Menu

Category Archives: Security

Articles about security

https://security-tracker.debian.org/tracker/DSA-5948-1

Amazon’s Ring can now use AI to ‘learn the routines of your residence’
Computer vision research feeds surveillance tech as patent links spike 5×
Supply chain attacks surge with orgs ‘flying blind’ about dependencies
French cybercrime police arrest five suspected BreachForums admins
Aflac, one of the USA’s largest insurers, is the latest to fall “under siege” to hackers
Google unveils Gemini CLI for developers

* bsc#1244148 Cross-References: * CVE-2011-10007

* bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062 * bsc#1235231

Nils Emmerich discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.

UK govt dept website that campaigns against encryption hijacked to advertise … payday loans
Cybercrime is surging across Africa
Software development meets the McNamara Fallacy
Pyrefly and Ty: Two new Rust-powered Python type-checking tools compared

commons-beanutils, utility for manipulating Java beans have an improper Access Control vulnerability. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers

* bsc#1239192 Cross-References: * CVE-2025-22868

New AI benchmarking tools evaluate real world performance
Kotlin 2.2.0 arrives with context parameters, unified management of compiler warnings
Don’t panic, but it’s only a matter of time before critical ‘CitrixBleed 2’ is under attack
Beware of fake SonicWall VPN app that steals users’ credentials
The vulnerability management gap no one talks about
The AI Fix #56: ChatGPT traps man in a cult of one, and AI is actually stupid
Twitter refuses to explain what it’s doing about hate speech and misinformation, sues New York State for asking

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

IBM Donates CBOM Toolset to Linux Foundation
o3-pro may be OpenAI’s most advanced commercial offering, but GPT-4o bests it
Four REvil ransomware crooks walk free, escape gulag fate, after admitting guilt
Public cloud becomes a commodity
LLMs aren’t enough for real-world, real-time projects
‘Psylo’ browser tries to obscure digital fingerprints by giving every tab its own IP address
Google’s Agent2Agent project moves to Linux Foundation
Typhoon-like gang slinging TLS certificate ‘signed’ by the Los Angeles Police Department
Ktor adds dependency injection and HTMX modules
Marks & Spencer ransomware attack was good news for other retailers
Iran cyberattacks against US biz more likely following air strikes
Agentic AI won’t wait for your data architecture to catch up
Second attack on McLaren Health Care in a year affects 743k people
GitHub’s AI billing shift signals the end of free enterprise tools era
Experts count staggering costs incurred by UK retail amid cyberattack hell

Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version

Why AI projects fail, and how developers can help them succeed
Devops debt: The hidden tax on innovation
How to succeed (or fail) with AI-driven development

* bsc#1241067 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059

* bsc#1234421 * bsc#1244405 * bsc#1244406 Cross-References:

* bsc#1243721 Cross-References: * CVE-2025-5222

Former US Army Sergeant pleads guilty after amateurish attempt at selling secrets to China

https://security-tracker.debian.org/tracker/DSA-5947-1

Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler

Harden temporary private mounts (#2373301)

4.9.0

This is the .NET monthly update for June 2025. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release-notes/9.0/9.0.6/9.0.107.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.6/9.0.6.md

Fix improper access control vulnerability Resolves: CVE-2025-48734

https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/OXIGQIHBL26HFKG6TT5SWSH7K7W6RO4H/ https://phabricator.wikimedia.org/T382326

https://security-tracker.debian.org/tracker/DSA-5946-1

https://security-tracker.debian.org/tracker/DSA-5945-1

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Netflix, Apple, BofA websites hijacked with fake help-desk numbers
Looks like Aflac is the latest insurance giant snagged in Scattered Spider’s web
Qilin ransomware top dogs treat their minions to on-call lawyers for fierier negotiations
Krispy Kreme hack exposed sensitive data of over 160,000 people

* bsc#1241158 * bsc#1241160 * bsc#1243282 * bsc#1243286 * bsc#1243288

* bsc#1234449 Cross-References: * CVE-2024-47606

* bsc#1239192 Cross-References: * CVE-2025-22868

* bsc#1227690 Cross-References: * CVE-2024-38526

* bsc#1233012 * bsc#1243273 * bsc#1244401 Cross-References:

GitHub hit by a sophisticated malware campaign as ‘Banana Squad’ mimics popular repos
IBM combines governance and security tools to solve the AI agent oversight crisis
Attack on Oxford City Council exposes 21 years of election worker data
Qilin offers “Call a lawyer” button for affiliates attempting to extort ransoms from victims who won’t pay
The hyperscalers disrupt the sovereign cloud disruptors
Developers set the pace for genAI tools adoption

https://security-tracker.debian.org/tracker/DSA-5944-1

Boffins devise voice-altering tech to jam ‘vishing’ schemes
Uncle Sam seeks time in tower dump data grab case after judge calls it ‘unconstitutional’
Glazed and confused: Hole lotta highly sensitive data nicked from Krispy Kreme

It was discovered that an Out Of Memory error may occur when attempting to initialize a huge byte array, even when maxFrameSize is set. For Debian 11 bullseye, this problem has been fixed in version

* bsc#1234415 * bsc#1234450 * bsc#1234453 * bsc#1234455 * bsc#1234456

UK gov asks university boffins to pinpoint cyber growth areas where it should splash cash

Several security issues were fixed in Samba.

Updates to Red Hat Advanced Cluster Security for Kubernetes Cloud Service strengthen your security posture
Taking advantage of Microsoft Edge’s built-in AI
Firecrawl: Easy web data extraction for AI applications

Several security issues were fixed in Express.

* bsc#1238681 * bsc#1239192 Cross-References: * CVE-2025-22868