Menu

Latest articles

https://security-tracker.debian.org/tracker/DSA-6096-1

How hackers are fighting back against ICE surveillance tech
Credential stuffing: What it is and how to protect yourself

Reusing passwords may feel like a harmless shortcut – until a single breach opens the door to multiple accounts

Putinswap: France trades alleged ransomware crook for conflict researcher
QR codes a powerful new phishing weapon in hands of Pyongyang cyberspies
China-linked cybercrims abused VMware ESXi zero-days a year before disclosure

An update that solves one vulnerability can now be installed.

Grok told to cover up as UK weighs action over AI ‘undressing’
pcTattletale founder pleads guilty in rare stalkerware prosecution

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Help desk read irrelevant script, so techies found and fixed their own problem
As agents run amok, CrowdStrike’s $740M SGNL deal aims to help get a grip on identity security

Several security issues were fixed in Tornado.

GnuPG could be made to crash or run programs if it received specially crafted network traffic.

GnuPG could be made to crash or run programs if it received specially crafted network traffic.

Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit
Databricks says its Instruction Retrieval offers better AI answers than RAG in the enterprise
Ransomware attacks kept climbing in 2025 as gangs refused to stay dead
CISA flags actively exploited Office relic alongside fresh HPE flaw
UK regulators swarm X after Grok generated nudes from photos
Maximum-severity n8n flaw lets randos run your automation server
OpenAI putting bandaids on bandaids as prompt injection problems keep festering
Yes, criminals are using AI to vibe-code malware
Logitech macOS mouse mayhem traced to expired dev certificate
The hidden devops crisis that AI workloads are about to expose

An update that solves one vulnerability can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves two vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

An update that solves three vulnerabilities can now be installed.

Cloudflare pours cold water on ‘BGP weirdness preceded US attack on Venezuela’ theory

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

AI-built Rue language pairs Rust memory safety with ease of use
Smashing Security podcast #449: How to scam someone in seven days
IBM’s AI agent Bob easily duped to run malware, researchers show
ESA calls cops as crims lift off 500 GB of files, say security black hole still open
Stalkerware slinger pleads guilty for selling snooper software to suspicious spouses
Microsoft scraps Exchange Online spam clamp after customers cry foul
Red Hat Hybrid Cloud Console: Your questions answered
Ministry of Justice splurged £50M on security – still missed Legal Aid Agency cyberattack
Jaguar Land Rover wholesale volumes plummet 43% in cyberattack aftermath
Microsoft acquires Osmos to ease data engineering bottlenecks in Fabric
HSBC app takes a dim view of sideloaded Bitwarden installations
Generative UI: The AI agent is the front end
What the loom tells us about AI and coding

An update that solves three vulnerabilities and has two security fixes can now be installed.

An update that solves three vulnerabilities and has two security fixes can now be installed.

An update that solves four vulnerabilities can now be installed.

An update that solves four vulnerabilities can now be installed.

MGAA-2026-0003 – Updated isodumper packages fix bugs

MGAA-2026-0002 – Updated sddm-theme-coffee-ng packages fix bug

AI won’t replace human devs for at least 5 years
Automated data poisoning proposed as a solution for AI theft threat
Red Team Blue Team Insights for Linux Admins: Key Security Roles Explained
HackerOne ‘ghosted’ me for months over $8,500 bug bounty, says researcher

https://security-tracker.debian.org/tracker/DSA-6095-1

Ruby 4.0.0 introduces ZJIT compiler, Ruby Box isolation
Brightspeed investigates breach as crims post stolen data for sale

https://security-tracker.debian.org/tracker/DSA-6094-1

Fake Windows BSODs check in at Europe’s hotels to con staff into running malware
Crypto wallet shop Ledger confirms customer data lifted in Global-e snafu
Open WebUI bug turns the ‘free model’ into an enterprise backdoor
Students bag extended Christmas break after cyber hit on school IT
UK injects just £210M into cyber plan to stop Whitehall getting pwnd
Generative AI and the future of databases
What drives your cloud security strategy?
Coinbase insider who sold customer data to criminals arrested in India

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

An update that solves eight vulnerabilities and has one security fix can now be installed.

One criminal, 50 hacked organizations, and all because MFA wasn’t turned on

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

C# wins Tiobe Programming Language of the Year honors for 2025

https://security-tracker.debian.org/tracker/DSA-6093-1

Congrats, cybercrims: You just fell into a honeypot

An update that solves 70 vulnerabilities can now be installed.

An update that solves one vulnerability can now be installed.

Moderate: postgresql:15 security update

Playing Koi: Palo Alto isn’t saying if it will buy security start-up
Gmail preparing to drop POP3 mail fetching
New Zealand orders review into ManageMyHealth cyberattack
6 incredibly hyped software trends that failed to deliver
How to make AI agents reliable

A vulnerability was found in Curl, an easy-to-use client-side URL transfer library and command line tool. It can cause a crash or potentially a memory out of bounds read. For Debian 11 bullseye, this problem has been fixed in version 7.74.0-1.3+deb11u16.

Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed XCF, JPEG 2000 or PNM files are opened. For the oldstable distribution (bookworm), these problems have been fixed

Trump admin sends heart emoji to commercial spyware makers with lifted Predator sanctions
Palo Alto Networks security-intel boss calls AI agents 2026’s biggest insider threat

Update to 1.148.0

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).

Changes with nginx 1.28.1 23 Dec 2025 *) Security: processing of a specially crafted login/password when using the “none” authentication method in the ngx_mail_smtp_module might cause worker process memory disclosure to the authentication server (CVE-2025-53859).