Security News > 2025 > January

Subaru Starlink flaw let hackers hijack cars in US and Canada
2025-01-24 17:35

Security researchers have discovered an arbitrary account takeover flaw in Subaru's Starlink service that could let attackers track, control, and hijack vehicles in the United States, Canada, and...

Hackers use Windows RID hijacking to create hidden admin account
2025-01-24 17:25

A North Korean threat group has been using a technique called RID hijacking that tricks Windows into treating a low-privileged account as one with administrator permissions. [...]

Hacker infects 18,000 "script kiddies" with fake malware builder
2025-01-24 16:34

A threat actor targeted low-skilled hackers, known as "script kiddies," with a fake malware builder that secretly infected them with a backdoor to steal data and take over computers. [...]

Microsoft: Outdated Exchange servers fail to auto-mitigate security bugs
2025-01-24 15:26

Microsoft says outdated Exchange servers cannot receive new emergency mitigation definitions because an Office Configuration Service certificate type is being deprecated. [...]

Don't want your Kubernetes Windows nodes hijacked? Patch this hole now
2025-01-24 15:00

SYSTEM-level command injection via API parameter *chef's kiss* A now-fixed command-injection bug in Kubernetes can be exploited by a remote attacker to gain code execution with SYSTEM privileges...

North Korean IT workers are extorting employers, FBI warns
2025-01-24 14:40

The FBI is on a mission to raise awareness about the threat that North Korean IT workers present to organizations in the US and around the world. While corporate espionage comes to mind first, the...

Managed Detection and Response – How are you monitoring?
2025-01-24 14:02

Security Information and Event Management (SIEM) systems are now a critical component of enterprise security. Learn more from Smarttech247 about how its VisionX + Splunk solution can help secure...

North Korean dev who renamed himself 'Bane' accused of IT worker fraud caper
2025-01-24 13:45

5 indicted as FBI warns North Korea dials up aggression, plus Russian devs allegedly get in on the act The US is indicting yet another five suspects it believes were involved in North Korea's...

Hackers get $886,250 for 49 zero-days at Pwn2Own Automotive 2025
2025-01-24 13:00

​The Pwn2Own Automotive 2025 hacking contest has ended with security researchers collecting $886,250 after exploiting 49 zero-days. [...]

RANsacked: Over 100 Security Flaws Found in LTE and 5G Network Implementations
2025-01-24 12:58

A group of academics has disclosed details of over 100 security vulnerabilities impacting LTE and 5G implementations that could be exploited by an attacker to disrupt access to service and even...