Menu

Category Archives: Security

Articles about security

The best new features in Java 25
How to use Python dataclasses
UK data regulator defends decision not to investigate MoD Afghan data breach
Self-propagating worm found in marketplaces for Visual Studio Code extensions

https://security-tracker.debian.org/tracker/DSA-6030-1

.NET 10 RC 2 features .NET MAUI, Android updates
Restructuring risk operations: building a business-aligned cyber strategy
The AI Fix #73: Google Gemini is a gambling addict, and how to poison an AI
Google kills its cookie killer

* bsc#1241219 Cross-References: * CVE-2025-3576

An update that solves one vulnerability can now be installed.

* bsc#1241219 Cross-References: * CVE-2025-3576

An update that solves five vulnerabilities can now be installed.

* bsc#1250439 * bsc#1250440 * bsc#1250441 * bsc#1250442 * bsc#1251975

An update that solves five vulnerabilities can now be installed.

Muji’s minimalist calm shattered as ransomware takes down logistics partner
John Bolton charged over classified emails after Iranian hack of his AOL account
Feds flag active exploitation of patched Windows SMB vuln
How malware vaccines could stop ransomware’s rampage
The dazzling appeal of the neoclouds
How to improve technical documentation with generative AI
Zero Trust Everywhere: a new era in cybersecurity for European organizations
Anti-fraud body leaks dozens of email addresses in invite mishap
Anthropic extends Claude Code to browsers
Visual Studio Code taps AI for merge conflict resolution

* bsc#1251279 * bsc#1251280 Cross-References: * CVE-2025-10230

An update that solves two vulnerabilities can now be installed.

* bsc#1251279 * bsc#1251280 Cross-References: * CVE-2025-10230

An update that solves six vulnerabilities can now be installed.

* bsc#1232384 * bsc#1245794 * bsc#1246075 * bsc#1248673 * bsc#1248749

An update that solves five vulnerabilities can now be installed.

AWS DNS error hits DynamoDB, causing problems for multiple services and customers
Hundreds of masked ICE agents doxxed by hackers, as personal details posted on Telegram
Implementing predictive monitoring with AIOps
How AI is reshaping the future of startups
Should enterprise developers care about Nvidia?
8 platform engineering anti-patterns
UK calls up Armed Forces veterans for digital ID soft launch

https://security-tracker.debian.org/tracker/DSA-6029-1

Simplified patching with Red Hat Enterprise Linux and Red Hat Insights

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Update to Python 3.9.24

Update to 3.11.14

Update to Python 3.10.19

Backport fixes for CVE-2025-11082, CVE-2025-11083, CVE-2025-11494, CVE-2025-11495.

What is an Out-of-Bounds Write Linux Security Vulnerability?

When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local attacker to pre-create

Added fix for mzbz#1990430 (crashes) Updated to latest upstream (144.0)

Backport fix for CVE-2025-10729.

Backport fix for CVE-2025-10729.

Update to python-3.11.14, fixes CVE-2025-8291.

Update to release v1.3.2

Threat actors are spreading malicious extensions via VS marketplaces
Have I Been Pwned logs 17.6M victims in Prosper breach
Labor unions sue Trump administration over social media surveillance
Carmakers fear chip crunch as Dutch sanctions hit Nexperia

An update that solves 326 vulnerabilities and has 45 security fixes can now be installed.

* bsc#1065729 * bsc#1164051 * bsc#1193629 * bsc#1194869 * bsc#1202700

An update that solves one vulnerability and contains one feature can now be installed.

* bsc#1223219 * jsc#PED-13826 Cross-References: * CVE-2024-32650

* bsc#1250232 Cross-References: * CVE-2025-9230

A mini-CrowdStrike moment? Windows 11 update cripples dev environments

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, memory disclosure or cross-site scripting.

An EU breakup with US cloud providers
Agents of chaos

https://security-tracker.debian.org/tracker/DSA-6028-1

https://security-tracker.debian.org/tracker/DSA-6027-1

https://security-tracker.debian.org/tracker/DSA-6025-1

Vulnerability scores, huh, what are they good for? Almost nothing
Chinese cyberspies snoop on Russian IT biz in rare east-on-east attack
Locked out of your Gmail account? Google says phone a friend

Redis could be made to crash or run programs if it received specially crafted network traffic from an authenticated user.

Redict could be made to crash or run programs if it received specially crafted network traffic from an authenticated user.

Redis could be made to crash or run programs if it received specially crafted network traffic from an authenticated user.

Apache Subversion could be made to crash if it opened a specially crafted file.

Microsoft kills 9.9-rated ASP.NET Core bug – ‘our highest ever’ score
Senator presses Cisco over firewall flaws that burned US agency

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

Auction house Sotheby’s finds its data on the block after cyberattack
Tech industry grad hiring crashes 46% as bots do junior work
Operation Heracles strikes blow against massive network of fraudulent crypto trading sites
Using Valkey on Azure and in .NET Aspire
How to run an R data visualization chatbot you can talk to
Rethinking operations in an agentic AI world
Machine learning meets malware: how AI-powered ransomware could destroy your business

https://security-tracker.debian.org/tracker/DSA-6026-1

Smashing Security podcast #439: A breach, a burnout, and a bit of Fleetwood Mac
Devs are writing VS Code extensions that blab secrets by the bucketload
NCSC warns companies to prepare for a day when your screens go dark
Capita fined £14M after 58-hour delay exposed 6.6M records
Selective retraining helps AI learn new skills without forgetting, study finds
Zoom dooms the developer’s afternoon
The best Java microframeworks to learn now
7 newer data science tools you should be using with Python

An update that solves one vulnerability can now be installed.

* bsc#1250553 Cross-References: * CVE-2025-10911

Update to exiv2-0.28.7, fixes CVE-2025-54080 and CVE-2025-55304.

Update to exiv2-0.28.7, fixes CVE-2025-54080 and CVE-2025-55304.