Menu

Latest articles

As humanoid robots enter the mainstream, security pros flag the risk of botnets on legs
AWS is still chasing a cohesive enterprise AI story after re:Invent

Several security issues were fixed in radare2.

* bsc#1241772 * bsc#1250683 * bsc#1253181 * bsc#1253185 * bsc#1253186

UK to Europe: The time to counter Russia’s information war machine is now

python-apt could be made to crash if it opened a specially crafted file.

UK finally vows to look at 35-year-old Computer Misuse Act
Whitehall rejects £1.8B digital ID price tag – but won’t say what it will cost
Amazon Q Developer: Everything you need to know
The hidden cost of Amazon Nova 2

* bsc#1254132 Cross-References: * CVE-2025-9820

An update that solves one vulnerability can now be installed.

* bsc#1250497 Cross-References: * CVE-2025-10922

Researchers spot 700 percent increase in hypervisor ransomware attacks
IBM to buy Confluent to extend its data and automation portfolio

https://security-tracker.debian.org/tracker/DSA-6074-1

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), this problem has been fixed in version 7:7.1.3-0+deb13u1.

AWS takes aim at the PoC-to-production gap holding back enterprise AI
193 cybercrims arrested, accused of plotting ‘violence-as-a-service’
UK moves to strengthen undersea cable defenses as Russian snooping ramps up
Home Office kept police facial recognition flaws to itself, UK data watchdog fumes
Barts Health seeks High Court block after Clop pillages NHS trust data
10 MCP servers for devops
AI memory is really a database problem
Block all AI browsers for the foreseeable future: Gartner
China’s first reusable rocket explodes, but its onboard Ethernet network flew
Apache warns of 10.0-rated flaw in Tika metadata ingestion tool

Multiple vulnerabilties have been found in libpng, the official PNG reference library, allowing information disclosure via out-of-bounds read, denial of service via application crash, or heap corruption with potential for arbitrary code execution.

Update to 2.9.7

Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287

Update to 2.9.7

https://security-tracker.debian.org/tracker/DSA-6073-1

Solving tool overload, one automation step at a time
Red Hat OpenShift sandboxed containers 1.11 and Red Hat build of Trustee 1.0 accelerate confidential computing across the hybrid cloud
CIS publishes hardening guidance for Red Hat OpenShift Virtualization
AI ambitions meet automation reality: The case for a unified automation platform
From vision to reality: A 5-step playbook for unified automation and AI
Death to one-time text codes: Passkeys are the new hotness in MFA

Loading a manipulated TGA file in krita, an image manipulation program, could result in a heap-based buffer overflow in KisTgaImport.

Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials

Fix CVE-2025-12744

Update to cef-142.0.17+g60aac24 & chromium 142.0.7444.175 (rhbz#2413981) High CVE-2025-13223: Type Confusion in V8 High CVE-2025-13224: Type Confusion in V8

Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials

Fix CVE-2025-12744

Crims using social media images, videos in ‘virtual kidnapping’ scams
Novel clickjacking attack relies on CSS and SVG
Cloudflare blames Friday outage on borked fix for React2shell vuln

https://security-tracker.debian.org/tracker/DSA-6072-1

https://security-tracker.debian.org/tracker/DSA-6071-1

Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture

Identity is effectively the new network boundary. It must be protected at all costs.

Asus supplier hit by ransomware attack as gang flaunts alleged 1 TB haul
Beijing-linked hackers are hammering max-severity React bug, AWS warns
AI in CI/CD pipelines can be tricked into behaving badly
UK pushes ahead with facial recognition expansion despite civil liberties backlash

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Bots, bias, and bunk: How can you tell what’s real on the net?
All I want for Christmas is a server-side JavaScript framework
Local clouds shape Europe’s AI future
Secure Boot: Strengthening Linux System Integrity from the Firmware Up

Update to security release 4.3.5a

Rebuilt with latest patched stb_image: memory-safety fixes

An AI for an AI: Anthropic says AI agents require AI defense
PRC spies Brickstormed their way into critical US networks and remained hidden for years
Hegseth needs to go to secure messaging school, report says

https://security-tracker.debian.org/tracker/DSA-6069-1

Twins who hacked State Dept hired to work for gov again, now charged with deleting databases
‘Futuristic’ Unison functional language debuts
Why the record-breaking 30 Tbps DDoS attack should concern every business
OpenAI to acquire AI training tracker Neptune
Microsoft quietly shuts down Windows shortcut flaw after years of espionage abuse
FBI warns of surge in account takeover (ATO) fraud schemes – what you need to know
Aisuru botnet turns Q3 into a terabit-scale stress test for the entire internet

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

A proactive defense against npm supply chain attacks
Spring AI tutorial: Get started with Spring AI
The first building blocks of an agentic Windows OS

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43392

TLS 1.3 includes welcome improvements, but still allows long-lived secrets
Rust core library partly polished for industrial safety spec

Rebuilt with stb_image patched for two new security bugs.

Patch two newly-reported memory-safety bugs in stb_image: https://github.com/nothings/stb/issues/1860 https://github.com/nothings/stb/issues/1861

Microsoft steers native port of TypeScript to early 2026 release
Smashing Security podcast #446: A hacker doxxes himself, and social engineering-as-a-service
Developers urged to immediately upgrade React, Next.js

https://security-tracker.debian.org/tracker/DSA-6070-1

‘Exploitation is imminent’ as 39 percent of cloud environs have max-severity React hole

https://security-tracker.debian.org/tracker/DSA-6068-1

https://security-tracker.debian.org/tracker/DSA-6067-1

MuddyWater: Snakes by the riverbank

MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook

Mistral targets lightweight processors with its biggest open model yet
AWS introduces powers for AI-powered Kiro IDE
AWS offers new service to make AI models better at work

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

KDE Connect could allow authentication of impersonated devices.