Menu

Category Archives: Security

Articles about security

Not seeing ROI from your AI? Observability may be the missing link

* bsc#1236136 Cross-References: * CVE-2024-13176

* bsc#1236518 Cross-References: * CVE-2023-45288

* bsc#1236460 Cross-References: * CVE-2022-49043

Google patches odd Android kernel security bug amid signs of targeted exploitation
Why digital resilience is critical to banks

Updated to 132.0.6834.159 * Medium CVE-2025-0762: Use after free in DevTools

Linux Foundation warns of US OFAC sanctions
TSA’s airport facial-recog tech faces audit probe

When it comes to endpoint detection and response (EDR) compatibility within an MDR offering, managed service providers (MSPs) are weighing two key priorities: native EDR integration or the flexibility to support multiple solutions. According to a recent OpenText survey, opinions are split almost evenly. While 52% of MSPs view native compatibility as moderately or very […]

EU supports AI challenge to Silicon Valley and China
Download the Agentic AI Enterprise Spotlight
Responding to Chrome’s Latest Security Vulnerabilities: Update to Chrome 132 Now!
2 officers bailed as anti-corruption unit probes data payouts to N Irish cops
The DeepSeek lesson
Tetragon: Extending eBPF and Cilium to runtime security
Solver can code that for you

* bsc#1236518 Cross-References: * CVE-2023-45288

* bsc#1236272 Cross-References: * CVE-2024-11218 * CVE-2024-9407

* bsc#1236272 Cross-References: * CVE-2024-11218 * CVE-2024-9407

Matthias Gerstner reported that pam-u2f, a PAM module which allows to use U2F (Universal 2nd Factor) devices in the PAM authentication stack, does not properly handle PAM_IGNORE return values, allowing to bypass the second factor or password-less login without inserting the proper

Privacy Commissioner warns the ‘John Smiths’ of the world can acquire ‘digital doppelgangers’
Medical monitoring machines spotted stealing patient data, users warned to pull the plug ASAP

https://security-tracker.debian.org/tracker/DSA-5857-1

JavaScript Temporal to ease dates and times

Several issues have been found in ffmpeg, a package that contains tools for transcoding, streaming and playing of multimedia files Those issues are related to possible integer overflows, double-free on

What does it mean to build in security from the ground up?
Gilmore Girls fans nabbed as Eurocops dismantle two major cybercrime forums
Monitoring Red Hat Ansible Automation Platform using Performance Co-Pilot

Data Privacy Week (Jan. 27-31) is an excellent opportunity to reflect on the importance of protecting one of your most valuable assets: your personal information. Whether you’re browsing online as a consumer or running a business, data privacy is paramount in an environment where cyber threats can lurk around every corner. In the spirit of […]

Cyber threats have never been more relentless, and businesses of all sizes are feeling the pressure. That’s where Managed Detection and Response (MDR) comes in—a lifeline for overburdened security teams navigating a threat landscape that’s growing more sophisticated by the day. At its core, MDR is about augmenting, complementing, and upskilling internal security operations. It’s […]

update to 0.10.4

Updated to 132.0.6834.159 * Medium CVE-2025-0762: Use after free in DevTools

Rebase to 20.18.2 Resolves: CVE-2025-22150 CVE-2025-23085 CVE-2025-23083

Update to version 18.20.6 (rhbz#2341760) (rhbz#2340936) (rhbz#2300997) Resolves CVE-2025-23084

Rebase to 20.18.2 Resolves: CVE-2025-22150 CVE-2025-23085 CVE-2025-23083

Update to version 18.20.6 (rhbz#2341760) (rhbz#2340936) (rhbz#2300997) Resolves CVE-2025-23084

New ASPA support is now always compiled in and available if enable-aspa is set. The aspa Cargo feature has been removed. (#990) If merging mutliple ASPA objects for a single customer ASN results in more than 16,380 provider ASNs, the ASPA is dropped. (Note that ASPA objects with more

JavaScript dates and times will get easier soon

An update that fixes one vulnerability is now available.

Multiple vulnerabilities have been fixed in DCMTK, a collection of libraries and applications implementing large parts the DICOM standard for medical images.

Vanilla upstream kernel version 6.6.74 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33968

Microsoft’s new DocumentDB rethinks NoSQL on PostgreSQL
The Big Short on Cybersecurity

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Another banner year for ransomware gangs despite takedowns by the cops
The quantum computing reality check
Plunge into Python: New tools and tips for Python developers
Google to Iran: Yes, we see you using Gemini for phishing and scripting. We’re onto you
TypeScript 5.8 arrives in beta
Data resilience and data portability
VMware plugs steal-my-credentials holes in Cloud Foundation

https://security-tracker.debian.org/tracker/DSA-5854-1

https://security-tracker.debian.org/tracker/DSA-5853-1

Trump admin’s purge of US cyber advisory boards was ‘foolish,’ says ex-Navy admiral
Ransomware attack at New York blood services provider – donors turned away during shortage crisis

* bsc#1236518 Cross-References: * CVE-2023-45288

Canvassing apps used by UK political parties riddled with privacy, security issues
Streamline the connectivity between your environment and Red Hat Insights services
WFH with privacy? 85% of Brit bosses snoop on staff
Sourcegraph unveils AI coding agents
Browser Use: An open-source AI agent to automate web-based tasks
Microsoft’s new DocumentDB builds on PostgreSQL

* bsc#1228770 Cross-References: * CVE-2013-4235

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Tomcat could be made to run programs if it received specially crafted network traffic.

Several security issues were fixed in jinja2.

VLC could be made to crash or run programs if it received specially crafted network traffic.

Wacom says crooks probably swiped customer credit cards from its online checkout
Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek
Smashing Security podcast #402: Hackers get hacked, the British Museum IT shutdown, and social media kidnaps

https://security-tracker.debian.org/tracker/DSA-5855-1

https://security-tracker.debian.org/tracker/DSA-5856-1

North Koreans clone open source projects to plant backdoors, steal credentials
Async closure support is stable for Rust 1.85
Java-based organizations mostly use Java for AI development – report
Why is my Mitel phone DDoSing strangers? Oh, it was roped into a new Mirai botnet
Transform your approach to data security

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

‘Bro delete the chat’: Feel the panic shortly before cops bust major online fraud ring
Ex-worker arrested after ‘shutdown’ of British Museum computer systems
Doing authentication right
4 tiny Docker images for lightweight containers
The biggest ideas in software and technology today
Spending watchdog blasts UK govt over sloth-like cyber resilience progress