Menu

Category Archives: Security

Articles about security

What the loom tells us about AI and coding
Generative UI: The AI agent is the front end

An update that solves three vulnerabilities and has two security fixes can now be installed.

An update that solves three vulnerabilities and has two security fixes can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

MGAA-2026-0003 – Updated isodumper packages fix bugs

MGAA-2026-0002 – Updated sddm-theme-coffee-ng packages fix bug

AI won’t replace human devs for at least 5 years
Automated data poisoning proposed as a solution for AI theft threat
Red Team Blue Team Insights for Linux Admins: Key Security Roles Explained
HackerOne ‘ghosted’ me for months over $8,500 bug bounty, says researcher

https://security-tracker.debian.org/tracker/DSA-6095-1

Ruby 4.0.0 introduces ZJIT compiler, Ruby Box isolation
Brightspeed investigates breach as crims post stolen data for sale

https://security-tracker.debian.org/tracker/DSA-6094-1

Fake Windows BSODs check in at Europe’s hotels to con staff into running malware
Crypto wallet shop Ledger confirms customer data lifted in Global-e snafu
Open WebUI bug turns the ‘free model’ into an enterprise backdoor
Students bag extended Christmas break after cyber hit on school IT
UK injects just £210M into cyber plan to stop Whitehall getting pwnd
What drives your cloud security strategy?
Generative AI and the future of databases
Coinbase insider who sold customer data to criminals arrested in India

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

One criminal, 50 hacked organizations, and all because MFA wasn’t turned on

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

C# wins Tiobe Programming Language of the Year honors for 2025

https://security-tracker.debian.org/tracker/DSA-6093-1

Congrats, cybercrims: You just fell into a honeypot

An update that solves 70 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

Moderate: postgresql:15 security update

Playing Koi: Palo Alto isn’t saying if it will buy security start-up
Gmail preparing to drop POP3 mail fetching
New Zealand orders review into ManageMyHealth cyberattack
How to make AI agents reliable
6 incredibly hyped software trends that failed to deliver

A vulnerability was found in Curl, an easy-to-use client-side URL transfer library and command line tool. It can cause a crash or potentially a memory out of bounds read. For Debian 11 bullseye, this problem has been fixed in version 7.74.0-1.3+deb11u16.

Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed XCF, JPEG 2000 or PNM files are opened. For the oldstable distribution (bookworm), these problems have been fixed

Trump admin sends heart emoji to commercial spyware makers with lifted Predator sanctions
Palo Alto Networks security-intel boss calls AI agents 2026’s biggest insider threat

Update to 1.148.0

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Bitfinex crypto thief who was serving five years thanks Trump for early release
Cybercrook claims to be selling infrastructure info about three major US utilities
Brit lands invite-only Aussie visa after uncovering vuln in government systems
LockBit takedown architect gets New Year award from King Charles
Back to the future: The most popular JavaScript stories and themes of 2025
Cisco XDR in 30: Turning Security Signals Into Confident Action

https://github.com/wb2osz/direwolf/releases/tag/1.8.1

Correctly handle the program name passed to the sleep disabler. Ensure GStreamer is initialized before using the Quirks. Fix several crashes and rendering issues. Fix CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531, CVE-2025-43535, CVE-2025-43536, CVE-2025-43541

Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442

Update to 2.83.2

https://github.com/wb2osz/direwolf/releases/tag/1.8.1

Two vulnerabilities were discovered in smb4k, a KDE desktop utility which allows unprivileged mounting of Samba/CIFS network shares, which may result in local denial of service or local privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 4.0.0-1+deb13u1.

What is cloud computing? From infrastructure to autonomous, agentic-driven ecosystems
Enterprise Spotlight: Setting the 2026 IT agenda
What’s next for Azure containers?
Critical vulnerability in IBM API Connect could allow authentication bypass

Rebuilt for CVEs

Rebuilt for CVE-2025-47906

Support for Go 1.26 and security fixes. Upstream release notes.

Rebuilt for CVEs

Support for Go 1.26 and security fixes. Upstream release notes.

https://security-tracker.debian.org/tracker/DSA-6092-1

An update that solves three vulnerabilities can now be installed.

European Space Agency hit again as cybercrims claim 200 GB data up for sale
Intro to Hotwire: HTML over the wire
Hong Kong’s newest anti-scam technology is over-the-counter banking

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

NSA: Managing Secure Boot for Linux Against Bootchain Attacks

An update that fixes one vulnerability is now available.

Cybersecurity pros admit to moonlighting as ransomware scum

Update to 1.1.97

Update to 5.8.0

New York’s incoming mayor bans Raspberry Pi at his inauguration party
An early end to the holidays: ‘Heartbleed of MongoDB’ is now under active exploit
This month in security with Tony Anscombe – December 2025 edition

As 2025 draws to a close, Tony looks back at the cybersecurity stories that stood out both in December and across the whole of this year

Nvidia licenses Groq’s inferencing chip tech and hires its leaders

A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file. For Debian 11 bullseye, this problem has been fixed in version

2026: The year we stop trusting any single cloud
How to build RAG at scale

An update that solves four vulnerabilities can now be installed.