Menu

Category Archives: Security

Articles about security

An update that solves four vulnerabilities can now be installed.

* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208

OpenAI API moonlights as malware HQ in Microsoft’s latest discovery

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

What is vibe coding? AI writes the code so developers can think big
10 top devops practices no one is talking about
Agentic AI is complex, not complicated
Diversifying cloud resources is essential
Google’s new query builder to tackle SQL complexity in cloud workload monitoring
China’s president Xi Jinping jokes about backdoors in Xiaomi smartphones
Anthropic experiments with AI introspection
AN0M, the backdoored ‘secure’ messaging app for criminals, is still producing arrests after four years
Google unveils Jules extension for Gemini CLI
MIT Sloan quietly shelves AI ransomware study after researcher calls BS
Ransomware negotiator, pay thyself!
Swift SDK arrives for Android development
AWS, Nvidia, CrowdStrike seek security startups to enter the arena
Cybercrooks team up with organized crime to steal pricey cargo
Metropolitan Police hails facial recognition tech after record year for arrests

* bsc#1250410 Cross-References: * CVE-2025-9230

* bsc#1252282 Cross-References: * CVE-2025-62171

* bsc#1246818 Cross-References: * CVE-2025-7783

Xu Biang discovered a buffer overflow bug in the eap-mschapv2 plugin of strongSwan, an IKE/IPsec suite. The eap-mschapv2 plugin does not correctly check the length of an

The race to shore up Europe’s power grids against cyberattacks and sabotage
Boring governance is the path to real AI adoption
What developers should know about network APIs
Was data mesh just a fad?

Several security vulnerabilities have been discovered in WordPress, a popular content management framework. CVE-2024-6307

* bsc#1251941 Cross-References: * CVE-2025-62291

Attackers targeting unpatched Cisco kit notice malware implant removal, install it again

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Upgrade to Ruby 3.3.10. CVE-2025-58767 ruby: REXML denial of service (rhbz#2396203)

New seamonkey packages are available for Slackware 15.0 and -current to fix security issues.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

Update to xwayland 24.1.9, CVE fix for: CVE-2025-62229, CVE-2025-62230, CVE-2025-62231

Update to upstream 2.4.3, including fixes for CVE-2025-62513 and CVE-2025-62705.

Rebuild for CVE-2025-47906. https://pkg.go.dev/vuln/GO-2025-3956

Fix CVE-2025-5455 – QtCore Assertion Failure Denial of Service

Fixes CVE-2025-11561 Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2402728 After startup SSSD already creates a Kerberos configuration snippet in /var/lib/sss/pubconf/krb5.include.d/localauth_plugin if the AD or IPA providers are used. This enables SSSD’s localauth plugin. Starting with this update the

New version 3.0.2 (rhbz#2407048) Fixes CVE-2025-11232 (rhbz#2407229)

Will JavaFX return to Java?

https://security-tracker.debian.org/tracker/DSA-6047-1

https://security-tracker.debian.org/tracker/DSA-6046-1

Russia finally bites the cybercrooks it raised, arresting suspected Meduza infostealer devs
Attackers dig up $11M in Garden Finance crypto exploit

* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268

* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208

OpenAI launches Aardvark to detect and patch hidden bugs in code
Resilience, not sovereignty, defines OpenStack’s next chapter
Agentic AI: What now, what next?

This upload fixes a few of security issues in the Python standard library included with PyPy, an alternative implementation of the Python 3 language. CVE-2024-6232

* bsc#1248631 * bsc#1249207 * bsc#1249208 Cross-References:

* bsc#1246019 * bsc#1248631 * bsc#1249207 * bsc#1249208

* bsc#1247737 * bsc#1248176 * bsc#1248631 * bsc#1249207 * bsc#1249208

NHS left with sick PCs as suppliers resist Windows 11 treatment
Europe preps Digital Euro to enter circulation in 2029
Rust 1.91 promotes Windows on Arm64 to Tier 1 target
Visual Studio October update adds Claude coding models

https://security-tracker.debian.org/tracker/DSA-6045-1

Suspected Chinese snoops weaponize unpatched Windows flaw to spy on European diplomats
Proton trains new service to expose corporate infosec cover-ups
Docker Compose vulnerability opens door to host-level writes – patch pronto
Spam text scammer fined £200,000 for targeting people in debt, after sending nearly one million messages
The human cost of the UK Government’s Afghan data leak
Invisible npm malware pulls a disappearing act – then nicks your tokens

The system could be made to expose sensitive information.

Netty could be made to send emails as your login if it received specially crafted input.

Cyberpunks mess with Canada’s water, energy, and farm systems
Postcode Lottery’s lucky dip turns into data slip as players draw each other’s info

Several security issues were fixed in AMD Microcode.

France jacks into the Matrix for state messaging – and pays too

Several security issues were fixed in GNU binutils.

Run Azure DevOps on premises
Key principles of a successful internal developer platform
Unit testing Spring MVC applications with JUnit 5
LinkedIn gives you until Monday to stop AI from training on your profile
Google adds tiered storage to NoSQL Bigtable to reduce complexity, costs

Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780)

Cursor 2.0 adds coding model, UI for parallel agents
Smashing Security podcast #441: Inside the mob’s million-dollar poker hack, and a Formula 1 fumble

https://security-tracker.debian.org/tracker/DSA-6043-1

This security hole can crash billions of Chromium browsers, and Google hasn’t patched it yet
EY exposes 4TB+ SQL database to open internet for who knows how long
Linux: Tee.Fail Moderate TEE Side-Channel Attack for 2024-001

Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.

Marketing giant Dentsu warns staff after Merkle data raid
Sole trader dispatched almost 1M spam texts to hard-up Brits, says watchdog
Introducing Red Hat’s STIG-hardened UBI for NVIDIA GPUs on Red Hat OpenShift
GitHub launches Agent HQ to bring order to AI-powered coding
UK government on the lookout for bargain-priced CTO
The quiet glory of REST and JSON
The top 4 JVM languages and why developers love them
What’s the Go language really good for?
9 in 10 Exchange servers in Germany still running out-of-support software

Jan-Niklas Sohn discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.

MGASA-2025-0251 – Updated poppler packages fix security vulnerability

MGASA-2025-0250 – Updated tomcat packages fix security vulnerabilities