Menu

Category Archives: Security

Articles about security

An update that solves 18 vulnerabilities can now be installed.

An update that solves 7 vulnerabilities can now be installed.

Three security issues were discovered in the Squid proxy caching server, which could result in the execution of arbitrary code, information disclosure or denial of service.

It was discovered that the symlink validation in node-tar-fs, a Node.js module that provides filesystem-like access to tar files, could be bypassed.

Firefox 140.3.1 has been released, which fixes connection errors with some sites; if HTTP/3 connections failed, the fallback is now handled more gracefully.

https://security-tracker.debian.org/tracker/DSA-6003-2

https://security-tracker.debian.org/tracker/DSA-6013-1

https://security-tracker.debian.org/tracker/DSA-6014-1

https://security-tracker.debian.org/tracker/DSA-6012-1

Hunt for RedNovember: Beijing hacked critical orgs in year-long snooping campaign
Alibaba unveils $53B global AI plan – but it will need GPUs to back it up

Update to 140.0.7339.207 * CVE-2025-10890: Side-channel information leakage in V8 * CVE-2025-10891: Integer overflow in V8 * CVE-2025-10892: Integer overflow in V8

4.0.6.3221

Update to 140.0.7339.207 * CVE-2025-10890: Side-channel information leakage in V8 * CVE-2025-10891: Integer overflow in V8 * CVE-2025-10892: Integer overflow in V8

From answer engine to infrastructure: Perplexity launches Search API for developers

Eugene Medvedev discovered that nncp, a package facilitating secure store-and-forward file and mail exchange, was susceptible to path traversal with the freq and file commands.

An update that fixes one vulnerability is now available.

Cyber threat-sharing law set to shut down, along with US government

* bsc#1234896 * bsc#1244824 * bsc#1245970 * bsc#1246473 * bsc#1246911

Microsoft spots fresh XCSSET malware strain hiding in Apple dev projects
Salesforce facing multiple lawsuits after Salesloft breach
‘An attacker’s playground:’ Crims exploit GoAnywhere perfect-10 bug
LockBit’s new variant is ‘most dangerous yet,’ hitting Windows, Linux and VMware ESXi
Prompt injection – and a $5 domain – trick Salesforce Agentforce into leaking sales

* bsc#1247901 * bsc#1247902 * bsc#1247904 Cross-References:

* bsc#1246974 * bsc#1249375 Cross-References: * CVE-2025-8114

* bsc#1246974 * bsc#1249375 Cross-References: * CVE-2025-8114

An update that solves two vulnerabilities can now be installed.

* bsc#1246001 * bsc#1246356 * bsc#1247499 Cross-References:

An update that solves three vulnerabilities can now be installed.

Volvo North America confirms staff data stolen following ransomware attack on IT supplier
UK and US security agencies order urgent fixes as Cisco firewall bugs exploited in wild
UK to roll out mandatory digital ID for right to work by 2029
SaaS: The quiet power behind cloud computing
Python and Poetry: 4 tools for keeping Python simple
What is infrastructure as code? Automating your infrastructure builds
Brits warned as illegal robo-callers with offshored call centers fined half a million
Microsoft Marketplace opens for AI apps, agents
North Korea’s Lazarus Group shares its malware with IT work scammers
GitHub Copilot-backed app modernization available for Java, .NET
Callous crims break into preschool network, publish toddlers’ data
Zero-day deja vu as another Cisco IOS bug comes under attack
Top Linux Malware Scanners for Detection and System Hardening

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

EU starting registration of fingerprints and faces for short-stay foreigners

Several security issues were fixed in the Linux kernel.

Two vulnerabilities were found in libxslt, an XSLT 1.0 processing library, which could lead to to denial of service or information disclosure.

Empty shelves, empty coffers: Co-op pegs cyber hit at £80m
The best new features in Postgres 18
Spec-driven AI coding with GitHub’s Spec Kit
Introduction to Java records: Simplified data-centric programming in Java
Check your own databases before asking to see our passport photos, Home Office tells UK cops
Three in four European companies are hooked on US tech
Google releases MCP server to Data Commons public data sets

https://security-tracker.debian.org/tracker/DSA-5979-2

https://security-tracker.debian.org/tracker/DSA-6010-1

https://security-tracker.debian.org/tracker/DSA-6011-1

Smashing Security podcast #436: The €600,000 gold heist, powered by ransomware

Parents across America face a growing wave of sophisticated online fraud designed to exploit their deepest fears and protective instincts. Americans reported losing more than $12.5 billion to fraud in 2024, representing a 25% increase over the prior year, according to new Federal Trade Commission data. Parents represent a particularly vulnerable target because scammers understand […]

New string of phishing attacks targets Python developers
SonicWall releases rootkit-busting firmware update following wave of attacks
INC ransomware: what you need to know
Google warns China-linked spies lurking in ‘numerous’ enterprises since March
The AI Fix #69: How we really use ChatGPT, and will AI agents crash the economy?

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

UK agency makes arrest in airport cyberattack investigation

* bsc#1246001 * bsc#1246356 * bsc#1247499 Cross-References:

* bsc#1231862 * bsc#1246001 * bsc#1246356 * bsc#1247499

* bsc#1246001 * bsc#1247499 Cross-References: * CVE-2025-38181

Cybercriminals cash out with casino giant’s employee data

Several security issues were fixed in the Linux kernel.

Disk Encryption: An Authoritative Guide for Linux Users
Configuring Proxy Servers on Linux for Enhanced Security and Privacy
Top Synthetic Data Generation Tools for AI and Testing in 2025
Campaigners urge UK PM Starmer to dump digital ID wheeze before it’s announced
Open source registries signal shift toward paid models as AI strains infrastructure
Politicos: ‘There is a good strong case for government intervention’ on JLR cyberattack
GraalVM 25 arrives, backed by JDK 25
How immutability tamed the Wild West
Reactive Java with Spring WebFlux and Reactor
How to manage Python projects with Poetry
QR codes become the vehicle for malware in new technique

https://security-tracker.debian.org/tracker/DSA-6009-1

https://security-tracker.debian.org/tracker/DSA-6008-1

Nearly half of businesses suffered deepfaked phone calls against staff
Third time’s the charm? SolarWinds (again) patches critical Web Help Desk RCE
OnePlus leaves researchers on read over Android bug that exposes texts
SIM city: Feds say 100,000-card farms could have killed cell towers in NYC
Kaspersky: RevengeHotels checks back in with AI-coded malware

Several security issues were fixed in pip.

OpenSSF warns that open source infrastructure doesn’t run on thoughts and prayers
GitHub moves to tighten npm security amid phishing, malware plague
What Is a Speculative Execution Linux Security Vulnerability?
Teradata taps open source frameworks to offer agent-building capabilities
Oracle gets to store US users’ TikTok data, says Trump

* bsc#1235237 Cross-References: * CVE-2024-55553