Menu

Category Archives: Security

Articles about security

An update that solves two vulnerabilities can now be installed.

* bsc#1242617 * bsc#1243862 Cross-References: * CVE-2024-12224

* bsc#1246602 * bsc#1246604 * bsc#1247938 * bsc#1247939

* bsc#1246602 * bsc#1246604 * bsc#1247938 * bsc#1247939

Workers fear for their jobs as JLR’s latest shutdown extended
Full Disk Encryption: What It Is, How It Works, and Why It Matters for Linux Security in 2025
Suspected Iran-backed attackers targeting European aerospace sector with novel malware
UK chancellor Putin the blame on Russia for cyber chaos, but evidence says otherwise
Vibe coding and the future of software development
Cloud computing has an ROI problem
The productivity paradox of AI-assisted coding
EV charging biz zaps customers with data leak scare
GitHub introduces registry for finding MCP servers
Web Codegen Scorer evaluates AI-generated web code
Cops cuff another teen over alleged Scattered Spider attack that broke Vegas casinos
EU’s cyber agency blames ransomware as Euro airport check-in chaos continues

* bsc#1249391 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5

An update that contains one feature can now be installed.

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

Car giant Stellantis says customer data nicked after partner vendor pwned
Advanced debug logging techniques: A technical guide
NPM attacks and the security of software supply chains
Do vector-native databases beat add-ons for AI applications?

An update that solves one vulnerability can now be installed.

* bsc#1248252 Cross-References: * CVE-2025-53192

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

FOMO? Brit banking biz rolls out AI tools, talks up security
Trump says Michael Dell is part of the team buying TikTok, with Larry Ellison and maybe some Murdochs
Tech troubles create aviation chaos on both sides of the Atlantic
Ransomware attack linked to museum break-in and theft of golden exhibits

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 11 vulnerabilities can now be installed.

Multiple vulnerabilities were found in PAM namespace module used to configure private namespaces for user sessions. CVE-2024-22365

https://security-tracker.debian.org/tracker/DSA-6007-1

Gamaredon X Turla collab

Notorious APT group Turla collaborates with Gamaredon, both FSB-associated groups, to compromise high‑profile targets in Ukraine

Everything You Need to Know About Linux Proxy Servers (2025 Guide)

Fix Out of bounds read for cookie path (CVE-2025-9086) Fix predictable WebSocket mask (CVE-2025-10148)

New upstream release fixing the following security weaknesses (CVE-2025-8114, CVE-2025-8277)

Rust 1.90 brings workspace publishing support to Cargo

* bsc#1247589 Cross-References: * CVE-2025-50422

* bsc#1248461 Cross-References: * CVE-2025-9301

ChatGPT joins human league, now solves CAPTCHAs for the right prompt
Ivanti EPMM holes let miscreants plant shady listeners, CISA says
Small businesses, big targets: Protecting your business against ransomware

Long known to be a sweet spot for cybercriminals, small businesses are more likely to be victimized by ransomware than large enterprises

Ding ding: Fortra rings the perfect-10 bell over latest GoAnywhere MFT bug
Scattered Spider teen cuffed after buying games and meals with extortion bitcoin
One token to pwn them all: Entra ID bug could have granted access to every tenant

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, information disclosure or bypass of the same-origin policy.

OpenAI plugs ShadowLeak bug in ChatGPT that let miscreants raid inboxes

The system could be made to crash or run programs as an administrator.

The system could be made to crash or run programs as an administrator.

Charities warn Ofcom too soft on Online Safety Act violators

The system could be made to crash or run programs as an administrator.

The system could be made to crash or run programs as an administrator.

How AI changes the data analyst role
How Oracle became a cloud player
Wasm 3.0 adds 64-bit backing, language support
Adding up the hidden costs of generative AI

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that an exploit for CVE-2025-10585 exists in the wild.

Vastaamo psychotherapy hack: US citizen charged in latest twist of notorious data breach
Replit update sparks developers’ dissatisfaction over pricing
MI6 reveals ‘Silent Courier’ dark web portal upgrade it hopes will help it recruit new spies

https://security-tracker.debian.org/tracker/DSA-6004-1

https://security-tracker.debian.org/tracker/DSA-6005-1

https://security-tracker.debian.org/tracker/DSA-6006-1

AI Alliance forges agent-native language, knowledge base
Google pushes emergency patch for Chrome 0-day – check your browser version now
Crims bust through SonicWall to grab sensitive config data
Cybercriminals pwn 850k+ Americans’ healthcare data
Two ‘Scattered Spider’ teens charged over attack on London’s transport network
Cloudflare DDoSed itself with React useEffect hook blunder

* bsc#1233421 Cross-References: * CVE-2024-52615

* bsc#1246197 * bsc#1249191 * bsc#1249348 * bsc#1249367 * jsc#PED-13055

* bsc#1246197 * bsc#1249191 * bsc#1249348 * bsc#1249367 * jsc#PED-13055

Insight Partners confirms ransomware hit, more than 12,000 caught in data dragnet
Panda-monium: China-backed cyber crew spoof Congressman to dig for dirt on US trade talks
Designing AI-ready architectures in compliance-heavy environments
Smoother Kubernetes sailing with AKS Automatic
“Pompompurin” resentenced: BreachForums creator heads back behind bars
San Francisco AI technology conference draws protests
Russian fake-news network, led by an ex-Florida sheriff’s deputy, storms back into action with 200+ new sites

https://security-tracker.debian.org/tracker/DSA-6003-1

Smashing Security podcast #435: Lights! Camera! Hacktion!
Scattered Spider gang feigns retirement, breaks into bank instead
HybridPetya: The Petya/NotPetya copycat comes with a twist

HybridPetya is the fourth publicly known real or proof-of-concept bootkit with UEFI Secure Boot bypass functionality

From mischief to malware: ICO warns schools about student hackers
Axiom Space aims for orbit with its Orbital Data Center Node
MongoDB adds vector search to self-managed editions to power generative AI apps
BreachForums kingpin goes from walk-free deal to 3-year stretch

* bsc#1236851 * bsc#1248070 Cross-References: * CVE-2025-23419

* bsc#1235673 * bsc#1235674 Cross-References: * CVE-2024-57822

* bsc#1243581 * bsc#1248410 * bsc#1248687 Cross-References: