Menu

Category Archives: Security

Articles about security

Strap in, get ready for more Rust drivers in Linux kernel
Microsoft admits GitHub hosted malware that infected almost a million devices
India wants backdoors into clouds, email, SaaS, for tax inspectors

Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles

Unbundle libxml2.

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in

Microsoft previews AI chat template for .NET
Kernel saunters – How Apple rearranged its XNU kernel with exclaves

Two vulnerabilities were discovered in openvpn, a virtual private network application which could result in authentication bypass or data injection.

High CVE-2025-1914: Out of bounds read in V8. Medium CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools. Medium CVE-2025-1916: Use after free in Profiles. Medium CVE-2025-1917: Inappropriate Implementation in Browser UI.

Update to 134.0.6998.35 * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles

The newest upstream commit Security fix for CVE-2025-27423

update to version 2.25.1, CVE-2025-27154

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2. (CVE-2023-5520) Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV. (CVE-2024-0321) Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

Developer sabotaged ex-employer with kill switch activated when he was let go

https://security-tracker.debian.org/tracker/DSA-5876-1

Microsoft reportedly struggling to build its own reasoning models to rival OpenAI
JFrog unveils JFrog ML for MLOps

https://security-tracker.debian.org/tracker/DSA-5875-1

Uncle Sam charges alleged Garantex admins after crypto-exchange web seizures
Alleged cyber scalpers Swiftly cuffed over $635K Taylor ticket heist
Anthropic’s upgraded Console targets more collaboration among developers
Like whitebox servers, rent-a-crew crime ‘affiliates’ have commoditized ransomware

Several security issues were fixed in the Linux kernel.

When to choose a bare-metal cloud
JavaScript tools and frameworks we’re watching now

Updated to latest upstream (136.0)

Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian

Refresh patches Add -std=gnu17 to CFLAGS to fix the build 042-man2html-CVE-2021-40647.patch Add more patches from Debian

The Badbox botnet is back, powered by up to a million backdoored Androids
Alibaba says its new AI model rivals DeepSeeks’s R-1, OpenAI’s o1
Visual Studio Code 1.98 shines on GitHub Copilot
International cops seize ransomware crooks’ favorite Russian crypto exchange
Uncle Sam mulls policing social media of all would-be citizens

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Several security issues were fixed in Ansible.

Toronto Zoo ransomware crooks snatch decades of visitor data
Up to $75M needed to fix up rural hospital cybersecurity as ransomware gangs keep scratching at the door

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

The key new features in .NET 10
Portkey: An open-source AI gateway for easy LLM orchestration
How to handle type erasure in advanced Java generics
Cybereason CEO leaves after months of boardroom blowups

Updated to latest upstream (136.0)

The newest upstream commit Security fix for CVE-2025-27423

Feds name and charge alleged Silk Typhoon spies behind years of China-on-US attacks
Smashing Security podcast #407: HP’s hold music, and human trafficking

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

C++ founder champions profiles for memory safety
Ex-NSA grandee says Trump’s staff cuts will ‘devastate’ America’s national security

https://security-tracker.debian.org/tracker/DSA-5873-1

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

China’s Silk Typhoon, tied to US Treasury break-in, now hammers IT and govt targets
Cactus ransomware: what you need to know
Apple drags UK government to court over ‘backdoor’ order
Fake police call cryptocurrency investors to steal their funds

Several security issues were fixed in the Linux kernel.

* bsc#1237683 Cross-References: * CVE-2024-43097 * CVE-2025-1930

Several security issues were fixed in the Linux kernel.

Leeds United kick card swipers into Row Z after 5-day cyberattack

A security issue was fixed in Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Qilin ransomware gang claims attacks on cancer clinic, OB-GYN facility
How prevention is better than cure
Ransomware thugs threaten Tata Technologies with leak if demands not met

https://security-tracker.debian.org/tracker/DSA-5874-1

VMware splats guest-to-hypervisor escape bugs already exploited in wild
The AI Fix #40: ChatGPT saved my life, and making evil AIs by accident
Embracing AI and Machine Learning Frameworks on Linux
CISA refutes claims it has been ordered to stop monitoring Russian cyber threats
How Google tracks Android device users before they’ve even opened an app
Does Microsoft’s Majorana chip meet enterprise needs?
Why genAI-powered intelligent document processing is a big deal
Teradata adds Enterprise Vector Store to augment RAG
It’s bad enough we have to turn on cams for meetings, now the person staring at you may be an AI deepfake
Plugging the holes in open banking

Several security issues were fixed in cmark-gfm.

So … Russia no longer a cyber threat to America?

Several security issues were fixed in spip.

wpa_supplicant and hostapd could be made to expose sensitive information over the network.

TypeScript 5.8 reaches general availability

Use-after-free of the root cursor. (CVE-2025-26594) Buffer overflow in XkbVModMaskText(). (CVE-2025-26595) Heap overflow in XkbWriteKeySyms(). (CVE-2025-26596) Buffer overflow in XkbChangeTypesOfKey(). (CVE-2025-26597) Out-of-bounds write in CreatePointerBarrierClient(). (CVE-2025-26598)

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Cybersecurity not the hiring-’em-like-hotcakes role it once was

March is a time for leprechauns and four-leaf clovers, and as luck would have it, it’s also a time to learn how to protect your private data from cybercrime. Each year, the first week of March (March 2-8) is recognized as National Consumer Protection Week (NCPW). During this time, many government agencies and consumer protection […]

Stop targeting Russian hackers, Trump administration orders US Cyber Command
Microsoft unveils finalized EU Data Boundary as European doubt over US grows
Polish space agency confirms cyberattack

* bsc#1237284 * bsc#1237287 Cross-References: * CVE-2024-57256

* bsc#1236974 Cross-References: * CVE-2024-12243

* bsc#1236974 Cross-References: * CVE-2024-12243

UK watchdog investigates TikTok and Reddit over child data privacy concerns
Governments can’t seem to stop asking for secret backdoors