Menu

Latest articles

How lean security teams can build resilient defenses
Feds finger Russian ‘behind Qakbot malware’ that hit 700K computers
Chinese snoops tried to break into US city utilities, says Talos
Irish privacy watchdog OKs Meta to train AI on EU folks’ posts
Russia expected to pass experimental law that tracks foreigners in Moscow via smartphones
Signal shuts the blinds on Microsoft Recall with the power of DRM
Understanding Malicious .desktop Files: A Persistent Threat to Linux Systems
Tails 6.15.1 Fixes Critical Tor Browser Flaws
The road to quantum-safe cryptography in Red Hat OpenShift
Unleashing innovation in Red Hat Enterprise Linux with extensions repository
Post-quantum cryptography in Red Hat Enterprise Linux 10
Zero trust workload identity manager now available in tech preview
EMEA blog | Dutch | Red Hat OpenShift Comes Out Exceptionally Strong in Data Security Survey Results
How HashiCorp Vault and Red Hat OpenShift can work together
Scottish council admits ransomware crooks stole school data
Evolving the Windows AI platform
How to add user context to request traces in ASP.NET Core
How to use method references in Java

libfcgi-perl could be made to crash or execute arbitrary code.

* bsc#1243268 Cross-References: * CVE-2025-47287

DOJ charges 12 more in $263 million crypto fraud takedown where money was hidden in squishmallow stuffed animals
Red Hat readies Advanced Developer Suite

Update to version 0.2.6.

Latest upstream release. Changelog: https://github.com/gorhill/uBlock/releases/tag/1.64.0 . Fixes CVE-2025-4215 .

Update to version 0.2.6.

Smashing Security podcast #418: Grid failures, Instagram scams, and Legal Aid leaks
US teen to plead guilty to extortion attack against PowerSchool
Russia’s Fancy Bear swipes a paw at logistics, transport orgs’ email servers
FBI, Microsoft, international cops bust Lumma infostealer service
CloudBees unveils AI-enhanced devops platform
Coinbase confirms insiders handed over data of 70K users
Google releases agent development kits for Python and Java
The who, where, and how of APT attacks in Q4 2024–Q1 2025

ESET Chief Security Evangelist Tony Anscombe highlights key findings from the latest issue of the ESET APT Activity Report

ESET APT Activity Report Q4 2024–Q1 2025

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2024 and Q1 2025

Microsoft beefs up SQL Server 2025 for AI-driven applications
Red Hat Enterprise Linux 10 adds AI-powered management
Judge allows Delta’s lawsuit against CrowdStrike to proceed with millions in damages on the line
Google carves out cloudy safe spaces for nations nervous about America’s reach
The AI Fix #51: Divorce by coffee grounds, and why AI robots need your brain

PostgreSQL could be made to crash if it received specially crafted network traffic.

Trump announces $175B for Golden Dome defense shield over America

* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

* bsc#1235958 * bsc#1235971 * bsc#1239651 * bsc#1242971 * jsc#PED-12028

* bsc#1242622 * jsc#PED-12028 Cross-References: * CVE-2025-3416

M&S warns of £300M dent in profits from cyberattack
UK ‘extremely dependent’ on US for space security
Scattered Spider snared financial orgs before targeting shops in Britain, America
‘Ongoing’ Ivanti hijack bug exploitation reaches clouds
GitHub unveils coding agent for GitHub Copilot
Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms
Microsoft Open-Sources WSL Years After Its Debut

* bsc#1240897 Cross-References: * CVE-2025-3360

* bsc#1234847 Cross-References: * CVE-2024-53156

* bsc#1205495 * bsc#1230764 * bsc#1231103 * bsc#1231450 * bsc#1231910

Ransomware attack on food distributor spells more pain for UK supermarkets
Why is Microsoft offering to turn websites into AI apps with NLWeb?
SEC Twitter hack: Man imprisoned for role in attack that caused Bitcoin’s price to soar.

Several security issues were fixed in the Linux kernel.

Cloud asset management: A crucial missing ingredient

* bsc#1242631 * bsc#1243177 Cross-References: * CVE-2025-3416

Virgin Media O2 patches hole that let callers snoop on your coordinates
CISA has a new No. 2 … but still no official top dog
SEC SIM-swapper who Googled ‘signs that the FBI is after you’ put behind bars

Microcode updates has been released for Intel(R) processors, addressing multiple potential vulnerabilties that may allow denial of service or information disclosure.

Microsoft aims to improve agent versatility with Copilot Studio updates
OpenAI launches Codex AI agent to tackle multi-step coding tasks

.NET could be used to perform spoofing over a network.

Millions at risk after attackers steal UK legal aid data dating back 15 years
The AI Fix nominated for top podcast award. Vote now!
IT chiefs of UK’s massive health service urge vendors to make public security pledge
What comes after Stack Overflow?
How we replaced Azure Redis with Memcached
The best Java certifications for software developers

* bsc#1228634 * bsc#1232533 * bsc#1241012 * bsc#1241045

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

Eeek! p0wned Alabama hit by unspecified ‘cybersecurity event’

Enable CSS Overscroll Behavior by default. Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. Fix rendering when device scale factor change comes before the web view geometry update.

China launches an AI cloud into orbit -12 sats for now, 2,800 in coming years
Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’

Mohamed Maatallah discovered a stack-based buffer overflow in the get_name() function in net-tools, a collection of programs for controlling the network subsystem of the Linux kernel, which may result in denial of service (application crash) or potentially the execution of

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo

Update to 1.25.0

Update to 136.0.7103.113 CVE-2025-4664: Insufficient policy enforcement in Loader CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo

Update to 1.25.0

https://security-tracker.debian.org/tracker/DSA-5923-1

https://security-tracker.debian.org/tracker/DSA-5922-1

https://security-tracker.debian.org/tracker/DSA-5921-1

Boffins devise technique that lets users prove location without giving it away
Using RHEL confidential virtual machines to protect AI workloads on Microsoft Azure

Enable CSS Overscroll Behavior by default. Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. Fix rendering when device scale factor change comes before the web view geometry update.

x86: Indirect Target Selection [XSA-469, CVE-2024-28956]

update to 4.8.2 fixing CVE-2024-47619

update to 4.8.2 to fix CVE-2024-47619

Fired US govt workers, Uncle Xi wants you! – to apply for this fake consulting gig