Remove 2025 Remove Libraries Remove Security
article thumbnail

Critical flaw in Apache Parquet’s Java Library allows remote code execution

Security Affairs

Experts warn of a critical vulnerability impacting Apache Parquet’s Java Library that could allow remote code execution. Apache Parquet’s Java Library is a software library for reading and writing Parquet files in the Java programming language. The researchers urge users to address the issue immediately.

Libraries 169
article thumbnail

Google fixed the first actively exploited Chrome zero-day since the start of the year

Security Affairs

Google has released out-of-band fixes to address a high-severity security vulnerability, tracked as CVE-2025-2783 , in Chrome browser for Windows. Kaspersky researchers Boris Larin (@oct0xor) and Igor Kuznetsov (@2igosha) reported the vulnerability on March 20, 2025. ” reads the advisory published by Google.

Libraries 291
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

GitLab addressed critical auth bypass flaws in CE and EE

Security Affairs

GitLab released security updates to address critical vulnerabilities in Community Edition (CE) and Enterprise Edition (EE). The company addressed nine vulnerabilities, including the two critical ruby-saml authentication bypass issues respectively tracked as CVE-2025-25291 and CVE-2025-25292. GitLab CE/EE versions 17.7.7,

article thumbnail

Critical Apache Roller flaw allows to retain unauthorized access even after a password change

Security Affairs

A critical flaw (CVE-2025-24859, CVSS 10) in Apache Roller lets attackers keep access even after password changes. A critical vulnerability, tracked as CVE-2025-24859 (CVSS score of 10.0), affects the Apache Roller open-source, Java-based blogging server software. All versions 6.1.4 are affected.

Passwords 138
article thumbnail

The Cyber Essentials Scheme’s 2025 Update and What it Means for Your Organisation

IT Governance

The Cyber Essentials scheme is updated each year to ensure its best-practice approach to basic cyber security remains relevant. So, whats new for 2025? Cyber Essentials and Cyber Essentials Plus: whats new in the 2025 update? As of 28 April 2025, new Cyber Essentials certifications will be assessed according to v3.2

IT 54
article thumbnail

Data Protection Conference 2025 - taking resposnsibility to keep data safe

CILIP

Data protection is all our responsibility: CILIP Data Protection Conference 2025 By Jess Pembroke, Director of Information Law Services at Naomi Korn Associates. The CILIP Data Protection Conference, on 21 May 2025, is an exciting new addition to the CILIP calendar.

article thumbnail

My Take: Is Amazon’s Alexa+ a Gutenberg moment — or a corporate rerun of history’s greatest co-opt?

The Last Watchdog

Last Friday morning, April 11, I was making my way home from NTT Researchs Upgrade 2025 innovation conference in San Francisco, when it struck me that were at a watershed moment. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be. What’s in the black box?