changing the face of warfare, and how you can fight AI-powered scams
ESET researchers discover new ties between affiliates of RansomHub and of rival gangs Medusa, BianLian, and Play
While relatively rare, real-world incidents impacting operational technology highlight that organizations in critical infrastructure can’t afford to dismiss the OT threat
Listen up, this is sure to be music to your ears – a few minutes spent securing your account today can save you a ton of trouble tomorrow
