Menu

Latest articles

Update to upstream 1.4.2, fix CVE-2025-22870

* bsc#1245320 Cross-References: * CVE-2025-6032

* bsc#1245320 Cross-References: * CVE-2025-6032

Election workers fear threats and intimidation without feds’ support in 2026

Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker

Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker

Typhoon-adjacent Chinese crew broke into Taiwanese web host
Cisco’s Secure Firewall Management Center now not-so secure, springs a CVSS 10 RCE hole

An update that fixes 5 vulnerabilities is now available.

Cyberattack on Dutch prosecution service is keeping speed cameras offline
Telco giant Colt suffers attack, takes systems offline
The truth about Python’s AI-powered popularity surge
Can your cloud provider really scale?
LLM chatbots trivial to weaponize for data theft, say boffins
Should UK.gov save money by looking for open source alternatives to Microsoft? You decide

fix CVE-2025-46206 (rhbz#2386395)

fixes CVE-2025-8534: null pointer dereference in tiff2p fixes CVE-2024-13978: null pointer dereference in tiff2pdf

update MANUAL to cover threat related to user HTML iframe

Ransomware crews don’t care about your endpoint security – they’ve already killed it

Several security issues were fixed in AIDE.

* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5975-1

https://security-tracker.debian.org/tracker/DSA-5974-1

Psst: wanna buy a legit FBI email account for $40?
‘MadeYouReset’ HTTP/2 flaw lets attackers DoS servers
Lock down your critical infrastructure, CISA begs admins
BtcTurk suspends operations amid alleged $49M hot wallet heist
Law and water: Russia blamed for US court system break-in and Norwegian dam drama
What Is a Use-After-Free (UAF) Vulnerability?
Italian hotels breached en masse since June, government confirms

Several security issues were fixed in Request Tracker.

Stock in the Channel pulls website amid cyberattack
Monitoring microservices: Best practices for robust systems
Wassette: A bridge between Wasm and MCP

Several security issues were fixed in Sidekiq.

The £9 billion question: To Microsoft or not to Microsoft?

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5977-1

https://security-tracker.debian.org/tracker/DSA-5976-1

Smashing Security podcast #430: Poisoned Calendar invites, ChatGPT, and Bromide
Fortinet discloses critical bug with working exploit code amid surge in brute-force attempts
Supply-chain dependencies: Check your resilience blind spot

Does your business truly understand its dependencies, and how to mitigate the risks posed by an attack on them?

How the always-on generation can level up its cybersecurity game

Digital natives are comfortable with technology, but may be more exposed to online scams and other threats than they think

Crooks can’t let go: Active attacks target Office vuln patched 8 years ago
The MedusaLocker ransomware gang is hiring penetration testers
The AI Fix #63: GPT-5 is the best AI ever, and Jim Acosta interviews a murdered teenager’s avatar
US reveals it seized $1 million worth of Bitcoin from Russian BlackSuit ransomware gang

* bsc#1243747 Cross-References: * CVE-2025-48057

* bsc#1246397 Cross-References: * CVE-2025-48924

* bsc#1085999 * bsc#1246397 Cross-References: * CVE-2025-48924

* bsc#1247249 Cross-References: * CVE-2025-8194

UK expands police facial recognition rollout with 10 new vans heading to a town near you
Claude Sonnet 4 upgrade enables full codebase processing in a single request

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Marc Andreessen wades into the UK’s Online Safety Act furor
Microsoft wares may be UK public sector’s only viable option
Secure chat darling Matrix admits pair of ‘high severity’ protocol flaws need painful fixes
Hands-on with Svelte: Build-time compilation in a reactive framework
Five kinds of static code coupling
Ransomware crew spills Saint Paul’s 43GB of secrets after city refuses to cough up cash
Crypto-crasher Do Kwon admits guilt over failed not-so-stablecoin that erased $41 billion
National Security & AI at DEFCON 2025: Where Code Meets Crisis
Microsoft’s Patch Tuesday baker’s dozen: 12 critical bugs plus a SharePoint RCE
Rubrik unveils ‘undo button’ for AI agent mistakes
Manpower franchise discloses data theft after RansomHub posts alleged stolen data
Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability

ESET Research discovered a zero-day vulnerability in WinRAR being exploited in the wild in the guise of job application documents; the weaponized archives exploited a path traversal flaw to compromise their targets

Major outage at Pennsylvania Attorney General’s Office blamed on ‘cyber incident’
BlackSuit ransomware crew loses servers, domains, and $1m in global shakedown
Devops, SRE and platform engineering: What’s the difference?

An update that fixes 9 vulnerabilities is now available.

* bsc#1221107 Cross-References: * CVE-2024-2236

* bsc#1246296 Cross-References: * CVE-2025-7425

Oh, great.Three notorious cybercrime gangs appear to be collaborating
Hyundai: Want cyber-secure car locks? That’ll be £49, please
A developer’s guide to code generation
The rise of AI model-as-a-service ecosystems

* bsc#1219386 Cross-References: * CVE-2023-5992

The White House could end UK’s decade-long fight to bust encryption
Poisoned telemetry can turn AIOps into AI Oops, researchers show
Rust 1.89 underscores arguments to const generics

https://security-tracker.debian.org/tracker/DSA-5973-1

https://security-tracker.debian.org/tracker/DSA-5972-1

Russia’s RomCom among those exploiting a WinRAR 0-day in highly-targeted attacks
WinRAR zero-day exploited in espionage attacks against high-value targets

The attacks used spearphishing campaigns to target financial, manufacturing, defense, and logistics companies in Europe and Canada, ESET research finds

US scrambles to recoup $1M+ nicked by NORKs