Menu

Latest articles

version update security update

1.282 – Sanitize all user-supplied values before inserting into HTTP headers; Fixed CVE-2025-40927.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, same-origin policy bypass or privilege escalation.

Users report chaos as Legal Aid Agency stumbles back online after cyberattack
Document databases – understanding your options
Microsoft’s Dev Proxy puts APIs to the test

Several security issues were fixed in libpng.

Qt could be made to crash or run programs as your login if it opened a specially crafted file.

It’s everyone but Meta in a new AI standards group
Did your npm pipeline break today? Check your ‘classic’ tokens
Smashing Security podcast #447: Grok the stalker, the Louvre heist, and Microsoft 365 mayhem
700+ self-hosted Gits battered in 0-day attacks with no fix imminent
US extradites Ukrainian woman accused of hacking meat processing plant for Russia
Microsoft won’t fix .NET RCE bug affecting slew of enterprise apps, researchers say
The big catch: How whaling attacks target top executives

Is your organization’s senior leadership vulnerable to a cyber-harpooning? Learn how to keep them safe.

Ransomware may have extorted over $2.1 billion between 2022-2024, but it’s not all bad news, claims FinCEN report
Protecting value at risk – the role of a risk operations center

* bsc#1251198 * bsc#1251199 Cross-References: * CVE-2025-61984

* bsc#1238879 Cross-References: * CVE-2025-27516

* bsc#1254132 Cross-References: * CVE-2025-9820

Crisis in Icebergen: How NATO crafts stories to sharpen cyber skills
Four years later, Irish health service offers €750 to victims of ransomware attack

Insufficient validation of incoming notifies over TCP in PDNS Recursor, a resolving name server, could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 5.2.7-0+deb13u1. We recommend that you upgrade your pdns-recursor packages.

Is vibe coding the new gateway to technical debt?
PythoC: A new way to generate C code from Python
Why AI agents are so good at coding

Several vulnerabilities were reported in the libpng PNG library, which could lead to information leaks, denial of service or potentially the execution of arbitrary code if a specially crafted image is processed. For the oldstable distribution (bookworm), these problems have been fixed in version 1.6.39-2+deb12u1.

* bsc#1244485 * bsc#1245878 * bsc#1254227 * bsc#1254430 * bsc#1254431

GitHub Action Secrets aren’t secret anymore: exposed PATs now a direct path into cloud environments
Linux Foundation launches Agentic AI Foundation

https://security-tracker.debian.org/tracker/DSA-6079-1

https://security-tracker.debian.org/tracker/DSA-6078-1

https://security-tracker.debian.org/tracker/DSA-6077-1

https://security-tracker.debian.org/tracker/DSA-6076-1

https://security-tracker.debian.org/tracker/DSA-6075-1

Microsoft reports 7.8-rated zero day, plus 56 more in December Patch Tuesday
How to answer the door when the AI agents come knocking
Porsche panic in Russia as pricey status symbols forget how to car
Privacy concerns raised as Grok AI found to be a stalker’s best friend
California man admits role in $263 million cryptocurrency theft that funded lavish lifestyle
The AI Fix #80: DeepSeek’s cheap GPT-5 rival, Antigravity fails, and why being rude to AI makes it smarter
As humanoid robots enter the mainstream, security pros flag the risk of botnets on legs
AWS is still chasing a cohesive enterprise AI story after re:Invent

Several security issues were fixed in radare2.

* bsc#1241772 * bsc#1250683 * bsc#1253181 * bsc#1253185 * bsc#1253186

UK to Europe: The time to counter Russia’s information war machine is now

python-apt could be made to crash if it opened a specially crafted file.

UK finally vows to look at 35-year-old Computer Misuse Act
Whitehall rejects £1.8B digital ID price tag – but won’t say what it will cost
Amazon Q Developer: Everything you need to know
The hidden cost of Amazon Nova 2

* bsc#1254132 Cross-References: * CVE-2025-9820

An update that solves one vulnerability can now be installed.

* bsc#1250497 Cross-References: * CVE-2025-10922

Researchers spot 700 percent increase in hypervisor ransomware attacks
IBM to buy Confluent to extend its data and automation portfolio

https://security-tracker.debian.org/tracker/DSA-6074-1

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), this problem has been fixed in version 7:7.1.3-0+deb13u1.

AWS takes aim at the PoC-to-production gap holding back enterprise AI
193 cybercrims arrested, accused of plotting ‘violence-as-a-service’
UK moves to strengthen undersea cable defenses as Russian snooping ramps up
Home Office kept police facial recognition flaws to itself, UK data watchdog fumes
Barts Health seeks High Court block after Clop pillages NHS trust data
10 MCP servers for devops
AI memory is really a database problem
Block all AI browsers for the foreseeable future: Gartner
China’s first reusable rocket explodes, but its onboard Ethernet network flew
Apache warns of 10.0-rated flaw in Tika metadata ingestion tool

Multiple vulnerabilties have been found in libpng, the official PNG reference library, allowing information disclosure via out-of-bounds read, denial of service via application crash, or heap corruption with potential for arbitrary code execution.

Update to 2.9.7

Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287

Update to 2.9.7

https://security-tracker.debian.org/tracker/DSA-6073-1

Solving tool overload, one automation step at a time
Red Hat OpenShift sandboxed containers 1.11 and Red Hat build of Trustee 1.0 accelerate confidential computing across the hybrid cloud
CIS publishes hardening guidance for Red Hat OpenShift Virtualization
AI ambitions meet automation reality: The case for a unified automation platform
From vision to reality: A 5-step playbook for unified automation and AI
Death to one-time text codes: Passkeys are the new hotness in MFA

Loading a manipulated TGA file in krita, an image manipulation program, could result in a heap-based buffer overflow in KisTgaImport.

Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials

Fix CVE-2025-12744

Update to cef-142.0.17+g60aac24 & chromium 142.0.7444.175 (rhbz#2413981) High CVE-2025-13223: Type Confusion in V8 High CVE-2025-13224: Type Confusion in V8

Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials

Fix CVE-2025-12744

Crims using social media images, videos in ‘virtual kidnapping’ scams
Novel clickjacking attack relies on CSS and SVG
Cloudflare blames Friday outage on borked fix for React2shell vuln

https://security-tracker.debian.org/tracker/DSA-6072-1

https://security-tracker.debian.org/tracker/DSA-6071-1

Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture

Identity is effectively the new network boundary. It must be protected at all costs.

Asus supplier hit by ransomware attack as gang flaunts alleged 1 TB haul
Beijing-linked hackers are hammering max-severity React bug, AWS warns
AI in CI/CD pipelines can be tricked into behaving badly
UK pushes ahead with facial recognition expansion despite civil liberties backlash

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Bots, bias, and bunk: How can you tell what’s real on the net?