The Ramnit botnet that is said to have affected 3.2 million computers has been shut down by European police.
After the Anthem mega-breach, questions abound about possible abuses of medical data. Here is a breakdown that offers some context.
A pair of possible exploits in hardware and software used for playing Blu-ray discs have come to light, reports PC World.
A widespread, long-standing security flaw that allows attackers to decrypt HTTPS-protected traffic between certain device and potentially millions of websites has been uncovered by security researchers, reports Ars Technica.
In this post, we lift the veil on Casper – another piece of software that we believe to have been created by the same organization that is behind Babar and Bunny.
There are many female researchers and computer experts who contribute to the field, helping everyone enjoy safer technology. We spoke to one of the most prominent: Lysa Myers, a member of our research team in the US.
An attempt to silence feminism blog Femsplain backfires on DDoS attackers, as they only help to raise its profile.
A number of seemingly unconnected Western websites were hacked over the weekend, with messages claiming Islamic State as the perpetrator.
iOS and OS X the most vulnerable operating systems? Don’t confuse vulnerabilities with exploits, or patch frequency with insecurity.
ESET assess the differences between CryptoFortress and TorrentLocker: two very different strains of ransomware.
One thing Microsoft has been very public about is Windows 10’s new strategy of releasing patches to update the operating system at different times for consumer and enterprise versions.
Apple fans keen to get their hands on the Apple Watch are advised to think before they click, after hackers exploited a wave of enthusiasm around the launch with a phishing scam linked to a fake giveaway.
IT teams’ time is always limited, and it doesn’t help when other things get in the way. Here’s seven things that waste your IT team’s time.
* bsc#1239460 Cross-References: * CVE-2025-24049
An update that fixes one vulnerability is now available.
This update includes an upstream patch to accept “0” as a valid epoch in Debian packages processed by BSSolv. This fixes a bug that prevents the Open Build Service backend from working
* bsc#1207948 * bsc#1215199 * bsc#1215211 * bsc#1218470 * bsc#1221651
Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/
Expat could be made to crash if it received specially crafted input.
* bsc#1240416 Cross-References: * CVE-2025-31344
* bsc#1240416 Cross-References: * CVE-2025-31344
Net::EasyTCP Perl module includes encryption functionality that requires a secure random number generator. Until and including the version 0.26, this module used a random number generator without any such guarantees. The reason for this was that it relied on Crypt::Random, a Perl module
Prior to version 0.008, the Perl module Data::Entropy relied on Perl’s builtin rand function to choose an entropy source. Version 0.008 does away with this need.
https://security-tracker.debian.org/tracker/DSA-5897-1
* bsc#1236217 * bsc#1239182 * bsc#1240550 Cross-References:
* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6
* bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029
5.0.0
Update to 0.4.8; Fixes: RHBZ#2237964, RHBZ#2282129
Fix CVE-2024-12905.
Address CVE-2025-30093 – rhbz#2355671
5.0.0
Fix CVE-2024-12905.
Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions
Backport fixes from v1.127.1
This is an update fixing CVE 2025-30232.
Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions
CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355026) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355024) CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow
This is an update fixing CVE 2025-30232.
https://security-tracker.debian.org/tracker/DSA-5893-1
https://security-tracker.debian.org/tracker/DSA-5894-1
https://security-tracker.debian.org/tracker/DSA-5895-1
https://security-tracker.debian.org/tracker/DSA-5896-1
https://security-tracker.debian.org/tracker/DSA-5892-1
Imagine waking up one day to find that someone has stolen your identity, opened credit cards in your name, or even withdrawn money from your bank accounts. It’s something that can easily happen if your personal data falls into the hands of cybercriminals. In our interconnected world, data breaches and identity theft are a constant […]
* bsc#1229122 * bsc#1240550 Cross-References: * CVE-2025-22871
Upgrade to 2.48.0: Move tile rendering to worker threads when rendering with the GPU. Fix preserve-3D intersection rendering. Added new function for creating Promise objects to the JavaScriptCore GLib API. The MediaRecorder backend gained WebM support (requires at least GStreamer
Several security issues were fixed in the Linux kernel.
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. (CVE-2024-56161)
* bsc#1228012 * bsc#1228578 * bsc#1233023 Cross-References:
