Menu

Category Archives: Security

Articles about security

Update to uriparser-1.0.0, fixes CVE-2025-67899.

fix setpwnam() buffer use [CVE-2025-14104] libblkid: use snprintf() instead of sprintf()

https://security-tracker.debian.org/tracker/DSA-6088-1

https://security-tracker.debian.org/tracker/DSA-6089-1

https://security-tracker.debian.org/tracker/DSA-6090-1

https://security-tracker.debian.org/tracker/DSA-6091-1

https://security-tracker.debian.org/tracker/DSA-6087-1

https://security-tracker.debian.org/tracker/DSA-6086-1

https://security-tracker.debian.org/tracker/DSA-6085-1

SNMP: CACTI Command Execution Risk Advisory for Linux Administrators

Update to 0.2.8

Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on

Update to 2.22.11

Update to 17.0.0 version (#2412270) Update fonttools 4.61.0

Update to 17.0.0 version (#2412270) Update fonttools 4.61.0

Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on

ATM jackpotting gang accused of unleashing Ploutus malware across US
WatchGuard sounds alarm as critical Firebox flaw comes under active attack
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions

Sydney Uni data goes walkabout after criminals raid code repo
Snowflake software update caused 13-hour outage across 10 regions
Enterprise automation resilience with EDB and Red Hat Ansible Automation Platform
Red Hat to acquire Chatterbox Labs: Frequently Asked Questions
Accelerating NetOps transformation with Ansible Automation Platform
HPE tells customers to patch fast as OneView RCE bug scores a perfect 10

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Ministers confirm breach at UK Foreign Office but details remain murky
Faith in the internet is fading among young Brits
AI and cybersecurity: Two sides of the same coin

An update that solves four vulnerabilities can now be installed.

PHP version 8.4.16 (18 Dec 2025) Core: Sync all boost.context files with release 1.86.0. (mvorisek) Fixed bug GH-20435 (SensitiveParameter doesn’t work for named argument passing to variadic parameter). (ndossche)

China turns on a vast experimental network it says is an heir to ARPANET
Amazon blocked 1,800 suspected North Korean scammers seeking jobs
Your car’s web browser may be on the road to cyber ruin
Python type checker ty now in beta
Crypto crooks co-opt stolen AWS creds to mine coins
Kim’s crypto thieving reached a record $2B in 2025
Another bad week for SonicWall as SMA 1000 zero-day under active exploit
FBI dismantles alleged $70M crypto laundering operation

It was discovered that c-ares, a library that performs DNS requests and name resolution asynchronously, does not properly handle termination of queries which may result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 1.34.5-1+deb13u1.

NHS tech supplier probes cyberattack on internal systems
React2Shell exploitation spreads as Microsoft counts hundreds of hacked machines
DVSA’s clapped-out booking system gets bot slapped as new boss rides in
UK surveillance law still full of holes, watchdog warns
What’s next for Azure infrastructure
High-performance programming with Java streams
Designing the agent-ready data stack

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

JetBrains releases Kotlin 2.3.0
Smashing Security podcast #448: The Kindle that got pwned

https://security-tracker.debian.org/tracker/DSA-6083-1

https://security-tracker.debian.org/tracker/DSA-6084-1

Attacks pummeling Cisco AsyncOS 0-day since late November
CEO spills the Tea about massive token farming campaigns
ESET Threat Report H2 2025

A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts

Blockchain company Nomad to repay users under FTC deal after $186M cyberattack
PwC on securing AI: building trust, compliance and confidence at scale
NATO’s battle for cloud sovereignty: Speed is existential
Microsoft security updates breaks MSMQ on older Win systems
England keeping pen and paper exams despite limited digital expansion
What developers call themselves
Surveillance at sea: Cruise firm bans smart glasses to curb covert recording
Spring Boot tutorial: Get started with Spring Boot
Django tutorial: Get started with Django 6

An update that solves one vulnerability, contains one feature and has one security fix can now be installed.

Microsoft deprecates IntelliCode for Visual Studio Code

This update includes the latest upstream release of mod_md, with various bug fixes and enhancements. See https://github.com/icing/mod_md/releases for more information. A fix for the security vulnerability CVE-2025-55753 is also included.

Update to 25.4.0

Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287

upstream stable upgrade from 2.41.1 to 2.41.3 (CVE-2025-14104 and other issues)

Backport fix for CVE-2025-11277

China’s Ink Dragon hides out in European government networks
Azul acquires enterprise Java middleware provider Payara
Analytics provider: We didn’t expose smut site data to crims
Browser ‘privacy’ extensions have eye on your AI, log all your chats
SantaStealer stuffs credentials, crypto wallets into a brand new bag
The AI Fix #81: ChatGPT is the last AI you’ll understand, and your teacher is a deepfake
From pr0n to playlists and paperclips, trio of breaches spills data of millions
MI6 chief: We’ll be as fluent in Python as we are in Russian
Harden your AI systems: Applying industry standards in the real world
AWS AI Factories: Innovation or complication?
5 key agenticops practices to start building now
PwC on using AI to turn cybersecurity risk into competitive advantage
No, SoundCloud hasn’t started tuning out VPNs. It’s mopping up after a cyberattack
Nvidia bets on open infrastructure for the agentic AI era with Nemotron 3
Amazon security boss blames Russia’s GRU for years-long energy-sector hacks

https://security-tracker.debian.org/tracker/DSA-6082-1

China, Iran are having a field day with React2Shell, Google warns
Delay to European Central Bank messaging project cost the Bank of England £23M
JLR: Payroll data stolen in cybercrime that shook UK economy
Apple, Google forced to issue emergency 0-day patches
Denmark takes a Viking swing at VPN-enabled piracy
Man jailed for teaching criminals how to use malware