Menu

Category Archives: Security

Articles about security

Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks
China says US spies exploited Microsoft Exchange zero-day to steal military info
This month in security with Tony Anscombe – July 2025 edition

Here’s a look at cybersecurity stories that moved the needle, raised the alarm, or offered vital lessons in July 2025

Florida prison email blunder exposes visitor contact info to inmates

* bsc#1243855 Cross-References: * CVE-2024-12224

* bsc#1243868 Cross-References: * CVE-2024-12224

* bsc#1221107 Cross-References: * CVE-2024-2236

Google upgrades Agent2Agent protocol with gRPC and enterprise-grade security
Deploy sensitive workloads with OpenShift confidential containers
Confidential containers on Microsoft Azure with Red Hat OpenShift Sandboxed Containers 1.10 and Red Hat Build of Trustee

An update that fixes one vulnerability is now available.

Cybercrooks attached Raspberry Pi to bank network and drained ATM cash
Spotlight report: How AI is reshaping IT
Dedicated servers outpace public clouds for AI
.NET Aspire 9.4 boasts CLI core commands, AI integrations
Fun and profit with ECMAScript 2025: What’s new in JavaScript
Top spy says LinkedIn profiles that list defense work ‘recklessly invite attention of foreign intelligence services’
As ransomware gangs threaten physical harm, ‘I am afraid of what’s next,’ ex-negotiator says
Gene scanner pays $9.8 million to get feds off its back in security flap
Microsoft’s Azure AI Speech needs just seconds of audio to spit out a convincing deepfake
Beijing summons Nvidia over alleged backdoors in China-bound AI chips
Kremlin goons caught abusing ISPs to spy on Moscow-based diplomats, Microsoft says
Silk Typhoon spun a web of patents for offensive cyber tools, report says
Brit watchdog pushes to rein in Microsoft and AWS with ‘strategic market status’
Informatica enhances IDMC with AI-powered MDM, governance, and compliance tools

* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274

* bsc#1236621 * bsc#1243009 * bsc#1243105 * bsc#1243268 * bsc#1243274

* bsc#1244795 * bsc#1246058 * bsc#1246059 Cross-References:

NHS disability equipment provider on brink of collapse a year after cyberattack
Managing Azure VMs with Project Flash
Why MCP matters – and how to secure it
Basic and advanced pattern matching in Java
Banning VPNs to protect kids? Good luck with that
Internet exchange points are ignored, vulnerable, and absent from infrastructure protection plans
AI use among software developers grows but trust remains an issue – Stack Overflow survey
Lethal Cambodia-Thailand border clash linked to cyber-scam slave camps
The TSA likes facial recognition at airports. Passengers and politicians, not so much

https://security-tracker.debian.org/tracker/DSA-5969-1

Smashing Security podcast #428: Red flags, leaked chats, and a final farewell
Enterprises neglect AI security – and attackers have noticed
Users left scrambling for a plan B as Dropbox drops Dropbox Passwords
Minnesota governor calls in the troops after St Paul cyberattack
The hidden risks of browser extensions – and how to stay safe

Not all browser add-ons are handy helpers – some may contain far more than you have bargained for

Palo Alto Networks inks $25b deal to buy identity-security shop CyberArk

Several security issues were fixed in SQLite.

Ransomware gang sets deadline to leak 3.5 TB of Ingram Micro data

Several security issues were fixed in cloud-init.

Google’s new toolset to help connect AI agents to BigQuery

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

How to write a good bug report
First look: Guided code generation with Kiro
Intro to the Lit: A standards-based reactive library

https://security-tracker.debian.org/tracker/DSA-5968-1

CISA caves to Wyden, agrees to release US telco insecurity report – but won’t say when
TypeScript 5.9 brings deferred module evaluation, expandable hovers

https://security-tracker.debian.org/tracker/DSA-5967-1

FBI: Watch out for these signs Scattered Spider is spinning its web around your org
Google patches Gemini CLI tool after prompt injection flaw uncovered
FluidCloud introduces ‘cloud cloning’ platform
Debian shifts to 64-bit time storage to head off Epochalypse
Snowflake brings analytics workloads into its cloud with Snowpark Connect for Apache Spark
Allianz Life hit by hackers, customer and staff personal data stolen
Tea Dating Advice app spills sensitive data

Let’s be honest – nobody wants antivirus software that slows down their computer. You know the feeling: you install security software to protect yourself, but suddenly your laptop takes forever to start up, programs freeze, and you’re constantly waiting for things to load. Well, we have some great news. A recent independent study by PassMark […]

The AI Fix #61: Replit panics, deletes $1M project; AI gets gold at Math Olympiad
Raspberry Pi RP2350 A4 update fixes old bugs and dares you to break it again
200,000 WordPress websites at risk of being hijacked due to vulnerable Post SMTP plugin
Teradata joins Snowflake, Databricks in expanding MCP ecosystem

Several security issues were fixed in the Linux kernel.

* bsc#1246090 Affected Products: * openSUSE Leap 15.3

Hidden in Plain Sight: Koske Linux Malwares Stealthy Panda Image Delivery
War Games: MoD asks soldiers with 1337 skillz to compete in esports
Are cloud ops teams too reliant on AI?
What is model context protocol? How MCP bridges AI and external services
How to excel in multicloud: The new checklist

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

This update fixes CVE-2025-8058, a low-impact security vulnerability in the regcomp function.

Microsoft spotlights Apple bug patched in March as SharePoint exploits continue
Security pros are drowning in threat-intel data and it’s making everything more dangerous
GitHub previews natural language app builder for AI-powered apps
Majority of 1.4M customers caught in Allianz Life data heist
French submarine secrets surface after cyber attack
Soco404: Linux Cryptomining Campaign Masquerades as 404 Error Pages
Aeroflot aeroflops over ‘IT issues’ after attackers claim year-long compromise

Two issues have been found in libcaca, a colour ASCII art library. Both are related to heap buffer overflow, which might lead to memory corruption.

It was discovered that there was a potential null pointer dereference vulnerability in libetpan, an low-level library for handling email.

The audiofile library allows the processing of audio data to and from audio files of many common formats (currently AIFF, AIFF-C, WAVE, NeXT/Sun, BICS, and raw data).

The importance of memory for AI
How agentic AI will change database management
12 coding agents at the cutting edge