Menu

Category Archives: Security

Articles about security

UK secretly allows facial recognition scans of passport, immigration databases
UK proxy traffic surges as users consider VPN alternatives amid Online Safety Act
TeaOnHer copies everything from Tea – including the data breaches
Should public clouds enforce government policies?
Prohibition never works, but that didn’t stop the UK’s Online Safety Act
What Is a SQLi Vulnerability?
Google rolls out AI coding tool for GitHub repos
Why blow up satellites when you can just hack them?

https://security-tracker.debian.org/tracker/DSA-5971-1

German security researchers say ‘Windows Hell No’ to Microsoft biometrics for biz
Microsoft, CISA warn yet another Exchange server bug can lead to ‘total domain compromise’
Black Hat’s network ops center brings rivals together for a common cause
CISA releases malware analysis for Sharepoint Server attack
Ukraine claims to have hacked secrets from Russia’s newest nuclear submarine
KLM, Air France latest major organizations looted for customer data
Meta training AI on social media posts? Only 7% in Europe think it’s OK

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

Introducing OpenShift Service Mesh 3.1

Several security issues were fixed in cifs-utils.

Anthropic targets DevSecOps with Claude Code update as AI rivals gear up
Getting started with A2A in .NET
The Claude party is almost over
Amnesty slams Elon Musk’s X for ‘central role’ in fueling 2024 UK riots

* bsc#1221107 * bsc#1246934 Cross-References: * CVE-2024-2236

Could agentic AI save us from the cybercrisis?
Microsoft researchers bullish on AI security agent even though it let 74% of malware slip through
Google updates agents in BigQuery to further automate analytics tasks
Google says the group behind last year’s Snowflake attack slurped data from one of its Salesforce instances
ESET Threat Report H1 2025: ClickFix, infostealer disruptions, and ransomware deathmatch

Threat actors are embracing ClickFix, ransomware gangs are turning on each other – toppling even the leaders – and law enforcement is disrupting one infostealer after another

Ransomware plunges insurance company into bankruptcy

Multiple vulnerabilities have been discovered in Composer, the worst of which can lead to arbitrary code execution.

A vulnerability has been discovered in Spreadsheet-ParseExcel, which can lead to arbitrary code execution.

A vulnerability has been discovered in NSS, which can lead to the recovery of private data.

A vulnerability has been discovered in FontForge, which can lead to arbitrary code execution.

TypeScript 5.9 arrives with deferred module evaluation, expandable hovers
Google Spanner gets a columnar engine to unite OLTP and OLAP workloads
Hospital fined after patient data found in street food wrappers

Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which can lead to execution of arbitrary code.

Multiple vulnerabilities have been discovered in PAM, the worst of which could lead to privilege escalation.

How to measure coupled code
How to code sign binaries on Windows
Roo Code review: Autonomous AI-powered development in the IDE
Vibe coding tool Cursor’s MCP implementation allows persistent code execution
JetBrains previews no-code app builder
Patch now: Millions of Dell PCs with Broadcom chips vulnerable to attack
Study finds humans not completely useless at malware detection
Chained bugs in Nvidia’s Triton Inference Server lead to full system compromise
The AI Fix #62: AI robots can now pass CAPTCHAs, and punch you in the face
What Is a RCE Vulnerability?

* bsc#1245773 Cross-References: * CVE-2025-53367

* bsc#1247249 Cross-References: * CVE-2025-8194

* bsc#1247249 Cross-References: * CVE-2025-8194

Hacker summer camp: What to expect from BSides, Black Hat, and DEF CON
Why benchmarks are key to AI progress
The problem with AI agent-to-agent communication protocols
Python popularity boosted by AI coding assistants – Tiobe
Antivirus vendors fail to spot persistent, nasty, stealthy Linux backdoor
SonicWall investigates ‘cyber incidents,’ including ransomware targeting suspected 0-day
Python-powered malware snags hundreds of credit cards, 200K passwords, and 4M cookies
Mozilla flags phishing wave aimed at hijacking trusted Firefox add-ons
German phone repair biz collapses following 2023 ransomware attack
When hyperscalers can’t safeguard one nation’s data from another, dark clouds are ahead
Millions of age checks performed as UK Online Safey Act gets rolling
9 habits of the highly ineffective vibe coder
Microsegmentation for developers
Erasing the trust gap in AI-driven development

* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:

* bsc#1228645 * bsc#1235250 * bsc#1245771 * bsc#1245776 * bsc#1245793

* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:

* bsc#1235250 * bsc#1245776 * bsc#1245793 * bsc#1245797

* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:

China’s botched Great Firewall upgrade invites attacks on its censorship infrastructure
Lazarus Group rises again, this time with malware-laden fake FOSS
Silent Push CEO on cybercrime takedowns: ‘It’s an ongoing cat-and-mouse game’

Update to 138.0.7204.183 * CVE-2025-8292: Use after free in Media Stream

This update fixes CVE-2025-7345 and CVE-2025-6199.

This update fixes these CVEs: CVE-2025-32364 CVE-2025-32365 CVE-2024-56378

reposurgeon: update to 5.3 version

In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. References: – https://bugs.mageia.org/show_bug.cgi?id=34447

Stefan Buehler discovered a flaw in sope, the set of Objective-C frameworks powering SOGo, which may result in denial of service via a specially crafted POST request.

Is your phone spying on you? | Unlocked 403 cybersecurity podcast (S2E5)

Here’s what you need to know about the inner workings of modern spyware and how to stay away from apps that know too much

Why the tech industry needs to stand firm on preserving end-to-end encryption

Restricting end-to-end encryption on a single-country basis would not only be absurdly difficult to enforce, but it would also fail to deter criminal activity

CISA roasts unnamed critical national infrastructure body for shoddy security hygiene

A flaw was found in how GLib¢”s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn¢”t. As a result, data may be written […]

Backports patch to fix non-CVE 2025-8224

This update fixes these CVEs: CVE-2025-4948 CVE-2025-32908 CVE-2025-32907 CVE-2025-4969

What Is An XSS Vulnerability?

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Apache Flink integrates AI for real-time decision-making
OpenAI removes ChatGPT self-doxing option

https://security-tracker.debian.org/tracker/DSA-5970-1