Menu

Category Archives: Security

Articles about security

Metal maker meltdown: Nucor stops production after cyber-intrusion

It was discovered that insecure file handling in open-vm-tools, an open source implementation of VMware Tools, may allow an unprivileged local guest user to tamper local files to trigger insecure file operations within that VM.

* bsc#1230959 * bsc#1231748 * bsc#1232326 * bsc#1240366 * bsc#1240607

Why CVSS is failing us and what we can do about it
Uncle Sam pulls $2.4B Leidos deal to support CISA after rival alleges foul play
How can we counter online disinformation? | Unlocked 403 cybersecurity podcast (S2E2)

Ever wondered why a lie can spread faster than the truth? Tune in for an insightful look at disinformation and how we can fight one of the most pressing challenges facing our digital world.

Ivanti patches two zero-days under active attack as intel agency warns customers
Meta’s still violating GDPR rules with latest plan to train AI on EU user data, says noyb
VPN Secure parent company CEO explains why he had to axe thousands of ‘lifetime’ deals
Two years’ jail for down-on-his-luck man who sold ransomware online
Boomi launches agentic AI tools, announces AWS collaboration
Informatica adds agents to automate its Intelligent Data Management Cloud
Go ahead and ignore Patch Tuesday – it might improve your security
Everyone’s deploying AI, but no one’s securing it – what could go wrong?
How to use template strings in Python 3.14
The three refactorings every developer needs most

A vulnerability has been discovered in FreeType, which can lead to remote code execution.

Abseil could be made to crash if it received specially crafted input.

Ransomware scum have put a target on the no man’s land between IT and operations
Scala stabilizes named tuples

Update to 136.0.7103.92 CVE-2025-4372: Use after free in WebAudio

Apple patched one first, but Microsoft’s blasted five exploited flaws this Pa-Tu

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Intel’s data-leaking Spectre defenses scared off yet again
Qatar’s $400M jet for Trump is a gold-plated security nightmare
Commvault fixes critical Command Center issue after flaw finder alert
The AI Fix #50: AI brings dead man back for killer’s trial, and the judge loves it
‘We still have embeds in CISA’: CTO of Brit cyber agency talks post-Trump relationship with US counterpart
4 key capabilities of Kong’s Event Gateway for real-time event streams
Emerging ClickFix Attacks Are Now Targeting Linux Systems
Marks & Spencer admits cybercrooks made off with customer info
Google to unveil AI agent for developers at I/O, expand Gemini integration
As US vuln-tracking falters, EU enters with its own security bug database
Agentic mesh: The future of enterprise agent ecosystems
How to use genAI for requirements gathering and agile user stories
What ‘cloud first’ can teach us about ‘AI first’

* bsc#1242008 * bsc#1242009 Cross-References: * CVE-2025-31650

Several security issues were fixed in the Linux kernel.

Türkiye-linked spy crew exploited a messaging app zero-day to snoop on Kurdish army in Iraq

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5918-1

M365 apps on Windows 10 to get security fixes into 2028
C# 14 introduces extension members
CISA mutes own website, shifts routine cyber alerts to Musk’s X, RSS, email
Why aggregating your asset inventory leads to better security
Attackers pwn charter airline helping Trump’s deportation campaign

Unlimited output buffer for unauthenticated clients has been fixed in the key¢”value database Redis. For Debian 11 bullseye, this problem has been fixed in version

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

A vulnerability has been discovered in Orc, which can lead to arbitrary code execution

Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in arbitrary code execution.

Britain’s cyber agents and industry clash over how to tackle shoddy software
What software developers need to know about cybersecurity
How to build (real) cloud-native applications
MySQL at 30: Still important but no longer king
Unending ransomware attacks are a symptom, not the sickness
DOGE worker’s old creds found exposed in infostealer malware dumps
You think ransomware is bad now? Wait until it infects CPUs

PDF signature forgery with adbe.pkcs7.sha1 SubFilter. (CVE-2025-2866) References: – https://bugs.mageia.org/show_bug.cgi?id=34234 – https://lists.debian.org/debian-security-announce/2025/msg00070.html

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on

Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function. (CVE-2025-31162) Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.

https://deluge.readthedocs.io/en/deluge-2.2.0/changelog.html 2.2.0 (2025-04-28) Breaking changes Removed Python 3.6 support (Python >= 3.7) Core

5.22.9

Update to version 22.15.0

GenAI isn’t taking software engineering jobs, but it is reshaping leadership roles
Catching a phish with many faces

Here’s a brief dive into the murky waters of shape-shifting attacks that leverage dedicated phishing kits to auto-generate customized login pages on the fly

Feds disrupt proxy-for-hire botnet, indict four alleged net miscreants
UK Ministry of Defence is spending less with US biz, and more with Europeans
Visual Studio Code beefs up AI coding features

Update to 47.7 notably fixing CVE-2025-3839

xz 5.8.1

xz 5.8.1

xz 5.8.1

xz 5.8.1

Fixes CVE-2025-47256 .

https://security-tracker.debian.org/tracker/DSA-5917-1

Beware of phone scams demanding money for ‘missed jury duty’

When we get the call, it’s our legal responsibility to attend jury service. But sometimes that call won’t come from the courts – it will be a scammer.

Sizing up the AI code generators
VC behemoth Insight Partners fears top-secret financial info swiped by cyber-miscreants
GenAI won’t take software engineering jobs, but is reshaping leadership

It all starts so innocently. You get a text saying “Your package couldn’t be delivered. Click here to reschedule.”  Little do you know, clicking that link could open the door for scammers to steal your identity, empty your bank account, or even plant malicious software (malware) on your device. Unless you know what to look out […]

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

openSUSE deep sixes Deepin desktop over security stink

* bsc#1224259 Cross-References: * CVE-2024-4853

* bsc#1242210 Cross-References: * CVE-2025-32873

* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References:

The dual challenge: Security and compliance
Trust and authenticity: In the kitchen and the software supply chain
LockBit ransomware gang breached, secrets exposed
Hackers hit deportation airline GlobalX, leak flight manifests, and leave an unsubtle message for “Donnie” Trump
Cloud repatriation hits its stride