Menu

Category Archives: Security

Articles about security

Europol shuts down Ramnit botnet used to steal bank details

The Ramnit botnet that is said to have affected 3.2 million computers has been shut down by European police.

Electronic health records and data abuse: it’s about more than medical info

After the Anthem mega-breach, questions abound about possible abuses of medical data. Here is a breakdown that offers some context.

Blu-ray exploits could allow computer malware infection

A pair of possible exploits in hardware and software used for playing Blu-ray discs have come to light, reports PC World.

FREAK attack: security vulnerability breaks HTTPS protection

A widespread, long-standing security flaw that allows attackers to decrypt HTTPS-protected traffic between certain device and potentially millions of websites has been uncovered by security researchers, reports Ars Technica.

Casper Malware: After Babar and Bunny, Another Espionage Cartoon

In this post, we lift the veil on Casper – another piece of software that we believe to have been created by the same organization that is behind Babar and Bunny.

Lysa Myers: “There are still only a handful of women in the security field”

There are many female researchers and computer experts who contribute to the field, helping everyone enjoy safer technology. We spoke to one of the most prominent: Lysa Myers, a member of our research team in the US.

DDoS attack on feminist blog backfires on International Women’s Day

An attempt to silence feminism blog Femsplain backfires on DDoS attackers, as they only help to raise its profile.

FBI investigating apparent ISIS attacks on Western websites

A number of seemingly unconnected Western websites were hacked over the weekend, with messages claiming Islamic State as the perpetrator.

Operating System Vulnerabilities, Exploits and Insecurity

iOS and OS X the most vulnerable operating systems? Don’t confuse vulnerabilities with exploits, or patch frequency with insecurity.

CryptoFortress mimics TorrentLocker but is a different ransomware

ESET assess the differences between CryptoFortress and TorrentLocker: two very different strains of ransomware.

Will Windows 10 leave enterprises vulnerable to zero-days?

One thing Microsoft has been very public about is Windows 10’s new strategy of releasing patches to update the operating system at different times for consumer and enterprise versions.

Hackers phish for data with fake Apple Watch giveaway

Apple fans keen to get their hands on the Apple Watch are advised to think before they click, after hackers exploited a wave of enthusiasm around the launch with a phishing scam linked to a fake giveaway.

7 tasks that waste your IT team’s time

IT teams’ time is always limited, and it doesn’t help when other things get in the way. Here’s seven things that waste your IT team’s time.

* bsc#1239460 Cross-References: * CVE-2025-24049

Google’s got a hot cloud infosec startup, a new unified platform — and its eye on Microsoft’s $20B+ security biz
Securing Kubernetes and Cloud-Native Environments through DevSecOps

An update that fixes one vulnerability is now available.

This update includes an upstream patch to accept “0” as a valid epoch in Debian packages processed by BSSolv. This fixes a bug that prevents the Open Build Service backend from working

* bsc#1207948 * bsc#1215199 * bsc#1215211 * bsc#1218470 * bsc#1221651

Pharmacist accused of using webcams to spy on women in intimate moments at work, home

Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/

Bad luck, Windows 10 users. No fix yet for ransomware-exploited bug
The AI Fix #45: The Turing test falls to GPT-4.5
Don’t open that JPG sent via WhatsApp for Windows. It might be an .EXE
Beware these 10 malicious VS Code extensions
Scattered Spider stops the Rickrolls, starts the RAT race

Expat could be made to crash if it received specially crafted input.

Mastering SSH for Secure Linux Remote Server Management
Meta launches AI family Llama 4 — but the EU doesn’t get everything
Why is cloud-based AI so hard?

* bsc#1240416 Cross-References: * CVE-2025-31344

* bsc#1240416 Cross-References: * CVE-2025-31344

Net::EasyTCP Perl module includes encryption functionality that requires a secure random number generator. Until and including the version 0.26, this module used a random number generator without any such guarantees. The reason for this was that it relied on Crypt::Random, a Perl module

Russian bots hard at work spreading political unrest on Romania’s internet
Visual Studio Code stabilizes agent mode

Prior to version 0.008, the Perl module Data::Entropy relied on Perl’s builtin rand function to choose an entropy source. Version 0.008 does away with this need.

As CISA braces for more cuts, threat intel sharing takes a hit
Warning to developers: Stay away from these 10 VSCode extensions
Oracle says its cloud was in fact compromised

https://security-tracker.debian.org/tracker/DSA-5897-1

Cloudflare unveils agentic AI development tools
Kotlin, Swift, and Ruby losing popularity – Tiobe index
That massive GitHub supply chain attack? It all started with a stolen SpotBugs token
Alleged Scattered Spider SIM-swapper must pay back $13.2M to 59 victims
Chrome to patch decades-old flaw that let sites peek at your history
UK’s attempt to keep details of Apple ‘backdoor’ case secret… denied
King Bob pleads guilty to Scattered Spider-linked cryptocurrency thefts from investors

* bsc#1236217 * bsc#1239182 * bsc#1240550 Cross-References:

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

* bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029

AI demands more software developers, not less
Language models in generative AI – does size matter?
10 Java-based tools and frameworks for generative AI
What native cloud security tools won’t catch
Asian tech players react to US tariffs with delays, doubts, deal-making
Signalgate solved? Report claims journalist’s phone number accidentally saved under name of Trump official

5.0.0

Update to 0.4.8; Fixes: RHBZ#2237964, RHBZ#2282129

Fix CVE-2024-12905.

Address CVE-2025-30093 – rhbz#2355671

5.0.0

Fix CVE-2024-12905.

Red Hat OpenShift and zero trust: Securing workloads with cert-manager and OpenShift Service Mesh

Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions

Backport fixes from v1.127.1

This is an update fixing CVE 2025-30232.

Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions

CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355026) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355024) CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow

This is an update fixing CVE 2025-30232.

https://security-tracker.debian.org/tracker/DSA-5893-1

https://security-tracker.debian.org/tracker/DSA-5894-1

https://security-tracker.debian.org/tracker/DSA-5895-1

https://security-tracker.debian.org/tracker/DSA-5896-1

https://security-tracker.debian.org/tracker/DSA-5892-1

Critical deserialization bug in Apache Parquet allows RCE
Google Cloud Next ’25: What to expect
Trump fires NSA boss, deputy

Imagine waking up one day to find that someone has stolen your identity, opened credit cards in your name, or even withdrawn money from your bank accounts. It’s something that can easily happen if your personal data falls into the hands of cybercriminals. In our interconnected world, data breaches and identity theft are a constant […]

* bsc#1229122 * bsc#1240550 Cross-References: * CVE-2025-22871

30 minutes to pwn town: Are speedy responses more important than backups for recovery?
Enterprises are getting worse at multicloud
Basking in JavaScript refinements
Alan Turing Institute: UK can’t handle a fight against AI-enabled crims
Ex-ASML, NXP staffer accused of stealing chip secrets, peddling them to Moscow
Retirement funds reportedly raided after unexplained portal probes and data theft

Upgrade to 2.48.0: Move tile rendering to worker threads when rendering with the GPU. Fix preserve-3D intersection rendering. Added new function for creating Promise objects to the JavaScriptCore GLib API. The MediaRecorder backend gained WebM support (requires at least GStreamer

Signalgate: Pentagon watchdog probes Defense Sec Hegseth
Sonatype warns of 18,000 open source malware packages

Several security issues were fixed in the Linux kernel.

For flux sake: CISA, annexable allies warn of hot DNS threat

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. (CVE-2024-56161)

Rust language adds trait upcasting

* bsc#1228012 * bsc#1228578 * bsc#1233023 Cross-References:

Suspected Chinese spies right now hijacking buggy Ivanti gear – for third time in 3 years