Menu

Latest articles

Update to upstream 2.1-48. 20250211 Addition of 06-bf-06/0x07 microcode (in intel-ucode/06-97-02) at revision 0x38; Addition of 06-bf-07/0x07 microcode (in intel-ucode/06-97-02) at revision 0x38; Addition of 06-bf-06/0x07 microcode (in intel-ucode/06-97-05) at revision 0x38; Addition of 06-bf-07/0x07 microcode (in intel-ucode/06-97-05) at revision 0x38;

Update to 133.0.6943.98 CVE-2025-0995: Use after free in V8 CVE-2025-0996: Inappropriate implementation in Browser UI CVE-2025-0997: Use after free in Navigation CVE-2025-0998: Out of bounds memory access in V8

Multiple vulnerabilities were fixed in trafficserver, a caching proxy server. CVE-2024-38479

C’©dric Krier has found that trytond, the Tryton application server, accepts compressed content from unauthenticated requests which makes it vulnerable to zip bomb attacks (see DLA 4022-1).

Buckle up for faster Python programs
Nearly 10 years after Data and Goliath, Bruce Schneier says: Privacy’s still screwed
EPMS: the cornerstone of cybersecurity in defense operations
Democratize security processes in your software development lifecycle

Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162

Latest upstream release. It adds support for tiles and fixes reading images generated by iOS 18+. See https://github.com/strukturag/libheif/releases for more details about the changes since 1.17.6. NOTE: heif-convert tool was renamed to heif-dec. How to test:

Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.

Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.

Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.

Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.

AI coding assistants limited but helpful, developers say
If you dread a Microsoft Teams invite, just wait until it turns out to be a Russian phish
SonicWall firewalls now under attack: Patch ASAP or risk intrusion via your SSL VPN
Transparency in AI: How Open-Source LLMs Can Prevent Hidden Vulnerabilities
Critical PostgreSQL bug tied to zero-day attack on US Treasury

* bsc#1236878 Cross-References: * CVE-2024-12133

2 charged over alleged New IRA terrorism activity linked to cops’ spilled data

Several security issues were fixed in Apache ActiveMQ.

Watchdog ponders why Apple doesn’t apply its strict app tracking rules to itself
Buckle up for the supercharged Python interpreter
Avoiding the cloud migration graveyard

* bsc#1212641 * bsc#1219912 * bsc#1229079 * bsc#1229104 * bsc#1231024

* bsc#1212641 * bsc#1219912 * bsc#1229079 * bsc#1229104 * bsc#1231024

US charges two Russian men in connection with Phobos ransomware operation
Chinese spies suspected of ‘moonlighting’ as tawdry ransomware crooks

https://security-tracker.debian.org/tracker/DSA-5866-1

JetBrains’ Ktor adds CLI for simpler project creation
More victims of China’s Salt Typhoon crew emerge: Telcos just now hit via Cisco bugs
US lawmakers press Trump admin to oppose UK’s order for Apple iCloud backdoor
US Coast Guard told to improve its cybersecurity, after warning raised that hacked ports could cost $2 billion per day

* bsc#1012628 * bsc#1194869 * bsc#1215199 * bsc#1216813 * bsc#1218470

* bsc#1236705 Cross-References: * CVE-2025-0938

* bsc#1218879 * bsc#1218880 * bsc#1218881 * bsc#1218882 * bsc#1218883

* bsc#1228044 * bsc#1236282 Cross-References: * CVE-2025-0395

North Korea targets crypto developers via NPM supply chain attack
How to adopt platform engineering in 2025
US woman faces years in federal prison for running laptop farm for N Korean IT workers
How to use mutexes and semaphores in C#
Diving into the Windows Copilot Runtime
Mysterious Palo Alto firewall reboots? You’re not alone
Have I Been Pwned likely to ban resellers from buying subs, citing ‘sh*tty behavior’ and onerous support requests
Feds want devs to stop coding ‘unforgivable’ buffer overflow vulnerabilities
Sophos sheds 6% of staff after swallowing Secureworks
Go 1.24 arrives with generic type aliases, boosted WebAssembly support
Smashing Security podcast #404: Podcast not found
Trump’s cyber chief pick has little experience in The Cyber
Arizona laptop farmer pleads guilty for funneling $17M to Kim Jong Un
Ransomware isn’t always about the money: Government spies have objectives, too
UK, US, Oz blast holes in LockBit’s bulletproof hosting provider Zservers
Russia’s Sandworm caught snarfing credentials, data from American and Brit orgs
Snowflake announces preview of Cortex Agent APIs to power enterprise data intelligence
Crimelords and spies for rogue states are working together, says Google

* bsc#1229644 * bsc#1230998 * bsc#1231993 Cross-References:

* bsc#1229644 * bsc#1229663 * bsc#1230998 * bsc#1231993

* bsc#1230998 * bsc#1231993 Cross-References: * CVE-2024-45016

Dynamic web apps with HTMX, Python, and Django
Rust memory management explained
Keep your code open to possibilities
February’s Patch Tuesday sees Microsoft offer just 63 fixes
Don’t use public ASP.NET keys (duh), Microsoft warns

https://security-tracker.debian.org/tracker/DSA-5865-1

https://security-tracker.debian.org/tracker/DSA-5864-1

Probe finds US Coast Guard has left maritime cybersecurity adrift
Yup, AMD’s Elba and Giglio definitely sound like they work corporate security
‘Key kernel maintainers’ still back Rust in the Linux kernel, despite the doubters
Triplestrength hits victims with triple trouble: Ransomware, cloud hijacks, crypto-mining

https://security-tracker.debian.org/tracker/DSA-5863-1

OpenText recently surveyed 255 MSPs to uncover key trends shaping the future of Managed Detection and Response (MDR). The findings reveal not only what cybersecurity professionals are prioritizing but also how MSPs can better meet the evolving demands of their small and midsize business (SMB) customers. One key takeaway from the survey: 81% of respondents […]

Man who SIM-swapped the SEC’s X account pleads guilty
I’m a security expert, and I almost fell for a North Korea-style deepfake job applicant …Twice

* bsc#1228165 * bsc#1236705 Cross-References: * CVE-2025-0938

* bsc#1227056 * bsc#1236483 Cross-References: * CVE-2023-45288

* bsc#1218879 * bsc#1218880 * bsc#1218881 * bsc#1218882 * bsc#1218883

Why the generative AI hype is good
Review: Zencoder has a vision for AI coding
The cloud giants stumble
C++, Go, and Rust gaining popularity – Tiobe
Apple warns ‘extremely sophisticated attack’ may be targeting iThings
All your 8Base are belong to us: Ransomware crew busted in global sting
What you need to know about Python 3.14’s faster interpreter
Toll booth bandits continue to scam via SMS messages

February is a great month to refresh your cyber awareness skills. February 11 marks Safer Internet Day, encouraging us to work together to make the internet a safer and better place. It’s the perfect time to learn more about cybersecurity risks and best practices for protecting yourself and your loved ones online. And while February […]

Secret Taliban records published online after hackers breach computer systems
Navigating AI-Driven Security Challenges in Linux Environments
US news org still struggling to print papers a week after ‘cybersecurity event’

* bsc#1236619 * jsc#PED-12018 Cross-References: * CVE-2025-24528