Menu

Latest articles

Could agentic AI save us from the cybercrisis?
Microsoft researchers bullish on AI security agent even though it let 74% of malware slip through
Google updates agents in BigQuery to further automate analytics tasks
Google says the group behind last year’s Snowflake attack slurped data from one of its Salesforce instances
ESET Threat Report H1 2025: ClickFix, infostealer disruptions, and ransomware deathmatch

Threat actors are embracing ClickFix, ransomware gangs are turning on each other – toppling even the leaders – and law enforcement is disrupting one infostealer after another

Ransomware plunges insurance company into bankruptcy

Multiple vulnerabilities have been discovered in Composer, the worst of which can lead to arbitrary code execution.

A vulnerability has been discovered in Spreadsheet-ParseExcel, which can lead to arbitrary code execution.

A vulnerability has been discovered in NSS, which can lead to the recovery of private data.

A vulnerability has been discovered in FontForge, which can lead to arbitrary code execution.

TypeScript 5.9 arrives with deferred module evaluation, expandable hovers
Google Spanner gets a columnar engine to unite OLTP and OLAP workloads
Hospital fined after patient data found in street food wrappers

Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which can lead to execution of arbitrary code.

Multiple vulnerabilities have been discovered in PAM, the worst of which could lead to privilege escalation.

Roo Code review: Autonomous AI-powered development in the IDE
How to code sign binaries on Windows
How to measure coupled code
Vibe coding tool Cursor’s MCP implementation allows persistent code execution
JetBrains previews no-code app builder
Patch now: Millions of Dell PCs with Broadcom chips vulnerable to attack
Study finds humans not completely useless at malware detection
Chained bugs in Nvidia’s Triton Inference Server lead to full system compromise
The AI Fix #62: AI robots can now pass CAPTCHAs, and punch you in the face
What Is a RCE Vulnerability?

* bsc#1245773 Cross-References: * CVE-2025-53367

* bsc#1247249 Cross-References: * CVE-2025-8194

* bsc#1247249 Cross-References: * CVE-2025-8194

Hacker summer camp: What to expect from BSides, Black Hat, and DEF CON
Why benchmarks are key to AI progress
The problem with AI agent-to-agent communication protocols
Python popularity boosted by AI coding assistants – Tiobe
Antivirus vendors fail to spot persistent, nasty, stealthy Linux backdoor
SonicWall investigates ‘cyber incidents,’ including ransomware targeting suspected 0-day
Python-powered malware snags hundreds of credit cards, 200K passwords, and 4M cookies
Mozilla flags phishing wave aimed at hijacking trusted Firefox add-ons
German phone repair biz collapses following 2023 ransomware attack
When hyperscalers can’t safeguard one nation’s data from another, dark clouds are ahead
Millions of age checks performed as UK Online Safey Act gets rolling
Microsegmentation for developers
9 habits of the highly ineffective vibe coder
Erasing the trust gap in AI-driven development

* bsc#1234675 * bsc#1235461 * bsc#1235871 Cross-References:

* bsc#1228645 * bsc#1235250 * bsc#1245771 * bsc#1245776 * bsc#1245793

* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:

* bsc#1235250 * bsc#1245776 * bsc#1245793 * bsc#1245797

* bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References:

China’s botched Great Firewall upgrade invites attacks on its censorship infrastructure
Lazarus Group rises again, this time with malware-laden fake FOSS
Silent Push CEO on cybercrime takedowns: ‘It’s an ongoing cat-and-mouse game’

Update to 138.0.7204.183 * CVE-2025-8292: Use after free in Media Stream

This update fixes CVE-2025-7345 and CVE-2025-6199.

This update fixes these CVEs: CVE-2025-32364 CVE-2025-32365 CVE-2024-56378

reposurgeon: update to 5.3 version

In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. References: – https://bugs.mageia.org/show_bug.cgi?id=34447

Stefan Buehler discovered a flaw in sope, the set of Objective-C frameworks powering SOGo, which may result in denial of service via a specially crafted POST request.

Is your phone spying on you? | Unlocked 403 cybersecurity podcast (S2E5)

Here’s what you need to know about the inner workings of modern spyware and how to stay away from apps that know too much

Why the tech industry needs to stand firm on preserving end-to-end encryption

Restricting end-to-end encryption on a single-country basis would not only be absurdly difficult to enforce, but it would also fail to deter criminal activity

CISA roasts unnamed critical national infrastructure body for shoddy security hygiene

A flaw was found in how GLib¢”s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn¢”t. As a result, data may be written […]

This update fixes these CVEs: CVE-2025-4948 CVE-2025-32908 CVE-2025-32907 CVE-2025-4969

Backports patch to fix non-CVE 2025-8224

What Is An XSS Vulnerability?

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Apache Flink integrates AI for real-time decision-making
OpenAI removes ChatGPT self-doxing option

https://security-tracker.debian.org/tracker/DSA-5970-1

Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks
China says US spies exploited Microsoft Exchange zero-day to steal military info
This month in security with Tony Anscombe – July 2025 edition

Here’s a look at cybersecurity stories that moved the needle, raised the alarm, or offered vital lessons in July 2025

Florida prison email blunder exposes visitor contact info to inmates

* bsc#1243855 Cross-References: * CVE-2024-12224

* bsc#1243868 Cross-References: * CVE-2024-12224

* bsc#1221107 Cross-References: * CVE-2024-2236

Google upgrades Agent2Agent protocol with gRPC and enterprise-grade security
Deploy sensitive workloads with OpenShift confidential containers
Confidential containers on Microsoft Azure with Red Hat OpenShift Sandboxed Containers 1.10 and Red Hat Build of Trustee

An update that fixes one vulnerability is now available.

Cybercrooks attached Raspberry Pi to bank network and drained ATM cash
Spotlight report: How AI is reshaping IT
Fun and profit with ECMAScript 2025: What’s new in JavaScript
.NET Aspire 9.4 boasts CLI core commands, AI integrations
Dedicated servers outpace public clouds for AI
Top spy says LinkedIn profiles that list defense work ‘recklessly invite attention of foreign intelligence services’
As ransomware gangs threaten physical harm, ‘I am afraid of what’s next,’ ex-negotiator says
Gene scanner pays $9.8 million to get feds off its back in security flap
Microsoft’s Azure AI Speech needs just seconds of audio to spit out a convincing deepfake
Beijing summons Nvidia over alleged backdoors in China-bound AI chips
Kremlin goons caught abusing ISPs to spy on Moscow-based diplomats, Microsoft says
Silk Typhoon spun a web of patents for offensive cyber tools, report says
Brit watchdog pushes to rein in Microsoft and AWS with ‘strategic market status’
Informatica enhances IDMC with AI-powered MDM, governance, and compliance tools