Menu

Latest articles

https://security-tracker.debian.org/tracker/DSA-5947-1

Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler

Harden temporary private mounts (#2373301)

4.9.0

This is the .NET monthly update for June 2025. Release Notes: SDK: https://github.com/dotnet/core/blob/main/release-notes/9.0/9.0.6/9.0.107.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.6/9.0.6.md

Fix improper access control vulnerability Resolves: CVE-2025-48734

https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/OXIGQIHBL26HFKG6TT5SWSH7K7W6RO4H/ https://phabricator.wikimedia.org/T382326

https://security-tracker.debian.org/tracker/DSA-5946-1

https://security-tracker.debian.org/tracker/DSA-5945-1

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Netflix, Apple, BofA websites hijacked with fake help-desk numbers
Looks like Aflac is the latest insurance giant snagged in Scattered Spider’s web
Qilin ransomware top dogs treat their minions to on-call lawyers for fierier negotiations
Krispy Kreme hack exposed sensitive data of over 160,000 people

* bsc#1241158 * bsc#1241160 * bsc#1243282 * bsc#1243286 * bsc#1243288

* bsc#1234449 Cross-References: * CVE-2024-47606

* bsc#1239192 Cross-References: * CVE-2025-22868

* bsc#1227690 Cross-References: * CVE-2024-38526

* bsc#1233012 * bsc#1243273 * bsc#1244401 Cross-References:

GitHub hit by a sophisticated malware campaign as ‘Banana Squad’ mimics popular repos
IBM combines governance and security tools to solve the AI agent oversight crisis
Attack on Oxford City Council exposes 21 years of election worker data
Qilin offers “Call a lawyer” button for affiliates attempting to extort ransoms from victims who won’t pay
Developers set the pace for genAI tools adoption
The hyperscalers disrupt the sovereign cloud disruptors

https://security-tracker.debian.org/tracker/DSA-5944-1

Boffins devise voice-altering tech to jam ‘vishing’ schemes
Uncle Sam seeks time in tower dump data grab case after judge calls it ‘unconstitutional’
Glazed and confused: Hole lotta highly sensitive data nicked from Krispy Kreme

It was discovered that an Out Of Memory error may occur when attempting to initialize a huge byte array, even when maxFrameSize is set. For Debian 11 bullseye, this problem has been fixed in version

* bsc#1234415 * bsc#1234450 * bsc#1234453 * bsc#1234455 * bsc#1234456

UK gov asks university boffins to pinpoint cyber growth areas where it should splash cash

Several security issues were fixed in Samba.

Updates to Red Hat Advanced Cluster Security for Kubernetes Cloud Service strengthen your security posture
Firecrawl: Easy web data extraction for AI applications
Taking advantage of Microsoft Edge’s built-in AI

Several security issues were fixed in Express.

* bsc#1238681 * bsc#1239192 Cross-References: * CVE-2025-22868

Sneaky Serpentine#Cloud slithers through Cloudflare tunnels to inject orgs with Python-based malware
Iran’s internet goes offline for hours amid claims of ‘enemy abuse’
Google previews Gemini 2.5 Flash-Lite
Parasoft C/C++test adds AI assistant
Smashing Security podcast #422: The curious case of the code copier
Minecraft cheaters never win … but they may get malware

https://security-tracker.debian.org/tracker/DSA-5943-1

Ransomware gang busted in Thailand hotel raid
Retail versus finance: How genAI coding strategies diverge
Asana’s cutting-edge AI feature ran into a little data leakage problem
Veeam patches third critical RCE bug in Backup & Replication in space of a year

* bsc#1154353 * bsc#1156395 * bsc#1170891 * bsc#1173139 * bsc#1184350

* bsc#1244039 Cross-References: * CVE-2024-47081

* bsc#1244039 Cross-References: * CVE-2024-47081

* bsc#1244039 Cross-References: * CVE-2024-47081

Get started with Python type hints
Better together: Developing web apps with Astro and Alpine
OpenAI’s o3 price plunge changes everything for vibe coders
How to bridge the MFA gap
Amazon CISO: Iranian hacking crews ‘on high alert’ since Israel attack
Trump administration set to waive TikTok sell-or-die deadline for a third time
AWS locks down cloud security, hits 100% MFA enforcement for root users
Sitecore CMS flaw let attackers brute-force ‘b’ for backdoor
The AI Fix #55: Atari beats ChatGPT at chess, and Apple says AI “thinking” is an illusion
Redefining identity security in the age of agentic AI

Ready, set, pack! Summer travel season is here and that means family road trips, beach vacations, international adventures and more. While summertime is prime time for getaways, did you know it’s also prime time for online fraud? Scammers are targeting the travel industry, putting millions of travelers at increased risk. Research shows that the travel […]

23andMe hit with £2.3M fine after exposing genetic data of millions
Malicious PyPI package targets Chimera users to steal AWS tokens, CI/CD secrets

* bsc#1223096 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

Secure RHEL Clones Chart Diverging Paths

Django could be made to log injection if received specially crafted input.

Amazon Bedrock faces revamp pressure amid rising enterprise demands
Design a better customer experience with agentic AI
A developer’s guide to AI protocols: MCP, A2A, and ACP
Navigating the rising costs of AI inferencing

Update to 128.11.1 https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/

Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags() Fixes CVE-2025-48432: Potential log injection via unescaped request path

Rebuild against idna 1.0+ for CVE-2024-12224

Rebuild for CVE-2024-12224, CVE-2025-4574

Java 25 to change Windows file operation behaviors
Scattered Spider has moved from retail to insurance
Remorseless extortionists claim to have stolen thousands of files from Freedman HealthCare
Canada’s WestJet says ‘expect interruptions’ online as it navigates cybersecurity turbulence
Eurocops arrest suspected Archetyp admin, shut down mega dark web drug shop
Salesforce study finds LLM agents flunk CRM and confidentiality tests
Microsoft adds export option to Windows Recall in Europe

* bsc#1215935 * bsc#1215936 * bsc#1233606 * bsc#1233608 * bsc#1233609

* bsc#1242015 Cross-References: * CVE-2025-3891

Databricks Data + AI Summit 2025: Five takeaways for data professionals, developers
Spy school dropout: GCHQ intern jailed for swiping classified data

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Rethinking the dividing lines between containers and VMs
Top 6 multicloud management solutions