Menu

Category Archives: Security

Articles about security

Are we creating too many AI models?
Thread-y or not, here’s Python!
After Chrome patches zero-day used to target Russians, Firefox splats similar bug
Cyber-crew claims it cracked American cableco, releases terrible music video to prove it

CVE-2025-2588

Update to 1.1.43, fixes CVE-2024-55549 and CVE-2025-24855.

Added patch for CVE-2024-4068 (rhbz#2280624)

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

China’s FamousSparrow flies back into action, breaches US org after years off the radar
Adobe announces AI agents for customer interaction

https://security-tracker.debian.org/tracker/DSA-5888-1

Several security issues were fixed in the Linux kernel.

Security shop pwns ransomware gang, passes insider info to authorities
CrushFTP CEO’s feisty response to VulnCheck’s CVE for critical make-me-admin bug

Alexander Tan discovered that the OpenSAML C++ library was susceptible to forging of signed SAML messages. For additional details please refer to the upstream advisory at https://shibboleth.net/community/advisories/secadv_20250313.txt

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

UK’s first permanent facial recognition cameras installed in South London
Ransomwared NHS software supplier nabs £3M discount from ICO for good behavior
Malaysian PM says “no way” to $10 million ransom after alleged cyber attack against Kuala Lumpur airport
What next for WASI on Azure Kubernetes Service?
Smashing Security podcast #410: Unleash the AI bot army against the scammers – now!
Microsoft lauds Hyperlight Wasm for WebAssembly workloads
Signalgate storm intensifies as journalist releases full secret Houthi airstrike chat

https://security-tracker.debian.org/tracker/DSA-5886-1

US defense contractor cops to sloppy security, settles after infosec lead blows whistle
Files stolen from NSW court system, including restraining orders for violence
Credible nerd says stop using atop, doesn’t say why, everyone panics
Critical RCE flaws put Kubernetes clusters at risk of takeover

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239460 Cross-References: * CVE-2025-24049

Databricks’ TAO method to allow LLM training with unlabeled data
NCSC taps influencers to make 2FA go viral
Vibe coding is groovy
Open-source Styrolite project aims to simplify container runtime security
What you need to know about Go, Rust, and Zig
Intro to Alpine.js: A JavaScript framework for minimalists

https://security-tracker.debian.org/tracker/DSA-5887-1

Oracle releases ML-optimized GraalVM for JDK 24
Warning for developers, web admins: update Next.js to prevent exploit
There are perhaps 10,000 reasons to doubt Oracle Cloud’s security breach denial
The AI Fix #43: I, for one, welcome our new robot overlords!
Infosec pro Troy Hunt HasBeenPwned in Mailchimp phish

This upload fixes two security issues in the version of nginx shipped in bullseye. CVE-2024-7347

Fauna to shut down FaunaDB service in May
Google acquires Wiz: A win for multicloud security
Cosmonic uses WebAssembly to manage apps
GenAI tools for R: New tools to make R programming easier
You know that generative AI browser assistant extension is probably beaming everything to the cloud, right?

* bsc#1239465 Cross-References: * CVE-2025-27363

VanHelsing ransomware emerges to put a stake through your Windows heart
Hm, why are so many DrayTek routers stuck in a bootloop?

Several security issues were fixed in SmartDNS.

Public-facing Kubernetes clusters at risk of takeover thanks to Ingress-Nginx flaw

Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens

0.9.30, rebuild due golang CVE-2025-22870

OTF, which backs Tor, Let’s Encrypt and more, sues to save funding from Trump cuts
Top Trump officials text classified Yemen airstrike plans to journo in Signal SNAFU
FCC on the prowl for Huawei and other blocked Chinese makers in America
As nation-state hacking becomes ‘more in your face,’ are supply chains secure?

https://security-tracker.debian.org/tracker/DSA-5885-1

Ivan Fratric discovered two use-after-free vulnerabilities in libxslt, an XSLT processing runtime library, which may result in the execution of arbitrary code if a specially crafted files are processed.

AI agents swarm Microsoft Security Copilot
23andMe’s genes not strong enough to avoid Chapter 11
Anatomy of Linux Ransomware Attacks and Protection Strategies
Is Washington losing its grip on crypto, or is it a calculated pivot to digital dominance?

Two use-after-free vulnerabilities have been fixed in the XSLT processing library libxslt. CVE-2024-55549

Microsoft tastes the unexpected consequences of tariffs on time
OpenTofu becomes the real deal
Prompt engineering courses and certifications tech companies want
Learning AI governance lessons from SaaS and Web2
Mobsters now overlap with cybercrime gangs and use AI for evil, Europol warns

Several security issues were fixed in NLTK.

Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens

China bans compulsory facial recognition and its use in private spaces like hotel rooms
Oracle Cloud says it’s not true someone broke into its login servers and stole data

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-44192

An update that fixes two vulnerabilities is now available.

Ex-NSA boss: Election security focus helped dissuade increase in Russian meddling with US
Mitigating threats against telco networks in the cloud

Update to 4.3.6 (rhbz#2352545)

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

Update to 4.3.6 (rhbz#2352545)

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

Backported fix for CVE-2024-12361 .

This is the monthly update for .NET for March 2025. Release Notes: SDK https://github.com/dotnet/core/blob/main/release-notes/8.0/8.0.14/8.0.114.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.14/8.0.14.md

https://security-tracker.debian.org/tracker/DSA-5884-1

A cross-site scripting vulnerability was discovered in hgweb, the integrated stand-alone web interface of the Mercurial version control system.

Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes

Kotlin bolsters K2 compiler plugin support, WebAssembly debugging

https://security-tracker.debian.org/tracker/DSA-5883-1