Menu

Latest articles

‘Exploitation is imminent’ as 39 percent of cloud environs have max-severity React hole

https://security-tracker.debian.org/tracker/DSA-6068-1

https://security-tracker.debian.org/tracker/DSA-6067-1

MuddyWater: Snakes by the riverbank

MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook

Mistral targets lightweight processors with its biggest open model yet
AWS introduces powers for AI-powered Kiro IDE
AWS offers new service to make AI models better at work

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

KDE Connect could allow authentication of impersonated devices.

Frequently asked questions about Red Hat Ansible Automation Platform 2.6
Confidential computing on AWS Nitro Enclave with Red Hat Enterprise Linux
Tracking event-driven automation with Red Hat Lightspeed and Red Hat Ansible Automation Platform 2.6
9 strategic articles defining the open hybrid cloud and AI future
Integrating Red Hat Lightspeed in 2025: From observability to actionable automation
Automation unleashed: Introducing the new Red Hat Certified Ansible Collection amazon.ai for generative AI

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The complete guide to Node.js frameworks
A first look at Google’s new Antigravity IDE
Seven coding domains no developer really understands
Here’s your worst nightmare: E-tailer can only resume partial sales 45 days after ransomware attack
Indian government reveals GPS spoofing at eight major airports
Get poetic in prompts and AI will break its guardrails
The AI Fix #79: Gemini 3, poetry jailbreaks, and do we even need safe robots?
AWS Transform now supports agentic modernization of custom code
Two Android 0-day bugs disclosed and fixed, plus 105 more to patch
Asahi cyber attack spirals into massive data breach impacting almost 2 million people
University of Pennsylvania joins list of victims from Clop’s Oracle EBS raid
Oversharing is not caring: What’s at stake if your employees post too much online

From LinkedIn to X, GitHub to Instagram, there are plenty of opportunities to share work-related information. But posting could also get your company into trouble.

AWS unveils Frontier AI agents for software development
Europol nukes Cryptomixer laundering hub, seizing €25M in Bitcoin
Kensington and Chelsea confirms IT outage was a data breach after all
FTC schools edtech outfit after intruder walked off with 10M student records
Why data contracts need Apache Kafka and Apache Flink
How to ensure your enterprise data is ‘AI ready’
The ripple effects of a VPN ban
Out-of-Bounds Read Bugs Add Quiet Pressure on Linux Security
India demands smartphone makers install a government app on every handset

Several security issues were fixed in CRaC JDK 17.

Several security issues were fixed in CRaC JDK 25.

Several security issues were fixed in CRaC JDK 21.

update to version 2.25.2

Update to 1.24.2 (rhbz#2417261) Additional fix for CVE-2025-11411 https://nlnetlabs.nl/projects/unbound/download/#unbound-1-24-2

Prevent unsafe URI schemes from participating in media playback. Make jsc_value_array_buffer_get_data() function introspectable. Fix logging in to Google accounts that have a WebAuthn second factor configured. Fix loading webkit://gpu when there are no threads configured for GPU rendering. Fix rendering gradients that use the CSS hue interpolation method.

Qdrant vector database adds tiered multitenancy
Stealthy browser extensions waited years before infecting 4.3M Chrome, Edge users with backdoors and spyware
Four arrested in South Korea over massive IP camera snooping spree
Contagious Interview attackers go ‘full stack’ to fool you
Dutch study finds teen cybercrime is mostly just a phase
South Korea’s answer to Amazon admits breach exposed 33.7M customers
French Football Federation faces own-goal after club software data breach
How to succeed as an independent software developer
How much will openness matter to AI?

A local file inclusion vulnerability has been discovered in mistral- dashboard, the OpenStack Workflow as a Service dashboard plugin, that may result in disclosure of arbitrary local files content through the

A local file inclusion vulnerability has been discovered in python- mistralclient, the OpenStack Workflow as a Service client, that may result in disclosure of arbitrary local files content through the

Google and Apple ordered to stop fake government TXTs

Multiple vulnerabilities have been discovered in Pagure, a Git-centered code hosting system (forge).

A possible remote code execution (RCE) vulnerability has been discovered in pytorch, an open source machine learning framework.

Update to pgadmin-9.10

Update to 2.86.2 Fix CVE-2025-13601 or #YWH-PGM9867-134

Swiss government says give M365, and all SaaS, a miss as it lacks end-to-end encryption

Version 0.18.1 Security Fixed critical issue where PKESK (public-key encrypted) session keys were generated as all-zero, allowing trivial decryption of messages encrypted with public keys only (CVE-2025-13402)

An update that solves 2 vulnerabilities can now be installed.

An update that solves 2 vulnerabilities can now be installed.

An update that solves 9 vulnerabilities can now be installed.

Update to 20251125: Revert “amdgpu: update GC 11.0.1 firmware” QCA: Add Bluetooth firmware for WCN685x uart interface qcom: Add ADSP firmware for qcs6490-thundercomm-rubikpi3 qcom: venus-5.4: update firmware binary for v5.4

Update to 4.19.0 Address CVEs by rebuilding with Go 1.24.10

https://security-tracker.debian.org/tracker/DSA-6066-1

* bsc#1253757 Cross-References: * CVE-2025-11563

* bsc#1245953 * bsc#1252930 * bsc#1252931 * bsc#1252932 * bsc#1252933

This month in security with Tony Anscombe – November 2025 edition

Data exposure by top AI companies, the Akira ransomware haul, Operation Endgame against major malware families, and more of this month’s cybersecurity news

Comprehending Fingerprinting Risks Faced by Linux Users Today

A race condition was discovered in Qt, a cross-platform C++ application framework. Code to make security-relevant decisions about an established HTTP2 connection may execute too early, because the encrypted() signal has not yet been emitted and processed.

What Is a Side-Channel Attack? A Linux Security Overview

* bsc#1249537 Cross-References: * CVE-2025-38616

New libxslt packages are available for Slackware 15.0 and -current to fix security issues.

Several security vulnerabilities were discovered in the server of the Tryton application platform, which could lead to information disclosure. For Debian 11 bullseye, these problems have been fixed in version

What parents should know to protect their children from doxxing

Online disagreements among young people can easily spiral out of control. Parents need to understand what’s at stake.

PostHog admits Shai-Hulud 2.0 was its biggest ever security bungle
The Ultimate Handbook for Linux Security Tools and Hardening Tips 2026
Brit telco Brsk confirms breach as bidding begins for 230K+ customer records
GrapheneOS bails on OVHcloud over France’s privacy stance

* bsc#1252110 * bsc#1252232 Cross-References: * CVE-2025-31133

* bsc#1215199 * bsc#1218644 * bsc#1230062 * bsc#1234634 * bsc#1234693

* bsc#1249191 * bsc#1249348 * bsc#1249367 * bsc#1253757

* bsc#1218644 * bsc#1238472 * bsc#1239206 * bsc#1241166 * bsc#1241637

* bsc#1253278 * bsc#1253642 * bsc#1253703 * jsc#PED-9265

* bsc#1252414 * bsc#1252417 * bsc#1252418 * jsc#PED-14233

TryHackMe races to add women to Christmas cyber challenge roster after backlash
AWS launches Flexible Training Plans for inference endpoints in SageMaker AI
Everything You Need to Know About Linux Proxy Servers (2026 Guide)
Full Disk Encryption: What It Is, How It Works, and Why It Matters for Linux Security in 2026
UNC2891 Hackers Use Linux Malware in Major Banking Security Heists
How Holiday Leave Exposes Linux Security Gaps in Docker and Kubernetes Environments
OBR drags in cyber bigwig after Budget leak blunder
UK digital ID plan gets a price tag at last – £1.8B
Spotlight: Making the most of multicloud
What is devops? Bringing dev and ops together to build better software