Menu

Category Archives: Security

Articles about security

Intro to Ktor: The server-side stack
Why you should use Docker and OCI containers
Microsoft fixes under-attack privilege-escalation holes in Hyper-V
Angular team unveils strategy for 2025

https://security-tracker.debian.org/tracker/DSA-5844-1

FBI wipes Chinese PlugX malware from thousands of Windows PCs in America
Snyk appears to deploy ‘malicious’ packages targeting Cursor for unknown reason
It’s not just Big Tech: The UK’s Online Safety Act applies across the board
UK floats ransomware payout ban for public sector
The cloud cost wake-up call I predicted
The journey towards a knowledge graph for generative AI

* bsc#1233712 Cross-References: * CVE-2024-50264

* bsc#1225819 * bsc#1228349 * bsc#1228786 * bsc#1229273 * bsc#1229553

* bsc#1225819 * bsc#1233712 Cross-References: * CVE-2023-52752

* bsc#1228573 * bsc#1229273 * bsc#1229553 * bsc#1232637 * bsc#1233712

* bsc#1229553 * bsc#1232637 * bsc#1233712 Cross-References:

* bsc#1210619 * bsc#1220537 * bsc#1223363 * bsc#1223683 * bsc#1225011

Miscreants ‘mass exploited’ Fortinet firewalls, ‘highly probable’ zero-day used

https://security-tracker.debian.org/tracker/DSA-5843-1

CISA publishes security goals for software development process, product design
Cryptojacking, backdoors abound as fiends abuse Aviatrix Controller bug

In today’s cyber threat landscape, good enough is no longer good enough. Cyberattacks don’t clock out at 5 PM, and neither can your security strategy. For Managed Service Providers (MSPs), offering customers 24/7 cybersecurity protection and response isn’t just a competitive advantage—it’s an essential service for business continuity, customer trust, and staying ahead of attackers. […]

Microsoft sues ‘foreign-based’ cyber-crooks, seizes sites used to abuse AI
Pastor’s “dream” crypto scheme alleged to be a multi-million dollar scam
Azure, Microsoft 365 MFA outage locks out users across regions
NATO’s newest member comes out swinging following latest Baltic Sea cable attack
Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days
An introduction to using tcpdump at the Linux command line

Several security issues were fixed in snapd.

Nominet probes network intrusion linked to Ivanti zero-day exploit
Yes, you should use coding assistants—but not like that
Open source trends for 2025 and beyond
The devops certifications tech companies want
Europe coughs up €400 to punter after breaking its own GDPR data protection rules

Several security issues were fixed in libxmltok.

https://security-tracker.debian.org/tracker/DSA-5842-1

An issue has been found in gnuchess, a tool to play a game of chess, either against the user or against itself. The issue is related to arbitrary code execution via crafted PGN (Portable

Out of Bounds Memory Read/Write in libjxl. (CVE-2024-11403) Resource exhaustion via Stack overflow in libjxl. (CVE-2024-11498) References: – https://bugs.mageia.org/show_bug.cgi?id=33818

Avahi wide-area dns uses constant source port. (CVE-2024-52615) Avahi wide-area dns predictable transaction ids. (CVE-2024-52616) References: – https://bugs.mageia.org/show_bug.cgi?id=33829

Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function. (CVE-2024-29645) References:

Command injection via RzBinInfo bclass due legacy code. (CVE-2022-1207) References: – https://bugs.mageia.org/show_bug.cgi?id=33895 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/YNDCM5TGWRLSMIJ74ZI6LMNSCCH5DBPL/

Various security, performance, accuracy, and stability issues have been fixed.

work around debugedit bug to fix aarch64 builds xen-hypervisor %post doesn’t load all needed grub2 modules update to xen-4.19.1 which includes Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818] libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819]

https://security-tracker.debian.org/tracker/DSA-5841-1

The fix for CVE-2024-6923 in the python3.9 source package which was released as part of a suite of updates in DLA 3980-1 [0] introduced safer processing of input in the email module to order to increase the security around email header injection attacks.

Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-10394), fileserver crashes and information leak on StoreACL/FetchACL (CVE-2024-10396) or buffer overflows in XDR

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or privilege escalation.

Important: kernel-rt security update

Important: webkit2gtk3 security update

Oracle refuses to yield JavaScript trademark, Deno Land says
Chinese cyber-spies peek over shoulder of officials probing real-estate deals near American military bases
Drug addiction treatment service admits attackers stole sensitive patient data
Canadian man loses a cryptocurrency fortune to scammers – here’s how you can stop it happening to you

* jsc#PED-11136 Cross-References: * CVE-2024-12678 * CVE-2024-25131

Ephemeral environments in cloud-native development
Why JavaScript’s still on top in 2025
Cohere goes ‘North’ with agentic AI

* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:

Devs sent into security panic by ‘feature that was helpful … until it wasn’t’

* bsc#1234991 Cross-References: * CVE-2025-0237 * CVE-2025-0238

Rust 1.84 introduces strict provenance APIs
Researchers build a bridge from C to Rust and memory safety
Look for the label: White House rolls out ‘Cyber Trust Mark’ for smart devices

https://security-tracker.debian.org/tracker/DSA-5839-1

Smashing Security podcast #399: Honey in hot water, and reset your devices
Space Bears ransomware: what you need to know
Zero-day exploits plague Ivanti Connect Secure appliances for second year running
Security pros baited with fake Windows LDAP exploit traps

* bsc#1235029 Cross-References: * CVE-2024-56826

United Nations aviation agency hacked, recruitment database plundered

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Working with minimal APIs in .NET
How to use the new Lock object in C# 13

xfpt could be made to crash or run programs if it opened a specially crafted file.

Thunderbird could be made to bypass security restrictions.

Several security issues were fixed in Firefox.

Japanese police claim China ran five-year cyberattack campaign targeting local orgs

Updated to latest upstream (134.0)

Database tables of student, teacher info stolen from PowerSchool in cyberattack

https://security-tracker.debian.org/tracker/DSA-5840-1

I tried hard, but didn’t fix all of cybersecurity, admits outgoing US National Cyber Director
GlassFish update fixes restart hangs, random 403 responses
Mitel 0-day, 5-year-old Oracle RCE bug under active exploit
DNA sequencers found running ancient BIOS, posing risk to clinical research
UN’s aviation agency confirms attack on recruitment database
Oracle offers price-performance boost with Exadata X11M update
Building generative AI applications is too hard, developers say

* bsc#1082555 * bsc#1176081 * bsc#1206344 * bsc#1213034 * bsc#1218562

* bsc#1082555 * bsc#1157160 * bsc#1218644 * bsc#1221977 * bsc#1222364

Tinyproxy could be made to crash or run programs if it received specially crafted input.

Crims backdoored the backdoors they supplied to other miscreants. Then the domains lapsed
Intro to Ktor: The HTTP server for Kotlin
Why the C programming language still rules

* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:

Akamai to quit its CDN in China, seemingly not due to trouble from Beijing