Menu

Category Archives: Security

Articles about security

* bsc#1236217 * bsc#1242715 Cross-References: * CVE-2025-22873

* bsc#1241658 * bsc#1241659 Cross-References: * CVE-2025-43965

* bsc#1243216 Cross-References: * CVE-2025-3875 * CVE-2025-3877

* bsc#1242809 Cross-References: * CVE-2025-3887

Microsoft envisions Windows Update as the unified platform for all software updates
Billions of cookies up for grabs as experts warn over session security
Tails and Tor: A New Alliance for Digital Security
Mistral AI launches code embedding model, claims edge over OpenAI and Cohere
European Commission: Make Europe Great Again… for startups
Docling: An open-source toolkit for advanced document processing
Using Microsoft Fabric to create digital twins
Reports of Deno’s demise ‘greatly exaggerated,’ Deno creator says
Victoria’s Secret website laid bare for three days after ‘security incident’
Adversarial AI: The new frontier in financial cybersecurity

https://security-tracker.debian.org/tracker/DSA-5929-1

Smashing Security podcast #419: Star Wars, the CIA, and a WhatsApp malware mirage
Attack on LexisNexis Risk Solutions exposes data on 300k +
Word to the wise: Beware of fake Docusign emails

Cybercriminals impersonate the trusted e-signature brand and send fake Docusign notifications to trick people into giving away their personal or corporate data

The AI Fix #52: AI adopts its own social norms, and AI DJ creates diversity scandal

A path traversal vulnerability in `PackageIndex` was found in setuptools. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context.

GNU C Library could be made to crash or run programs if it processed specially crafted dynamically shared library.

* bsc#1243313 Cross-References: * CVE-2025-47273

* bsc#1243356 Cross-References: * CVE-2025-21490

* bsc#1242809 Cross-References: * CVE-2025-3887

Russian IT pro sentenced to 14 years forced labor for sharing medical data with Ukraine
Revive Your Old PC & Fortify Your System with FunOS
The cost of compromise: Why password attacks are still winning in 2025
How to hire software developers
AI didn’t kill Stack Overflow
DragonForce double-whammy: First hit an MSP, then use RMM software to push ransomware
ASUS to chase business PC market with free AI, or no AI – because nobody knows what to do with it

https://security-tracker.debian.org/tracker/DSA-5926-1

https://security-tracker.debian.org/tracker/DSA-5927-1

Don’t click on that Facebook ad for a text-to-AI-video tool
Adidas customers’ personal information at risk after data breach
New Russian cyber-spy crew Laundry Bear joins the email-stealing pack
Adidas confirms criminals stole data from customer service provider

A flaw was discovered in the dynamic linking support in the GNU C Library, the C standard library implementation used by Debian. Privilege escalation may be possible in statically compiled setuid

Salesforce to buy Informatica in $8 billion deal

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in Intel Microcode.

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

Ransomware attack on MATLAB dev MathWorks – licensing center still locked down
AWS adds observability support to Aurora PostgreSQL Limitless
Lessons from building retrieval systems for AI assistants
What we know now about generative AI for software development
IT leadership lessons from ‘Leroy Jenkins’

PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2021-3539

Multicloud developer lessons from the trenches

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1243313 Cross-References: * CVE-2025-47273

* bsc#1242931 Cross-References: * CVE-2025-4207

New updates for Red Hat Enterprise Linux on confidential virtual machines
InfluxDB’s new model for time series workloads
The tough task of making AI code production-ready
TeleMessage security SNAFU worsens as 60 government staffers exposed
China approves rules for national ‘online number’ ID scheme
Danabot under the microscope

ESET Research has been tracking Danabot’s activity since 2018 as part of a global effort that resulted in a major disruption of the malware’s infrastructure

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Data Security Best Practices for Strengthening Linux Networks

A few fixes

This is the May 2025 update for .NET 8 for Fedora. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.16/8.0.116.md Runtime: https://github.com/dotnet/core/blob/main/release-

Update to version 12.5.2. Fixes CVE-2025-22247

Update to 128.10.2 https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/

A few fixes

Cybercrime is ‘orders of magnitude’ larger than state-backed ops, says ex-White House advisor
Danabot: Analyzing a fallen empire

ESET Research shares its findings on the workings of Danabot, an infostealer recently disrupted in a multinational law enforcement operation

Lumma Stealer: Down for the count

The bustling cybercrime enterprise has been dealt a significant blow in a global operation that relied on the expertise of ESET and other technology companies

Remembering John Young, co-founder of web archive Cryptome

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Kotlin gets a new AI agent framework

Update to 128.10.2 https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/ Update to 128.10.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-34/ https://www.thunderbird.net/en-US/thunderbird/128.10.1esr/releasenotes/

CVE-2025-46646 ghostscript: Mishandling of Overlong UTF-8 Encoding in decode_utf8() (fedora#2362639, fedora#2362446)

Fix for CVE-2025-47268

https://security-tracker.debian.org/tracker/DSA-5925-1

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel’® Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2024-28956) Insufficient resource pool in the core management mechanism for some

Heap buffer overflow in HTML. (CVE-2025-4096) Out of bounds memory access in DevTools. (CVE-2025-4050) Insufficient data validation in DevTools. (CVE-2025-4051) Inappropriate implementation in DevTools. (CVE-2025-4052) Use after free in WebAudio. (CVE-2025-4372)

Ransomware scum leaked Nova Scotia Power customers’ info
ESET takes part in global operation to disrupt Lumma Stealer

Our intense monitoring of tens of thousands of malicious samples helped this global disruption operation

CISA says SaaS providers in firing line after Commvault zero-day Azure attack
Understanding Security Threats In Open-Source Software Supply Chains
RHEL 10 Enhances Security Across Hybrid Environments
Grandpa-conning crook jailed over sugar-coated drug scam
3AM ransomware attack poses as a call from IT support to compromise networks

* bsc#1229504 * bsc#1233019 * bsc#1234847 Cross-References:

* bsc#1233019 * bsc#1234847 Cross-References: * CVE-2024-50115

* bsc#1233019 * bsc#1233678 * bsc#1234847 Cross-References:

Suspected creeps behind DanaBot malware that hit 300K+ computers revealed
Ivanti makes dedicated fans of Chinese spies who just can’t resist attacking its buggy kit
US Navy sailor charged in horrific child sextortion case

https://security-tracker.debian.org/tracker/DSA-5924-1