Menu

Latest articles

Retrieval-augmented generation with Nvidia NeMo Retriever
IBM can’t afford an unreliable cloud
More customers asking for Google’s Data Boundary, says Cloud Experience boss
Browser wars are back, predicts Palo Alto, thanks to AI

https://security-tracker.debian.org/tracker/DSA-5979-1

Go language previews performance-boosting garbage collector
Facial recognition works better in the lab than on the street, researchers show
Pot calls kettle black as China dubs US ‘surveillance empire’ over chip tracking
Microsoft’s Nuance coughs up $8.5M to rid itself of MOVEit breach suit
Workday warns of CRM breach after social engineers make off with business contact details
What Is A Virtual Private Network (VPN)?

* bsc#1236217 * bsc#1246118 * bsc#1247719 * bsc#1247720 * jsc#SLE-18320

Google adds VM monitoring to Database Center amid enterprise demand
Introducing Red Hat Technical Account Management Service for Product Security
Boffins say tool can sniff 5G traffic, launch ‘attacks’ without using rogue base stations
Every question you ask, every comment you make, I’ll be recording you
How does the metrics layer enhance the power of advanced analytics?
Why software developers burn out, and how to fix it
Why AI fails at business context, and what to do about it

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1244631 * bsc#1245218 * bsc#1245350 * bsc#1245989 * bsc#1247350

* bsc#1244337 * bsc#1247350 * bsc#1247351 Cross-References:

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

* bsc#1245218 * bsc#1245350 * bsc#1247350 * bsc#1247351

Someone’s poking the bear with infostealers targeting Russian crypto developers

https://security-tracker.debian.org/tracker/DSA-5978-1

P2P payment service Zelle sued for enabling payment fraud hell

Update to upstream 1.4.2, fix CVE-2025-22870

* bsc#1245320 Cross-References: * CVE-2025-6032

* bsc#1245320 Cross-References: * CVE-2025-6032

Election workers fear threats and intimidation without feds’ support in 2026

Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker

Updated to 139.0.7258.127 * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker

Typhoon-adjacent Chinese crew broke into Taiwanese web host
Cisco’s Secure Firewall Management Center now not-so secure, springs a CVSS 10 RCE hole

An update that fixes 5 vulnerabilities is now available.

Cyberattack on Dutch prosecution service is keeping speed cameras offline
Telco giant Colt suffers attack, takes systems offline
The truth about Python’s AI-powered popularity surge
Can your cloud provider really scale?
LLM chatbots trivial to weaponize for data theft, say boffins
Should UK.gov save money by looking for open source alternatives to Microsoft? You decide

fix CVE-2025-46206 (rhbz#2386395)

fixes CVE-2025-8534: null pointer dereference in tiff2p fixes CVE-2024-13978: null pointer dereference in tiff2pdf

update MANUAL to cover threat related to user HTML iframe

Ransomware crews don’t care about your endpoint security – they’ve already killed it

Several security issues were fixed in AIDE.

* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References:

https://security-tracker.debian.org/tracker/DSA-5975-1

https://security-tracker.debian.org/tracker/DSA-5974-1

Psst: wanna buy a legit FBI email account for $40?
‘MadeYouReset’ HTTP/2 flaw lets attackers DoS servers
Lock down your critical infrastructure, CISA begs admins
BtcTurk suspends operations amid alleged $49M hot wallet heist
Law and water: Russia blamed for US court system break-in and Norwegian dam drama
What Is a Use-After-Free (UAF) Vulnerability?
Italian hotels breached en masse since June, government confirms

Several security issues were fixed in Request Tracker.

Stock in the Channel pulls website amid cyberattack
Monitoring microservices: Best practices for robust systems
Wassette: A bridge between Wasm and MCP

Several security issues were fixed in Sidekiq.

The £9 billion question: To Microsoft or not to Microsoft?

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5977-1

https://security-tracker.debian.org/tracker/DSA-5976-1

Smashing Security podcast #430: Poisoned Calendar invites, ChatGPT, and Bromide
Fortinet discloses critical bug with working exploit code amid surge in brute-force attempts
Supply-chain dependencies: Check your resilience blind spot

Does your business truly understand its dependencies, and how to mitigate the risks posed by an attack on them?

How the always-on generation can level up its cybersecurity game

Digital natives are comfortable with technology, but may be more exposed to online scams and other threats than they think

Crooks can’t let go: Active attacks target Office vuln patched 8 years ago
The MedusaLocker ransomware gang is hiring penetration testers
The AI Fix #63: GPT-5 is the best AI ever, and Jim Acosta interviews a murdered teenager’s avatar
US reveals it seized $1 million worth of Bitcoin from Russian BlackSuit ransomware gang

* bsc#1243747 Cross-References: * CVE-2025-48057

* bsc#1246397 Cross-References: * CVE-2025-48924

* bsc#1085999 * bsc#1246397 Cross-References: * CVE-2025-48924

* bsc#1247249 Cross-References: * CVE-2025-8194

UK expands police facial recognition rollout with 10 new vans heading to a town near you
Claude Sonnet 4 upgrade enables full codebase processing in a single request

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Marc Andreessen wades into the UK’s Online Safety Act furor
Microsoft wares may be UK public sector’s only viable option
Secure chat darling Matrix admits pair of ‘high severity’ protocol flaws need painful fixes
Hands-on with Svelte: Build-time compilation in a reactive framework
Five kinds of static code coupling
Ransomware crew spills Saint Paul’s 43GB of secrets after city refuses to cough up cash
Crypto-crasher Do Kwon admits guilt over failed not-so-stablecoin that erased $41 billion
National Security & AI at DEFCON 2025: Where Code Meets Crisis