Menu

Category Archives: Security

Articles about security

* bsc#1236619 * jsc#PED-12018 Cross-References: * CVE-2025-24528

* bsc#1233760 Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6

How Secure Is Linux? Examining Features That Ensure Safety
Secure Your DevTools: Critical UAF Vulnerability Warning
Firefox 135 Released: Key Updates & Advanced Browser Protection Features
Tails 6.12: An Essential Privacy, Security, and Reliability Upgrade

USN-7206-3 caused some regression in rsync.

Google’s generative AI Toolbox for Databases to help connect agents with databases
UK armed forces fast-tracking cyber warriors to defend digital front lines
When LLMs become influencers
Are database administrators doomed?
Will Kubernetes ever get easier?

* bsc#1236596 Cross-References: * CVE-2024-11187

Judge says US Treasury ‘more vulnerable to hacking’ since Trump let the DOGE out
India’s banking on the bank.in domain cleaning up its financial services sector
DeepSeek’s iOS app is a security nightmare, and that’s before you consider its TikTok links

https://security-tracker.debian.org/tracker/DSA-5862-1

Huawei revenue growing fast, suggesting China’s scoffing at sanctions

https://security-tracker.debian.org/tracker/DSA-5861-1

Vulnerabilities were found in sssd, a set of daemons to manage access to remote directories and authentication mechanisms, which could lead to privilege escalation.

update to 1.33.0

Security fix for CVE-2023-52892, CVE-2024-27354

Add code to deal with sched_setattr() not being exported in glibc 2.41 Address CVE-2024-54159 denial of services via symlink attack

Update to 1.17.3 Fixes CVE-2024-0134 or GHSA-7jm9-xpwx-v999 Fixes CVE-2024-0135 or GHSA-9v84-cc9j-pxr6, CVE-2024-0136 or GHSA- vcfp-63cx-4h59, and CVE-2024-0137 or GHSA-frhw-w3wm-6cw4

New ASPA support is now always compiled in and available if enable-aspa is set. The aspa Cargo feature has been removed. (#990) If merging mutliple ASPA objects for a single customer ASN results in more than 16,380 provider ASNs, the ASPA is dropped. (Note that ASPA objects with more

Updated to latest upstream (135.0)

Update to 0.8.4

xrdp allows an infinite number of login attempts. (CVE-2024-39917) References: – https://bugs.mageia.org/show_bug.cgi?id=33985 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/FMYGECEBC7XEBNQ2ZHXYRQBLCMHHXKP5/

When an input DER data contains a large number of SEQUENCE OF or SET OF elements, decoding the data and searching a specific element in it take quadratic time to complete. This could be utilized for a remote DoS attack by presenting a crafted certificate to the network peer.

Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.

Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.

https://security-tracker.debian.org/tracker/DSA-5860-1

UK Home Office silent on alleged Apple backdoor order

* bsc#1236270 Cross-References: * CVE-2024-11218

UK industry leaders unleash hurricane-grade scale for cyberattacks
Data breaches at UK law firms are on the rise, research reveals

A vulnerability has been discovered in the OpenJDK Java runtime, which may result in authorisation bypass or information disclosure. For Debian 11 bullseye, this problem has been fixed in version

The hidden threat of neglected cloud infrastructure
Full-stack JavaScript leads the way
Apple missed screenshot-snooping malware in code that made it into the App Store, Kaspersky claims

Updated to latest upstream (135.0)

If Ransomware Inc was a company, its 2024 results would be a horror show

Fix CVE-2025-0781

Fix CVE-2025-0781

GitHub Copilot previews agent mode
Coordinates of millions of smartphones feared stolen, sparking yet another lawsuit against data broker
Federal judge tightens DOGE leash over critical Treasury payment system access

https://security-tracker.debian.org/tracker/DSA-5859-1

Dems want answers on national security risks posed by hiring freeze, DOGE probes
Oracle maintains hold on JavaScript trademark
Thailand cuts power and internet to areas of Myanmar to disrupt scam gangs

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Google rolls out cheaper AI model as industry scrutinizes costs
Using NATS with .NET Aspire

Several security issues were fixed in Ruby.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Several security issues were fixed in CKEditor.

Democrats demand to know WTF is up with that DOGE server on OPM’s network

Fix for CVE-2025-0781

Robocallers who phoned the FCC pretending to be from the FCC land telco in trouble
Smashing Security podcast #403: Coinbase crypto heists, QR codes, and ransomware in the classroom
Mixing Rust and C in Linux likened to cancer by kernel maintainer
Malicious package found in the Go ecosystem

What are passkeys? You may have seen the term “passkeys” appearing more frequently in tech news, app updates, and security discussions. Major companies like Apple, Google, and Microsoft are rolling out passkeys as a replacement for passwords, promising both enhanced security and a smoother user experience. But what exactly are passkeys, and why are they […]

Digma Preemptive Observability Analysis engine tackles AI code bugs
DOGE latest: Citrix supremo has ‘read-only’ access to US Treasury payment system

Simplifying security management is an important step toward better protection without sacrificing operational efficiency. With the added capability of automating processes by integrating with popular tools, security management can also deliver streamlined workflows. OpenText Secure Cloud provides billing reconciliation by integrating with popular tools such as HaloPSA, ConnectWise PSA, AutoTask, and Kaseya BMS so you […]

Netgear fixes critical bugs as Five Eyes warn about break-ins at the edge
Man sentenced to 7 years in prison for role in $50m internet scam
Is 2025 the year of quantum computing?
US cranks up espionage charges against ex-Googler accused of trade secrets heist
Common Vulnerability Scoring System (CVSS) vs. Risk: Why are we still having this conversation?
Databricks acquires BladeBridge to aid data warehouse migrations
Cloud development environments for the win
How to make lightweight Docker images (and keep them slim)
Smart Traffic Enforcement: Kazakhstan’s Qorgau System in Action

OpenJDK 23 could be made to expose sensitive information over the network.

OpenJDK 21 could be made to expose sensitive information over the network.

OpenJDK 17 could be made to expose sensitive information over the network.

OpenJDK 11 could be made to expose sensitive information over the network.

USN-7096-1 caused some minor regressions in OpenJDK 8.

AWS tightens default security on Redshift

Rebuilt against golang-x-net 0.33.0 for CVE-2024-45338

Rust update fixes ‘forever’ compilation

https://security-tracker.debian.org/tracker/DSA-5858-1

Google: How to make any AMD Zen CPU always generate 4 as a random number
Automated builds, tests, and quality gates are key to software quality – report
The AI Fix #36: A DeepSeek special
Poisoned Go programming language package lay undetected for 3 years
Grubhub serves up security incident with a side of needing to change your password
US accuses Canadian math prodigy of $65M crypto scheme
Cyberattack on NHS causes hospitals to miss cancer care targets
Abandoned AWS S3 buckets can be reused in supply-chain attacks that would make SolarWinds look ‘insignificant’
Anthropic unveils new framework to block harmful content from AI models
UK govt must learn fast and let failing projects die young
Public cloud providers are missing the mark with AI
What you need to know about developing AI agents