Nearly every aspect of life is connected to the internet, so protecting your devices, identity, and privacy has never been more critical. Cyber threats are no longer just the occasional virus or suspicious email. Phishing scams, ransomware attacks, data breaches, and identity theft are part of a growing list of online dangers that are a […]
Cyber threats. Identity theft. Online profiling. Financial fraud. Social media misuse. The list just gets longer. As more aspects of our lives move online and digital devices proliferate, staying safe from threats has become more important than ever. Consider all the connected devices you use for daily tasks—browsing, shopping, banking, gaming, and more. Then think […]
OpenText recently surveyed 255 MSPs to uncover key trends shaping the future of Managed Detection and Response (MDR). One technology area it explored was security orchestration, automation, and response (SOAR)—the workhorse behind automating security workflows. The survey revealed several key benefits of SOAR in MDR, highlighting how it can help MSPs and SMBs improve incident […]
Security fixes for CVE-2024-11168 and CVE-2025-0938
update to 1.33.2 fix CVE-2025-24898
Security fixes for CVE-2024-11168 and CVE-2025-0938
update to 1.33.2 fix CVE-2025-24898
Multiple vulnerabilities have been found in libxml2, a library providing support to read, modify and write XML and HTML files. These vulnerabilities could potentially lead to denial of servie or other unintended behaviors.
Update to 133.0.6943.126 CVE-2025-0999: Heap buffer overflow in V8 CVE-2025-1426: Heap buffer overflow in GPU CVE-2025-1006: Use after free in Network
This update addresses a null pointer dereferencing issue that could cause the session for a client that sent specially-crafted commands to the server to crash (not the sessions of other clients).
This update addresses a null pointer dereferencing issue that could cause the session for a client that sent specially-crafted commands to the server to crash (not the sessions of other clients).
Bing Shi discovered that GnuTLS, a portable library which implements the Transport Layer Security and Datagram Transport Layer Security protocols, had inefficient handling of certificate data with a large number of names or name constraints, potentially leading to Denial of
* bsc#1236946 Cross-References: * CVE-2024-27856 * CVE-2024-54543
A North Korea-aligned activity cluster tracked by ESET as DeceptiveDevelopment drains victims’ crypto wallets and steals their login details from web browsers and password managers
* bsc#1237084 Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP6
* bsc#1237084 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5
* bsc#1236560 Cross-References: * CVE-2024-45339
https://security-tracker.debian.org/tracker/DSA-5869-1
Some employment scams take an unexpected turn as cybercriminals shift from “hiring” to “firing” staff
The following vulnerabilities have been discovered in the package mosquitto, MQTT message broker.
The 6.12.15 stable kernel update contains a number of important fixes across the tree. The 6.12.14 stable kernel update contains a number of important fixes across the tree.
Fix regression of Match directive processing
Includes CVE fixes.
Update gnutls to the latest upstream release, including a fix for CVE-2024-12243.
Security fix for CVE-2025-0938
The atmospheric scientist makes a compelling case for a head-to-heart-to-hands connection as a catalyst for climate action
* bsc#1237091 Cross-References: * CVE-2025-1244
* bsc#1237037 * bsc#1237038 Cross-References: * CVE-2025-24970
* bsc#1237096 Cross-References: * CVE-2024-31068 * CVE-2024-36293
Several security issues were fixed in libsndfile.
https://security-tracker.debian.org/tracker/DSA-5867-1
* bsc#1237091 Cross-References: * CVE-2025-1244
A vulnerability was discovered in pam-pkcs11, a PAM module which allows to use PKCS#11 based smart cards in the PAM authentication stack, which may allow to bypass the authentication in some scenarios.
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enabled (disabled by default).
Several security issues were fixed in Docker.
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enabled (disabled by default).
* bsc#1237096 Cross-References: * CVE-2024-31068 * CVE-2024-36293
https://security-tracker.debian.org/tracker/DSA-5868-1
The virtual treasure chests and other casino-like rewards inside your children’s games may pose risks you shouldn’t play down
Ever wondered what it’s like to hack for a living – legally? Learn about the art and thrill of ethical hacking and how white-hat hackers help organizations tighten up their security.
As AI advances at a rapid clip, reshaping industries, automating tasks, and redefining what machines can achieve, one question looms large: what remains uniquely human?
Deepfake fraud, synthetic identities, and AI-powered scams make identity theft harder to detect and prevent – here’s how to fight back
Don’t wait for a costly breach to provide a painful reminder of the importance of timely software patching
As is their wont, cybercriminals waste no time launching attacks that aim to cash in on the frenzy around the latest big thing – plus, what else to know before using DeepSeek
DeepSeek’s bursting onto the AI scene, apparent shifts in US cybersecurity policies, and a massive student data breach all signal another eventful year in cybersecurity and data privacy
You should think twice before trusting your AI assistant, as database poisoning can markedly alter its output – even dangerously so
Left unchecked, AI’s energy and carbon footprint could become a significant concern. Can our AI systems be far less energy-hungry without sacrificing performance?
The renowned physicist explores how time and entropy shape the evolution of the universe, the nature of existence, and the eventual fate of everything, including humanity
Don’t roll the dice on your online safety – watch out for bogus sports betting apps and other traps commonly set by scammers
Incoming laws, combined with broader developments on the threat landscape, will create further complexity and urgency for security and compliance teams
Data breaches can cause a loss of revenue and market value as a result of diminished customer trust and reputational damage
ESET researchers uncover a vulnerability in a UEFI application that could enable attackers to deploy malicious bootkits on unpatched systems
