news
Security Leftovers
-
Security Week ☛ Critical Apache Tika Vulnerability Leads to XXE Injection
The bug allows attackers to carry out XML External Entity (XXE) injection attacks via crafted XFA files inside PDF files.
-
LWN ☛ Security updates for Monday
Security updates have been issued by Debian (ffmpeg, krita, lasso, and libpng1.6), Fedora (abrt, cef, chromium, tinygltf, webkitgtk, and xkbcomp), Oracle (buildah, delve and golang, expat, python-kdcproxy, qt6-qtquick3d, qt6-qtsvg, sssd, thunderbird, and valkey), Red Hat (webkit2gtk3), and SUSE (git-bug, go1, and libpng12-0).
-
Security Week ☛ Exploitation of React2Shell Surges
An increasing number of threat actors have been attempting to exploit the React vulnerability CVE-2025-55182 in their attacks.
-
Security Week ☛ Ransomware Payments Surpassed $4.5 Billion: US Treasury
Ransomware payments reached the highest level in 2023, at $1.1 billion paid in 1,512 reported incidents.
-
Hardening the Backbone: Strengthening Linux Server Security with Preemptive Defense
Linux has long been the backbone of the modern enterprise.
From web applications and databases to cloud infrastructure, Linux servers power mission-critical workloads that keep businesses running. But as attackers sharpen their focus on these systems, it’s clear that the old assumption—Linux is inherently secure—no longer holds true.