Menu

Category Archives: Security

Articles about security

WhatsApp API worked exactly as promised, and stole everything
Linux Kernel Encryption Changes Prevent Physical Hardware Attacks
Why IPv6 Influences Linux Firewall Behavior and Exposure Risks
React2Shell: How a Framework Bug Drives Full Linux Compromise
When is an AI agent not really an agent?

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves 65 vulnerabilities and has 11 security fixes can now be installed.

An update that solves 65 vulnerabilities and has 11 security fixes can now be installed.

An update that solves eight vulnerabilities and has two security fixes can now be installed.

An update that solves eight vulnerabilities and has two security fixes can now be installed.

Stop letting ‘urgent’ derail delivery. Manage interruptions proactively
Microsoft previews C++ code editing tools for GitHub Copilot
Poisoned WhatsApp API package steals messages and accounts
Palo Alto’s new Google Cloud deal boosts AI integration, could save on cloud costs
Spy turned startup CEO: ‘The WannaCry of AI will happen’
Hacktivists scrape 86M Spotify tracks, claim their aim is to preserve culture
Conman and wannabe MI6 agent must repay £125k to romance scam victim
Cursor owner Anysphere agrees to buy Graphite code review tool
Explore 2026 Secure Linux Distros for Enhanced Privacy and Security
Around 1,000 systems compromised in ransomware attack on Romanian water agency
Turning automation spend into a measurable advantage
Attestation vs. integrity in a zero-trust world
Building AI agents the safe way
6 AI breakthroughs that will define 2026
8 old programming languages developers won’t quit

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

There’s so much stolen data in the world, South Korea will require face scans to buy a SIM

It was discovered that usbmuxd, USB multiplexor daemon for iPhone and iPod Touch devices, incorrectly handled certain paths received with the SavePairRecord command. A local attacker could possibly use this issue to delete and write files named *.plist in arbitrary locations. For Debian 11 bullseye, this problem has been fixed in version

Erik Krogh Kristensen and Rasmus Petersen from the GitHub Security Lab discovered a ReDoS (Regular Expression Denial of Service) vulnerability in python-mechanize, a library to automate interaction with websites modeled after the Perl module WWW::Mechanize, which could lead to Denial of Service when parsing a malformed authentication header.

Fixes CVE-2025-58188, unretire package and update to 3.8.2.

Update to pgadmin-9.11, fixes CVE_2025-13780.

Through gritted teeth, Apple and Google allow alternative app stores in Japan
Google sends Dark Web Report to its dead services graveyard
NIST tried to pull the pin on NTP servers after blackout caused atomic clock drift

MGASA-2025-0331 – Updated webkit2 packages fix security vulnerabilities

MGASA-2025-0330 – Updated php packages fix security vulnerabilities

32.0.3 release, fixes RHBZ# 2420196 RHBZ# 2420197 RHBZ# 2420198 RHBZ# 2421368

Update to cef-143.0.10+g8aed01b + chromium-143.0.7499.146 (rhbz#2423482) High CVE-2025-14765: Use after free in WebGPU High CVE-2025-14766: Out of bounds read and write in V8 High CVE-2025-13630: Type Confusion in V8 High CVE-2025-13631: Inappropriate implementation in Google Updater

Update to uriparser-1.0.0, fixes CVE-2025-67899.

fix setpwnam() buffer use [CVE-2025-14104] libblkid: use snprintf() instead of sprintf()

https://security-tracker.debian.org/tracker/DSA-6088-1

https://security-tracker.debian.org/tracker/DSA-6089-1

https://security-tracker.debian.org/tracker/DSA-6090-1

https://security-tracker.debian.org/tracker/DSA-6091-1

https://security-tracker.debian.org/tracker/DSA-6087-1

https://security-tracker.debian.org/tracker/DSA-6086-1

https://security-tracker.debian.org/tracker/DSA-6085-1

SNMP: CACTI Command Execution Risk Advisory for Linux Administrators

Update to 0.2.8

Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on

Update to 2.22.11

Update to 17.0.0 version (#2412270) Update fonttools 4.61.0

Update to 17.0.0 version (#2412270) Update fonttools 4.61.0

Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on

ATM jackpotting gang accused of unleashing Ploutus malware across US
WatchGuard sounds alarm as critical Firebox flaw comes under active attack
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions

Sydney Uni data goes walkabout after criminals raid code repo
Snowflake software update caused 13-hour outage across 10 regions
Enterprise automation resilience with EDB and Red Hat Ansible Automation Platform
Red Hat to acquire Chatterbox Labs: Frequently Asked Questions
Accelerating NetOps transformation with Ansible Automation Platform
HPE tells customers to patch fast as OneView RCE bug scores a perfect 10

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Ministers confirm breach at UK Foreign Office but details remain murky
Faith in the internet is fading among young Brits
AI and cybersecurity: Two sides of the same coin

An update that solves four vulnerabilities can now be installed.

PHP version 8.4.16 (18 Dec 2025) Core: Sync all boost.context files with release 1.86.0. (mvorisek) Fixed bug GH-20435 (SensitiveParameter doesn’t work for named argument passing to variadic parameter). (ndossche)

China turns on a vast experimental network it says is an heir to ARPANET
Amazon blocked 1,800 suspected North Korean scammers seeking jobs
Your car’s web browser may be on the road to cyber ruin
Python type checker ty now in beta
Crypto crooks co-opt stolen AWS creds to mine coins
Kim’s crypto thieving reached a record $2B in 2025
Another bad week for SonicWall as SMA 1000 zero-day under active exploit
FBI dismantles alleged $70M crypto laundering operation

It was discovered that c-ares, a library that performs DNS requests and name resolution asynchronously, does not properly handle termination of queries which may result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 1.34.5-1+deb13u1.

NHS tech supplier probes cyberattack on internal systems
React2Shell exploitation spreads as Microsoft counts hundreds of hacked machines
DVSA’s clapped-out booking system gets bot slapped as new boss rides in
UK surveillance law still full of holes, watchdog warns
What’s next for Azure infrastructure
High-performance programming with Java streams
Designing the agent-ready data stack

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

JetBrains releases Kotlin 2.3.0
Smashing Security podcast #448: The Kindle that got pwned

https://security-tracker.debian.org/tracker/DSA-6083-1

https://security-tracker.debian.org/tracker/DSA-6084-1

Attacks pummeling Cisco AsyncOS 0-day since late November