Menu

Latest articles

OpenSilver extends to iOS and Android

* bsc#1197331 * bsc#1203769 * bsc#1235441 * bsc#1237768 * bsc#1238271

* bsc#1239750 Cross-References: * CVE-2022-49737

https://security-tracker.debian.org/tracker/DSA-5882-1

go-gh could be made to expose sensitive information over the network.

* bsc#1239547 Cross-References: * CVE-2025-24201

* bsc#1239547 Cross-References: * CVE-2025-24201

* bsc#1237363 * bsc#1237370 * bsc#1237418 Cross-References:

Nvidia launches AgentIQ toolkit to connect disparate AI agents
Everyone needs a genAI strategy now
Bridging the digital skills gap
AdTech CEO whose products detected fraud jailed for financial fraud
Paragon spyware deployed against journalists and activists, Citizen Lab claims
Capital One cracker could be sent back to prison after judges rule she got off too lightly
Developers: apply these 10 mitigations first to prevent supply chain attacks
Dept of Defense engineer took home top-secret docs, booked a fishing trip to Mexico – then the FBI showed up
Microsoft .NET 10 Preview 2 shines on C#, runtime, encryption
BlackLock ransomware: What you need to know
Infoseccers criticize Veeam over critical RCE vulnerability and a failing blacklist
Ex-Sun CEO Scott McNealy reflects on Java’s founding
What OpenInfra Joining Linux Foundation Means for Cloud Security Posture Management
Smashing Security podcast #409: Peeping perverts and FBI phone calls
Too many software supply chain defense bibles? Boffins distill advice
The post-quantum cryptography apocalypse will be televised in 10 years, says UK’s NCSC

Several security issues were fixed in Valkey.

Red Hat Advanced Cluster Security 4.7 simplifies management, enhances workflows, and generates SBOMs
Secure AI inferencing: POC with NVIDIA NIM on CoCo with OpenShift AI

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in HTTP request smuggling, validation bypass or denial of service.

Supply-chain CAPTCHA attack hits over 100 car dealerships
How to implement idempotent APIs in ASP.NET Core
TypeScript gets Go-faster stripes

Multiple vulnerabilities were discovered in modules shipped with cpython 3.9, the primary interpreter for the Python programming language.

fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864

fix CVE-2024-56737, CVE-2025-56737, CVE-2025-1864 Fix CVE-2025-1744 and CVE-2025-1864

Several security issues were fixed in Alpine.

Effective Strategies to Optimize Linux Security in 2025
Attackers swipe data of 500k+ people from Pennsylvania teachers union
Names, bank info, and more spills from top sperm bank
IBM scores perfect 10 … vulnerability in mission-critical OS AIX
Rising Malware Threats to Linux: Understanding Risks and Defenses
Cloud trends 2025: Repatriation and sustainability make their marks
Ex-US Cyber Command chief: Europe and 5 Eyes can’t fully replicate US intel
Exploring FireDragon: A High-Performing, Secure Linux Browser
Apache Tomcat Vulnerability CVE-2025-24813 Exposes Linux Servers to Remote Attacks

* bsc#1229640 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452

* bsc#1228755 * bsc#1231196 * bsc#1231204 * bsc#1233679 * bsc#1235452

* bsc#1231204 * bsc#1233679 Cross-References: * CVE-2024-46818

* bsc#1229640 * bsc#1231204 * bsc#1233679 Cross-References:

GitHub suffers a cascading supply chain attack compromising CI/CD secrets
SAP introduces Joule for Developers
Astro with HTMX: Server-side rendering made easy
You can build it on a Chromebook
Show top LLMs buggy code and they’ll finish off the mistakes rather than fix them
CISA fires, now rehires and immediately benches security crew on full pay
Oracle reveals five new features coming to Java

https://security-tracker.debian.org/tracker/DSA-5881-1

Oracle, Nvidia partner to add AI software into OCI services
US tech jobs outlook clouded by DOGE cuts, Trump tariffs
The AI Fix #42: AIs with anxiety, and why AIs don’t know what happened
Microsoft isn’t fixing 8-year-old shortcut exploit abused for spying
Google acquisition target Wiz links fresh supply chain attack to 23K pwned GitHub repos

* bsc#1237467 Cross-References: * CVE-2025-26618

UK wants dirt on data brokers before criminals get there first
Mandatory Coinbase wallet migration? It’s a phishing scam!

* bsc#1228017 * bsc#1229640 * bsc#1231204 * bsc#1233679

* bsc#1233679 Cross-References: * CVE-2024-50302

* bsc#1229640 * bsc#1231204 * bsc#1233679 Cross-References:

Extortion crew threatened to inform Edward Snowden (?!) if victim didn’t pay up
‘Dead simple’ hijacking hole in Apache Tomcat ‘now actively exploited in the wild’
Court filing: DOGE aide broke Treasury policy by emailing unencrypted database
Amazon to kill off local Alexa processing, all voice requests shipped to the cloud

https://security-tracker.debian.org/tracker/DSA-5879-1

What is KubeVirt? How does it migrate VMware workloads to Kubernetes?

FreeType could be made to crash or run programs if it opened a specially crafted font file.

GitHub supply chain attack spills secrets from 23,000 projects

* bsc#1239197 Cross-References: * CVE-2025-22868

* bsc#1239197 Cross-References: * CVE-2025-22868

Attackers attempted hijacking 12,000 GitHub accounts with click-fix alerts
UK government to open £16B IT services competition after 6-month delay

Several security issues were fixed in X.Org X Server.

Microsoft wouldn’t look at a bug report without a video. Researcher maliciously complied
Free file converter malware scam “rampant” claims FBI
Borked Chromecasts are beginning to receive their update – just hope you didn’t do a factory reset
Combining AI and no-code for business app development
Why AI-generated code isn’t good enough (and how it will get better)
AI can give you code but not community

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

https://security-tracker.debian.org/tracker/DSA-5880-1

FCC stands up Council on National Security to fight China in ways that CISA used to

An update that fixes one vulnerability is now available.

An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files which may result in arbitrary code execution. References: