Menu

Latest articles

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

xorg-x11-server CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180

Update to 3.13.5, this release fixes the following CVEs: CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, CVE-2025-4435, and CVE 2025-4517

Crims are posing as insurance companies to steal health records and payment info
Google touts Python client library for Data Commons

https://security-tracker.debian.org/tracker/DSA-5951-1

Cisco punts network-security integration as key for agentic AI
Aloha, you’ve been pwned: Hawaiian Airlines discloses ‘cybersecurity event’
So you CAN turn an entire car into a video game controller
Data spill in aisle 5: Grocery giant Ahold Delhaize says 2.2M affected after cyberattack

* bsc#1232908 * bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062

* bsc#1235231 Cross-References: * CVE-2024-56601

SafePay ransomware: What you need to know
Dumping mainframes for cloud can be a costly mistake
Rust-powered: Two new Python tools to watch

* bsc#1239948 * bsc#1244304 * bsc#1244503 Cross-References:

Rust 1.88 adds support for naked functions

https://security-tracker.debian.org/tracker/DSA-5952-1

https://security-tracker.debian.org/tracker/DSA-5950-1

FBI used bitcoin wallet records to peg notorious IntelBroker as UK national
What if Microsoft just turned you off? Security pro counts the cost of dependency
Cisco fixes two critical make-me-root bugs on Identity Services Engine components
Teradata aims to simplify on-premises AI for data scientists with AI Factory

Several security issues were fixed in libarchive.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1243565 * bsc#1245054 * bsc#1245055 Cross-References:

* bsc#1236217 * bsc#1244156 * bsc#1244157 * bsc#1244158 * jsc#SLE-18320

Glasgow City Council online services crippled following cyberattack
Designing a metadata-driven ETL framework with Azure ADF: An architectural perspective
Qilin ransomware attack on NHS supplier contributed to patient fatality
Eclipse Foundation releases Jakarta EE 11
UK to buy nuclear-capable F-35As that can’t be refueled from RAF tankers
How to use route constraints in ASP.NET Core minimal APIs
Bringing post-quantum cryptography to Windows
Frozen foods supermarket chain deploys facial recognition tech
That WhatsApp from an Israeli infosec expert could be a Iranian phish
Ubuntu Chooses Performance Over Mitigation: Intel GPU Users See 20% Gains
Smashing Security podcast #423: Operation Endgame, deepfakes, and dead slugs
Citrix bleeds again: This time a zero-day exploited – patch now

https://security-tracker.debian.org/tracker/DSA-5949-1

https://security-tracker.debian.org/tracker/DSA-5948-1

Amazon’s Ring can now use AI to ‘learn the routines of your residence’
Computer vision research feeds surveillance tech as patent links spike 5×
Supply chain attacks surge with orgs ‘flying blind’ about dependencies
French cybercrime police arrest five suspected BreachForums admins
Aflac, one of the USA’s largest insurers, is the latest to fall “under siege” to hackers
Google unveils Gemini CLI for developers

* bsc#1244148 Cross-References: * CVE-2011-10007

* bsc#1232929 * bsc#1233680 * bsc#1233708 * bsc#1235062 * bsc#1235231

Nils Emmerich discovered several vulnerabilities in the Xorg X server, which may result in privilege escalation if the X server is running privileged.

UK govt dept website that campaigns against encryption hijacked to advertise … payday loans
Cybercrime is surging across Africa
Pyrefly and Ty: Two new Rust-powered Python type-checking tools compared
Software development meets the McNamara Fallacy

commons-beanutils, utility for manipulating Java beans have an improper Access Control vulnerability. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers

* bsc#1239192 Cross-References: * CVE-2025-22868

New AI benchmarking tools evaluate real world performance
Kotlin 2.2.0 arrives with context parameters, unified management of compiler warnings
Don’t panic, but it’s only a matter of time before critical ‘CitrixBleed 2’ is under attack
Beware of fake SonicWall VPN app that steals users’ credentials
The vulnerability management gap no one talks about
The AI Fix #56: ChatGPT traps man in a cult of one, and AI is actually stupid
Twitter refuses to explain what it’s doing about hate speech and misinformation, sues New York State for asking

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

IBM Donates CBOM Toolset to Linux Foundation
o3-pro may be OpenAI’s most advanced commercial offering, but GPT-4o bests it
Four REvil ransomware crooks walk free, escape gulag fate, after admitting guilt
LLMs aren’t enough for real-world, real-time projects
Public cloud becomes a commodity
‘Psylo’ browser tries to obscure digital fingerprints by giving every tab its own IP address
Google’s Agent2Agent project moves to Linux Foundation
Typhoon-like gang slinging TLS certificate ‘signed’ by the Los Angeles Police Department
Ktor adds dependency injection and HTMX modules
Marks & Spencer ransomware attack was good news for other retailers
Iran cyberattacks against US biz more likely following air strikes
Agentic AI won’t wait for your data architecture to catch up
Second attack on McLaren Health Care in a year affects 743k people
GitHub’s AI billing shift signals the end of free enterprise tools era
Experts count staggering costs incurred by UK retail amid cyberattack hell

Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version

How to succeed (or fail) with AI-driven development
Devops debt: The hidden tax on innovation
Why AI projects fail, and how developers can help them succeed

* bsc#1241067 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059

* bsc#1234421 * bsc#1244405 * bsc#1244406 Cross-References:

* bsc#1243721 Cross-References: * CVE-2025-5222