Menu

Latest articles

New to Rust? Don’t make these common mistakes
Naming is easy! A guide for developers
Ukraine war spurred infosec vet Mikko Hyppönen to pivot to drones
‘Deliberate attack’ deletes shopping app’s AWS and GitHub resources

https://security-tracker.debian.org/tracker/DSA-5935-1

Meta pauses mobile port tracking tech on Android after researchers cry foul
Kotlin cozies up to Spring Framework
You say Cozy Bear, I say Midnight Blizzard, Voodoo Bear, APT29 …

https://security-tracker.debian.org/tracker/DSA-5934-1

Snowflake acquires Crunchy Data for enterprise-grade PostgreSQL to counter Databricks’ Neon buy
Google quietly pushes emergency fix for Chrome 0-day as exploit runs wild
Snowflake takes aim at legacy data workloads with SnowConvert AI migration tools
X’s new ‘encrypted’ XChat feature seems no more secure than the failure that came before it

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to “*.example.com”, a request to “[::1%25.example.com]:80` will incorrectly match and not be proxied – CVE-2025-22870.

Crooks fleece The North Face accounts with recycled logins
Don’t let dormant accounts become a doorway for cybercriminals

Do you have online accounts you haven’t used in years? If so, a bit of digital spring cleaning might be in order.

C# 14 introduces file-based apps
Snowflake’s Cortex AISQL aims to simplify unstructured data analysis

Several security issues were fixed in the Linux kernel.

Microsoft patches the patch that put Windows 11 in a coma
Snowflake launches Openflow to tackle AI-era data ingestion challenges
The Hidden Security Risks of Open-Source AI
Illicit crypto-miners pouncing on lazy DevOps configs that leave clouds vulnerable

Open VM Tools could be made to overwrite files as the administrator.

The high cost of misconfigured DevOps: Global cryptojacking hits enterprises
Bling slinger Cartier tells customers to be wary of phishing attacks after intrusion
Real-time analytics with StarTree Cloud and Apache Pinot
3 cloud migration secrets

Several security issues were fixed in MariaDB.

The month of June is a time for fun in the sun and a break from the school year, but did you know it’s also the perfect time to step up your family’s online security? June is Internet Safety Month, a yearly reminder to strengthen your defenses against online threats. In today’s hyper-connected world, we […]

Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Various other fixes

Two security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2025-47779

Ukrainians smuggle drones hidden in cabins on trucks to strike Russian airfields
Download the ‘New Thinking about Cloud Computing’ Enterprise Spotlight

* bsc#1214960 * bsc#1230092 Cross-References: * CVE-2024-45310

* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

* bsc#1215199 * bsc#1223809 * bsc#1224013 * bsc#1224597 * bsc#1224757

* bsc#1231284 Cross-References: * CVE-2024-8508

* bsc#1237367 * bsc#1239185 * bsc#1239322 * bsc#1239765 * jsc#PED-12534

* bsc#1234128 * bsc#1234665 * bsc#1239883 * bsc#1243317

US community bank says thieves drained customer data through third party hole
Google’s AI Edge Gallery will let developers deploy offline AI models — here’s how it works
7 ways to improve your AI coding results
Demystifying serverless in the modern data and AI landscape
Private cloud still matters—but it doesn’t matter most
Lumma infostealer takedown may have inflicted only a flesh wound as crew keeps pinching and selling data
This month in security with Tony Anscombe – May 2025 edition

From a flurry of attacks targeting UK retailers to campaigns corralling end-of-life routers into botnets, it’s a wrap on another month filled with impactful cybersecurity news

Unlock sensitive data for AI with Cloudera on Red Hat OpenShift

twitter-bootstrap3 a popular front end framework was affected by a vulnerability. A cross-site scripting (XSS) vulnerability

A vulnerability has been found in kitty, a fast, featureful, GPU based terminal emulator, which possible allows arbitrary code execution. CVE-2022-41322

Update to 128.11.0 https://www.thunderbird.net/en-US/thunderbird/128.11.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-46/

Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Fixes for systemd itself, run0, systemd-networkd, “secure” pager, man pages, shell completions, sd-boot, sd-varlink Hardware database update

https://security-tracker.debian.org/tracker/DSA-5933-1

Multiple stack-based buffer overflows have been fixed in the net-tools network utilities. For Debian 11 bullseye, this problem has been fixed in version

Double free on init failure has been fixed in libvpx, a library for decoding and encoding VP8 and VP9 videos. For Debian 11 bullseye, this problem has been fixed in version

Damascened Peacock: Russian hackers targeted UK Ministry of Defence
Mysterious leaker GangExposed outs Conti kingpins in massive ransomware data dump

Several issues have been found in espeak-ng, a Multi-lingual software speech synthesizer. The issues are related to buffer overflow or underflow in several

Buffer underflow on glib through glib/gstring.c via function g_string_insert_unichar. (CVE-2025-4373) References: – https://bugs.mageia.org/show_bug.cgi?id=34310

Heap buffer under-read in gnu coreutils sort via key specification. (CVE-2025-5278) References: – https://bugs.mageia.org/show_bug.cgi?id=34313

Multiple security issues were discovered in Flask-CORS, a Flask extension for handling Cross Origin Resource Sharing (CORS). CVE-2024-1681

New upstream version (139.0)

This update contains the backported fix for CVE-2024-52804 (cookie parsing DoS vuln).

CheerpJ WebAssembly JVM previews Java 17 support

https://security-tracker.debian.org/tracker/DSA-5931-1

https://security-tracker.debian.org/tracker/DSA-5930-1

MariaDB’s acquisition of Codership: Why enterprises should care
ConnectWise customers get mysterious warning about ‘sophisticated’ nation-state hack
Feds arrest DoD techie, claim he dumped top secret files in park for foreign spies to find
US medical org pays $50M+ to settle case after crims raided data and threatened to swat cancer patients
Teradata partners with Fivetran to assist data centralization in VantageCloud
Meta – yep, Facebook Meta – is now a defense contractor
Angular v20 arrives with eyes on generative AI development

Apport could be made to leak sensitive information.

* bsc#1243353 Cross-References: * CVE-2025-5263 * CVE-2025-5264

* bsc#1241274 * bsc#1241275 * bsc#1241276 * bsc#1242208 * bsc#1243429

* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268

* bsc#1242931 Cross-References: * CVE-2025-4207

AWS’ Serverless MCP Server to aid agentic development of managed applications
Crims defeat human intelligence with fake AI installers they poison with ransomware

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure. For Debian 11 bullseye, these problems have been fixed in version

Data watchdog put cops on naughty step for lost CCTV footage
F-strings with superpowers: What’s new in Python 3.14 beta
A wake-up call for real cloud ROI
The UK wants you to sign up for £1B cyber defense force
Interlock ransomware: what you need to know
Infosecurity Europe 2025 drives cybersecurity priorities amid growing global risks
Security outfit SentinelOne’s services back online after lengthy outage
Feds gut host behind pig butchering scams that bilked $200M from Americans

https://security-tracker.debian.org/tracker/DSA-5932-1

Microsoft’s May Patch Tuesday update fails on some Windows 11 VMs

https://security-tracker.debian.org/tracker/DSA-5923-2

https://security-tracker.debian.org/tracker/DSA-5928-1

Why is China deep in US networks? ‘They’re preparing for war,’ HR McMaster tells lawmakers
Unlocking data’s true potential: The open lakehouse as AI’s foundation
8,000+ Asus routers popped in ‘advanced’ mystery botnet plot
Google Cloud’s BigLake-driven lakehouse updates aim to optimize performance, costs

* bsc#1242008 * bsc#1242009 Cross-References: * CVE-2025-31650

* bsc#1236217 * bsc#1242715 Cross-References: * CVE-2025-22873

* bsc#1241658 * bsc#1241659 Cross-References: * CVE-2025-43965