Menu

Latest articles

How Terraform is evolving infrastructure as code
China cracks down on personal information collection. No, seriously
Oracle Health reportedly warns of info leak from legacy server

Microcode updates has been released for Intel(R) processors, addressing multiple potential vulnerabilties that may allow local privilege escalation, denial of service or information disclosure.

Multiple vulnerabilities were discovered in vim, an enhanced vi editor. CVE-2021-3872

Update to 0.4.8; Fixes: RHBZ#2237964, RHBZ#2282129

An issue has been found in librabbitmq, a AMQP client library and tools written in C. The issue is related to credential visibility when

Malware in Lisp? Now you’re just being cruel

Update to 2.12.10

CVE-2025-2588

Google introduces Gemini 2.5 reasoning models
ECMAScript 2025 JavaScript standard takes shape

* bsc#1235147 Cross-References: * CVE-2024-5594

* bsc#1239685 Cross-References: * CVE-2025-2361

* bsc#1238685 Cross-References: * CVE-2025-22870

How Cloud Security is Transforming Cybersecurity Services
VanHelsing ransomware: what you need to know
Cardiff’s children’s chief confirms data leak 2 months after cyber risk was ‘escalated’
Thread-y or not, here’s Python!
Are we creating too many AI models?
After Chrome patches zero-day used to target Russians, Firefox splats similar bug
Cyber-crew claims it cracked American cableco, releases terrible music video to prove it

CVE-2025-2588

Update to 1.1.43, fixes CVE-2024-55549 and CVE-2025-24855.

Added patch for CVE-2024-4068 (rhbz#2280624)

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

China’s FamousSparrow flies back into action, breaches US org after years off the radar
Adobe announces AI agents for customer interaction

https://security-tracker.debian.org/tracker/DSA-5888-1

Several security issues were fixed in the Linux kernel.

Security shop pwns ransomware gang, passes insider info to authorities
CrushFTP CEO’s feisty response to VulnCheck’s CVE for critical make-me-admin bug

Alexander Tan discovered that the OpenSAML C++ library was susceptible to forging of signed SAML messages. For additional details please refer to the upstream advisory at https://shibboleth.net/community/advisories/secadv_20250313.txt

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

* bsc#1239330 Cross-References: * CVE-2024-6104 * CVE-2025-22869

UK’s first permanent facial recognition cameras installed in South London
Ransomwared NHS software supplier nabs £3M discount from ICO for good behavior
Malaysian PM says “no way” to $10 million ransom after alleged cyber attack against Kuala Lumpur airport
What next for WASI on Azure Kubernetes Service?
Smashing Security podcast #410: Unleash the AI bot army against the scammers – now!
Microsoft lauds Hyperlight Wasm for WebAssembly workloads
Signalgate storm intensifies as journalist releases full secret Houthi airstrike chat

https://security-tracker.debian.org/tracker/DSA-5886-1

US defense contractor cops to sloppy security, settles after infosec lead blows whistle
Files stolen from NSW court system, including restraining orders for violence
Credible nerd says stop using atop, doesn’t say why, everyone panics
Critical RCE flaws put Kubernetes clusters at risk of takeover

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239339 Cross-References: * CVE-2025-22869 * CVE-2025-27144

* bsc#1239460 Cross-References: * CVE-2025-24049

Databricks’ TAO method to allow LLM training with unlabeled data
NCSC taps influencers to make 2FA go viral
Intro to Alpine.js: A JavaScript framework for minimalists
What you need to know about Go, Rust, and Zig
Open-source Styrolite project aims to simplify container runtime security
Vibe coding is groovy

https://security-tracker.debian.org/tracker/DSA-5887-1

Oracle releases ML-optimized GraalVM for JDK 24
Warning for developers, web admins: update Next.js to prevent exploit
There are perhaps 10,000 reasons to doubt Oracle Cloud’s security breach denial
The AI Fix #43: I, for one, welcome our new robot overlords!
Infosec pro Troy Hunt HasBeenPwned in Mailchimp phish

This upload fixes two security issues in the version of nginx shipped in bullseye. CVE-2024-7347

Fauna to shut down FaunaDB service in May
GenAI tools for R: New tools to make R programming easier
Cosmonic uses WebAssembly to manage apps
Google acquires Wiz: A win for multicloud security
You know that generative AI browser assistant extension is probably beaming everything to the cloud, right?

* bsc#1239465 Cross-References: * CVE-2025-27363

VanHelsing ransomware emerges to put a stake through your Windows heart
Hm, why are so many DrayTek routers stuck in a bootloop?

Several security issues were fixed in SmartDNS.

Public-facing Kubernetes clusters at risk of takeover thanks to Ingress-Nginx flaw

Update to 134.0.6998.117 * Critical CVE-2025-2476: Use after free in Lens

0.9.30, rebuild due golang CVE-2025-22870

OTF, which backs Tor, Let’s Encrypt and more, sues to save funding from Trump cuts
Top Trump officials text classified Yemen airstrike plans to journo in Signal SNAFU
FCC on the prowl for Huawei and other blocked Chinese makers in America
As nation-state hacking becomes ‘more in your face,’ are supply chains secure?

https://security-tracker.debian.org/tracker/DSA-5885-1

Ivan Fratric discovered two use-after-free vulnerabilities in libxslt, an XSLT processing runtime library, which may result in the execution of arbitrary code if a specially crafted files are processed.

AI agents swarm Microsoft Security Copilot
23andMe’s genes not strong enough to avoid Chapter 11
Anatomy of Linux Ransomware Attacks and Protection Strategies
Is Washington losing its grip on crypto, or is it a calculated pivot to digital dominance?

Two use-after-free vulnerabilities have been fixed in the XSLT processing library libxslt. CVE-2024-55549

Microsoft tastes the unexpected consequences of tariffs on time
Learning AI governance lessons from SaaS and Web2
Prompt engineering courses and certifications tech companies want