Menu

Latest articles

The most relevant new features in JDK 24
How eBPF is changing container networking
Who needs Google technology? Probably not you
US Cyber Command reportedly pauses cyberattacks on Russia
Download the AI Risk Management Enterprise Spotlight

A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. A privileged attacker could cause a Denial-of-Service (DoS) of the MariaDB server.

C++ creator calls for help to defend programming language from ‘serious attacks’

A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file. (CVE-2025-22919) A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted

nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm –without-symbol-version` function. (CVE-2024-57360) GNU Binutils objdump.c disassemble_bytes stack-based overflow. (CVE-2025-0840)

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

https://security-tracker.debian.org/tracker/DSA-5872-1

Red Hat is now a CVE Numbering Authority of Last Resort in the CVE Program

Update to chromium-133.0.6943.141

CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function

CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function

New version 4.2.11

Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162

deadlock potential with VT-d and legacy PCI device pass-through [XSA-467, CVE-2025-1713]

TrapC proposal to fix C/C++ memory safety
Rust 1.85 arrives with long-awaited async closures

https://security-tracker.debian.org/tracker/DSA-5871-1

Ransomware criminals love CISA’s KEV list – and that’s a bug, not a feature
Google’s AlloyDB is looking more and more like PostgreSQL

* bsc#1237093 Cross-References: * CVE-2025-1094

* bsc#1237431 Cross-References: * CVE-2025-26597

* bsc#1237431 Cross-References: * CVE-2025-26597

Do more with Python’s new built-in async programming library
The rising threat of shadow AI
Microsoft names alleged credential-snatching ‘Azure Abuse Enterprise’ operators
Feds: Army soldier suspected of AT&T heist Googled ‘can hacking be treason,’ ‘defecting to Russia’
What is retrieval-augmented generation? More accurate and reliable LLMs
FBI officially fingers North Korea for $1.5B Bybit crypto-burglary

https://security-tracker.debian.org/tracker/DSA-5870-1

Microsoft’s Phi-4-multimodal AI model handles speech, text, and video
Warning issued as hackers offer firms fake cybersecurity audits to break into their systems
DeepSeek offers steep discounts, escalating AI price war
Understanding thread synchronization in C#
What’s next for Microsoft’s Semantic Kernel?

Several security issues were fixed in PHP.

Does terrible code drive you mad? Wait until you see what it does to OpenAI’s GPT-4o

Multiple vulnerabilities were discovered in GNU Emacs, the extensible, customisable, self-documenting, real-time display editor. CVE-2023-28617

Libxmltok could be made to crash if it opened a specially crafted file.

Merge branch ‘f42’ into f41 Merge branch ‘rawhide’ into f41 Fix merge conflict

Microsoft’s .NET 10 arrives in first preview
Wallbleed vulnerability unearths secrets of China’s Great Firewall 125 bytes at a time
Smashing Security podcast #406: History’s biggest heist just happened, and online abuse
With millions upon millions of victims, scale of unstoppable info-stealer malware laid bare
Bybit declares war on North Korea’s Lazarus crime-ring to regain $1.5B stolen from wallet

A heap-based buffer overflow flaw in the decoding functions of openh264, a codec library which supports H.264 encoding and decoding, may allow a remote attacker to cause a denial of service or the execution of arbitrary code if a specially crafted video is processed.

New emacs packages are available for Slackware 15.0 and -current to fix security issues.

Qualcomm pledges 8 years of security updates for Android kit using its chips (YMMV)
Essential Updates for X.Org and XWayland Address Eight New Security Flaws
Signal will withdraw from Sweden if encryption-busting laws take effect

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Get started with async in Python
Plug-and-play web development with Astro
11 rules for writing better code
Red Hat OpenShift improves virtualization support

Cross-References: * CVE-2020-13936 CVSS scores:

200-plus impressively convincing GitHub repos are serving up malware

Upstream kernel version 6.6.79 fixes bugs and vulnerabilities. The kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.

Vanilla upstream kernel version 6.6.79 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=34024

Incoming deputy boss of Homeland Security says America’s top cyber-agency needs to be reined in
Cot framework aims to ease Rust web development
Drug-screening biz DISA took a year to disclose security breach affecting millions
Xi know what you did last summer: China was all up in Republicans’ email, says book
MITRE Caldera security suite scores perfect 10 for insecurity
IBM acquires DataStax to boost watsonx’s generative AI capabilities
Harassment allegations against DEF CON veteran detailed in court filing
The AI Fix #39: AIs value their lives over yours, and flattery gets you nowhere

Several security issues were fixed in the Linux kernel.

* bsc#1237058 * bsc#1237062 Cross-References: * CVE-2025-24031

* bsc#1227320 * bsc#1227371 * bsc#1228585 * bsc#1236783

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Google rolls out free version of Gemini Code Assist for individuals
Review: Gemini Code Assist is good at coding
What the private sector can teach government about cloud computing
Flaw found in stalkerware apps, exposing millions of people. Here’s how to find out if your phone is being spied upon
MongoDB acquires Voyage AI to reduce hallucinations in AI applications
Microsoft gives Azure AI users a place to experiment with latest technologies
Shifting the cybersecurity odds
The software UK techies need to protect themselves now Apple’s ADP won’t

* bsc#1233296 * bsc#1236278 * bsc#1236470 Cross-References:

* bsc#1233296 * bsc#1236278 * bsc#1236470 Cross-References:

* bsc#1236783 Cross-References: * CVE-2024-53104

* bsc#1227320 * bsc#1227371 * bsc#1228585 * bsc#1236783

10 machine learning mistakes and how to avoid them
A smarter approach to training AI models
AI coding assistants are on a downward spiral
Rather than add a backdoor, Apple decides to kill iCloud E2EE for UK peeps