Collected every two hours from specialised publications — each link leads to the original article.
Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities.According to OX Securit…
An update that solves one vulnerability can now be installed.
A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent, according to new …
0.9.31
An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.
An update that solves two vulnerabilities and contains one feature can now be installed.
Update to 1.11.0 upstream release Resolves: rhbz#2413614
Rebuilt for CVE-2025-47906
Update to 1.1.97
Rebuild for CVEs
Rebuilt for CVE-2025-61723
Rebuilt for CVE-2025-58185
Rebuilt for CVE-2025-61723
Update logrus for https://access.redhat.com/security/cve/cve-2025-65637
Rebuild with the latest golang in repos
Rebuild with the latest golang in repos
Chinese-speaking users are the target of a search engine optimization (SEO) poisoning campaign that uses fake software sites to distribute malware."The attacke…
The maintainers of the nx build system have alerted users to a supply chain attack that allowed attackers to publish malicious versions of the popular npm pack…
North Korean threat actors have been attributed to a coordinated cyber espionage campaign targeting diplomatic missions in their southern counterpart between M…
A new multi-stage malware campaign is targeting Minecraft users with a Java-based malware that employs a distribution-as-service (DaaS) offering called Stargaz…
* bsc#1236516 * bsc#1238686 * jsc#MSQA-992 Cross-References:
updates dependencies to close security loophole
The following vulnerability has been discovered in the gorilla/csrf package for Go: Prior to 1.7.3, gorilla/csrf did not validate the Origin header against an …