Menu

Category Archives: Security

Articles about security

* bsc#1248631 * bsc#1249207 * bsc#1249208 * bsc#1249847 * bsc#1252946

How GlassWorm wormed its way back into developers’ code — and what it says about open source security

This is the October 2025 release of .NET 8. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.21/8.0.121.md Runtime: https://github.com/dotnet/core/blob/main/release-

Update to 141.0.7390.122 High CVE-2025-12036 chromium: Inappropriate implementation in V8 High CVE-2025-11756: Use after free in Safe Browsing High CVE-2025-11458: Heap buffer overflow in Sync High CVE-2025-11460: Use after free in Storage

LLM side-channel attack could allow snoops to guess what you’re talking about
C# rises in Tiobe language popularity index
Critical federal cybersecurity funding set to resume as government shutdown draws to a close – for now
Phishers try to lure 5K Facebook advertisers with fake business pages

An update that solves one vulnerability can now be installed.

* bsc#1249473 Cross-References: * CVE-2025-48041

* bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057

An update that solves two vulnerabilities can now be installed.

* bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057

An update that solves five vulnerabilities and has one security fix can now be installed.

Russian broker pleads guilty to profiting from Yanluowang ransomware attacks
Runtime bugs break container walls, enabling root on Docker hosts
Allianz UK joins growing list of Clop’s Oracle E-Business Suite victims
Hack halts Dutch broadcaster, forcing radio hosts back to LPs
As AI enables bad actors, how are 3,000+ teams responding?
AI is all about inference now
The hidden skills behind the AI engineer
Cisco creating new security model using 30 years of data describing cyber-dramas and saves
Microsoft teases agents that become ‘independent users within the workforce’

https://security-tracker.debian.org/tracker/DSA-6051-1

Data breach at Chinese infosec firm reveals cyber-weapons and target list
Louvre’s pathetic passwords belong in a museum, just not that one

MGASA-2025-0271 – Updated opencontainers-runc packages fix security vulnerabilities

MGASA-2025-0270 – Updated xen packages fix security vulnerabilities

MGASA-2025-0269 – Updated libxml2 & libxslt packages fix security vulnerabilities

MGAA-2025-0092 – Updated qarte packages fix bug

This is the October 2025 release of .NET 9, updating the SDK to version 9.0.111 and runtime to version to 9.0.10. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.10/9.0.111.md

Add CVE and bug fixes to bundled mbedtls in dolphin-emu

In memoriam: David Harley

Former colleagues and friends remember the cybersecurity researcher, author, and mentor whose work bridged the human and technical sides of security

The who, where, and how of APT attacks in Q2 2025–Q3 2025

ESET Chief Security Evangelist Tony Anscombe highlights some of the key findings from the latest issue of the ESET APT Activity Report

Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map
What is generative AI? How artificial intelligence creates content
Microsoft lets shopping bots loose in a sandbox

Rebuild with the latest golang in repos

New upstream stable version 1.22.5

Rebuild with the latest golang in repos

Upgrade to 4.3.4 upstream version. Build with Go 1.24.9 fixes multiple Go CVEs BZ#2408093 BZ#2408688 BZ#2409563 BZ#2410514 BZ#2411412

New version 3.0.2 (rhbz#2407048) Fixes CVE-2025-11232 (rhbz#2407228)

New upstream stable version 1.22.5

Kong Insomnia 12 bolsters AI, MCP tools
Previously unknown Landfall spyware used in 0-day attacks on Samsung phones
ESET APT Activity Report Q2 2025–Q3 2025

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q2 2025 and Q3 2025

Cybercrims plant destructive time bomb malware in industrial .NET extensions

Several security issues were fixed in the Linux kernel.

An update that solves one vulnerability can now be installed.

* bsc#1252749 Cross-References: * CVE-2025-62594

An update that solves one vulnerability can now be installed.

* bsc#1239119 Cross-References: * CVE-2025-30258

Microsoft’s data sovereignty: Now with extra sovereignty!
AWS launches ‘Capabilities by Region’ to simplify planning for cloud deployments
Bank of England says JLR’s cyberattack contributed to UK’s unexpectedly slower GDP growth

The system could be made to expose sensitive information.

NVIDIA’s GTC 2025 A glimpse into our AI-powered future
How TeamViewer builds enterprise trust through security-first design
More Django developers turning to AI – report
We can’t ignore cloud governance anymore
AI makes JavaScript programming fun again
Malicious npm packages contain Vidar infostealer

https://security-tracker.debian.org/tracker/DSA-6050-1

Gootloader malware back for the attack, serves up ransomware
Google’s cheaper, faster TPUs are here, while users of other AI processors face a supply crunch
Tabnine launches ‘org-native’ AI agent platform
Cisco warns of ‘new attack variant’ battering firewalls under exploit for 6 months
The rising tide of cyber attacks against the UK water sector
“Pay up or we share the tapes”: Hackers target massage parlour clients in blackmail scheme
Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming

How a fast-growing scam is tricking WhatsApp users into revealing their most sensitive financial and other data

The AI Fix #75: Claude’s existential battery crisis, and why ChatGPT is a terrible therapist
You’ll never guess what the most common passwords are. Oh, wait, yes you will
Perplexity’s open-source tool to run trillion-parameter models without costly upgrades
Flaw in React Native CLI opens dev servers to attacks

* bsc#1248004 Cross-References: * CVE-2025-55159

* bsc#1250413 Cross-References: * CVE-2025-9900

* bsc#1252414 * bsc#1252417 * bsc#1252418 * bsc#1252758

An update that solves three vulnerabilities and has one security fix can now be installed.

* bsc#1252414 * bsc#1252417 * bsc#1252418 * bsc#1252758

* bsc#1251194 Cross-References: * CVE-2025-61962

SonicWall fingers state-backed cyber crew for September firewall breach
Google boosts Vertex AI Agent Builder with new observability and deployment tools
Databricks adds customizable evaluation tools to boost AI agent accuracy
Malware-pwned laptop gifts cybercriminals Nikkei’s Slack
Why UK businesses are paying ICO millions for password mistakes you’re probably making right now
Microsoft steers Aspire to a polyglot future
Developers don’t care about Kubernetes clusters
Smashing Security podcast #442: The hack that messed with time, and rogue ransom where negotiators
Mozilla.ai releases universal interface to LLMs

https://security-tracker.debian.org/tracker/DSA-6049-1

Uncle Sam lets Google take Wiz for $32B
How social engineering works | Unlocked 403 cybersecurity podcast (S2E6)

Think you could never fall for an online scam? Think again. Here’s how scammers could exploit psychology to deceive you – and what you can do to stay one step ahead

AMD red-faced over random-number bug that kills cryptographic security
Attackers abuse Gemini AI to develop ‘Thinking Robot’ malware and data processing agent for spying purposes
M&S pegs cyberattack cleanup costs at £136M as profits slump
Famed software engineer DJB tries Fil-C… and likes what he sees
UK agri dept spent hundreds of millions upgrading to Windows 10 – just in time for end of support
How multi-agent collaboration is redefining real-world problem solving
A fresh look at the Spring Framework
Some thoughts on AI and coding