Menu

Latest articles

Red teams are safe from robots for now, as AI makes better shield than spear
Wikimedia Foundation loses first court battle to swerve Online Safety Act regulation
Intel chief Lip-Bu Tan to visit White House after Trump calls for him to step down
Deepfake detectors are slowly coming of age, at a time of dire need
UK retail giant M&S restores Click & Collect months after cyber attack, some services still down
Your CV is not fit for the 21st century – time to get it up to scratch
The advantages of stack-based internal developer platforms
Multi-agent AI workflows: The next evolution of AI coding
Who does the unsexy but essential work for open source?

* bsc#1246318 * bsc#1246388 Cross-References: * CVE-2025-52520

* bsc#1233791 * bsc#1233834 Cross-References: * CVE-2024-22117

* bsc#1247519 * bsc#1247520 * bsc#1247522 Cross-References:

Trend Micro offers weak workaround for already-exploited critical vuln in management console
Black Hat USA 2025: Is a high cyber insurance premium about your risk, or your insurer’s?

A sky-high premium may not always reflect your company’s security posture

Android adware: What is it, and how do I get it off my device?

Is your phone suddenly flooded with aggressive ads, slowing down performance or leading to unusual app behavior? Here’s what to do.

DEF CON hackers plug security holes in US water systems amid tsunami of threats
The inside story of the Telemessage saga, and how you can view the data

update to xen-4.19.3 includes patches for x86: Incorrect stubs exception handling for flags recovery [XSA-470, CVE-2025-27465] x86: Transitive Scheduler Attacks [XSA-471, CVE-2024-36350,

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

New release of Incus. Release information: https://github.com/lxc/incus/releases/tag/v6.15.0

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

Updated perl to version 5.40.3 https://metacpan.org/release/SHAY/perl-5.40.3/view/pod/perldelta.pod

What is a CSRF Vulnerability?
Chinese biz using AI to hit US politicians, influencers with propaganda
Black Hat USA 2025: Policy compliance and the myth of the silver bullet

Who’s to blame when the AI tool managing a company’s compliance status gets it wrong?

Black Hat USA 2025: Does successful cybersecurity today increase cyber-risk tomorrow?

Success in cybersecurity is when nothing happens, plus other standout themes from two of the event’s keynotes

Star leaky app of the week: StarDict
Ex-White House cyber, counter-terrorism guru: Microsoft considers security an annoyance, not a necessity

* bsc#1246090 Affected Products: * openSUSE Leap 15.4

* bsc#1245573 Cross-References: * CVE-2025-6297

* bsc#1244925 Cross-References: * CVE-2025-50181

Infosec hounds spot prompt injection vuln in Google Gemini apps
Hashcat 7.0.0: Redefining Password Recovery & Security on Linux
Critical NestJS Vulnerability Exposes Developers to RCE Risk
How to Build a Ransomware Kill Chain Strategy for Linux Security
UK secretly allows facial recognition scans of passport, immigration databases
UK proxy traffic surges as users consider VPN alternatives amid Online Safety Act
TeaOnHer copies everything from Tea – including the data breaches
Should public clouds enforce government policies?
Prohibition never works, but that didn’t stop the UK’s Online Safety Act
What Is a SQLi Vulnerability?
Google rolls out AI coding tool for GitHub repos
Why blow up satellites when you can just hack them?

https://security-tracker.debian.org/tracker/DSA-5971-1

German security researchers say ‘Windows Hell No’ to Microsoft biometrics for biz
Microsoft, CISA warn yet another Exchange server bug can lead to ‘total domain compromise’
Black Hat’s network ops center brings rivals together for a common cause
CISA releases malware analysis for Sharepoint Server attack
Ukraine claims to have hacked secrets from Russia’s newest nuclear submarine
KLM, Air France latest major organizations looted for customer data
Meta training AI on social media posts? Only 7% in Europe think it’s OK

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

* bsc#1234959 Cross-References: * CVE-2024-56738

Introducing OpenShift Service Mesh 3.1

Several security issues were fixed in cifs-utils.

Anthropic targets DevSecOps with Claude Code update as AI rivals gear up
The Claude party is almost over
Getting started with A2A in .NET
Amnesty slams Elon Musk’s X for ‘central role’ in fueling 2024 UK riots

* bsc#1221107 * bsc#1246934 Cross-References: * CVE-2024-2236

Could agentic AI save us from the cybercrisis?
Microsoft researchers bullish on AI security agent even though it let 74% of malware slip through
Google updates agents in BigQuery to further automate analytics tasks
Google says the group behind last year’s Snowflake attack slurped data from one of its Salesforce instances
ESET Threat Report H1 2025: ClickFix, infostealer disruptions, and ransomware deathmatch

Threat actors are embracing ClickFix, ransomware gangs are turning on each other – toppling even the leaders – and law enforcement is disrupting one infostealer after another

Ransomware plunges insurance company into bankruptcy

Multiple vulnerabilities have been discovered in Composer, the worst of which can lead to arbitrary code execution.

A vulnerability has been discovered in Spreadsheet-ParseExcel, which can lead to arbitrary code execution.

A vulnerability has been discovered in NSS, which can lead to the recovery of private data.

A vulnerability has been discovered in FontForge, which can lead to arbitrary code execution.

TypeScript 5.9 arrives with deferred module evaluation, expandable hovers
Google Spanner gets a columnar engine to unite OLTP and OLAP workloads
Hospital fined after patient data found in street food wrappers

Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which can lead to execution of arbitrary code.

Multiple vulnerabilities have been discovered in PAM, the worst of which could lead to privilege escalation.

Roo Code review: Autonomous AI-powered development in the IDE
How to code sign binaries on Windows
How to measure coupled code
Vibe coding tool Cursor’s MCP implementation allows persistent code execution
JetBrains previews no-code app builder
Patch now: Millions of Dell PCs with Broadcom chips vulnerable to attack
Study finds humans not completely useless at malware detection
Chained bugs in Nvidia’s Triton Inference Server lead to full system compromise
The AI Fix #62: AI robots can now pass CAPTCHAs, and punch you in the face
What Is a RCE Vulnerability?

* bsc#1245773 Cross-References: * CVE-2025-53367