news
Security Patches and Breaches, Latest CISA Reports
-
LWN ☛ Security updates for Thursday
Security updates have been issued by AlmaLinux (gnutls, mysql:8.4, opentelemetry-collector, and python-cryptography), Debian (nextcloud-desktop), Fedora (chromium, firefox, forgejo, gitleaks, kernel, kernel-headers, lemonldap-ng, perl-Cpanel-JSON-XS, and python-pip), Red Hat (firefox and libxml2), Slackware (expat and mozilla), SUSE (avahi, bluez, cups, curl, firefox-esr, gdk-pixbuf, gstreamer, java-1_8_0-ibm, krb5, net-tools, podman, raptor, sevctl, tkimg, ucode-intel, and vim), and Ubuntu (linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp,
linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-fips, linux-azure-fips, linux-gcp-fips, and linux-gcp-6.14, linux-oracle, linux-oracle-6.14).
-
OpenSSF (Linux Foundation) ☛ Improving Risk Management Decisions with SBOM Data: A New Whitepaper from the OpenSSF SBOM Everywhere SIG
SBOMs are becoming part of everyday software practice, but many teams still ask the same question: how do we turn SBOM data into decisions we can trust? Our new whitepaper, “Improving Risk Management Decisions with SBOM Data,” answers that by tying SBOM information to concrete risk-management outcomes across engineering, security, legal, and operations.
-
Security Week ☛ Nearly 250,000 Impacted by Data Breach at Medical Associates of Brevard
The BianLian ransomware group took credit for the cyberattack on the healthcare organization in January 2025.
-
Security Week ☛ Tiffany Data Breach Impacts Thousands of Customers
The high-end jewelry retailer is informing customers in the United States and Canada that hackers accessed information related to gift cards.
-
Infostealer and ransomware on the rise in South Africa
More than 42 million web attacks and 95.6 million on-device attacks were detected in Sub-Saharan Africa in the first half of 2025.
-
Federal News Network ☛ More U.S. cyber offense could mean more risk for companies caught in the crossfire
"The majority of security and privacy incidents start with human error. It's not always a brute force attack on the system," said Brandon Robinson.
-
Security Week ☛ Insight Partners Confirms Data Breach Result of Ransomware Attack
Venture capital firm Insight Partners says the data breach disclosed in February 2025 impacts over 12,000 people.
-
Security Week ☛ SonicWall Prompts Password Resets After Hackers Obtain Firewall Configurations
The company sent a new preferences file to less than 5% of customers, urging them to import it into firewalls and reset their passwords.
-
Security Week ☛ Chrome 140 Update Patches Sixth Zero-Day of 2025
An exploited type confusion in the V8 JavaScript engine tracked as CVE-2025-10585 was found by Surveillance Giant Google Threat Analysis Group this week.
-
CISA
-
CISA ☛ 2025-09-16 [Older] CISA Releases Eight Industrial Control Systems Advisories
-
CISA ☛ 2025-09-16 [Older] Schneider Electric Altivar Products, ATVdPAC Module, ILC992 InterLink Converter
-
CISA ☛ 2025-09-16 [Older] Hitachi Energy RTU500 Series
-
CISA ☛ 2025-09-16 [Older] Siemens SIMATIC NET CP, SINEMA, and SCALANCE
-
CISA ☛ 2025-09-16 [Older] Siemens RUGGEDCOM, SINEC NMS, and SINEMA
-
CISA ☛ 2025-09-16 [Older] Siemens OpenSSL Vulnerability in Industrial Products
-
CISA ☛ 2025-09-16 [Older] Siemens Multiple Industrial Products
-
CISA ☛ 2025-09-16 [Older] Delta Electronics DIALink
-
CISA ☛ 2025-09-11 [Older] CISA Adds One Known Exploited Vulnerability to Catalog
-
CISA ☛ 2025-09-11 [Older] CISA Releases Eleven Industrial Control Systems Advisories
-
CISA ☛ 2025-09-11 [Older] Siemens SIMOTION Tools
-
CISA ☛ 2025-09-11 [Older] Siemens SIMATIC Virtualization as a Service (SIVaaS)
-
CISA ☛ 2025-09-11 [Older] Siemens SINAMICS Drives
-
CISA ☛ 2025-09-11 [Older] Siemens SINEC OS
-
CISA ☛ 2025-09-11 [Older] Siemens Apogee PXC and Talon TC Devices
-
CISA ☛ 2025-09-11 [Older] Siemens Industrial Edge Management OS (IEM-OS)
-
CISA ☛ 2025-09-11 [Older] Siemens User Management Component (UMC)
-
CISA ☛ 2025-09-11 [Older] Schneider Electric EcoStruxure
-
CISA ☛ 2025-09-11 [Older] Schneider Electric Modicon M340, BMXNOE0100, and BMXNOE0110
-
-
Windows TCO / Windows Bot Nets
-
Security Week ☛ Threat Actor Infests Hotels With New RAT
RevengeHotels has been targeting hotels in Brazil and Spanish-speaking regions with VenomRAT implants in 2025.
-
Tom's Hardware ☛ Shai-Hulud malware campaign dubbed 'the largest and most dangerous npm supply-chain compromise in history' — 'hundreds' of JavaScript packages affected [Ed: Microsoft transmits malware to people via NPM]
Security researchers are tracking a malware campaign that has compromised hundreds of packages distributed via the npm ecosystem.
-