Security News > 2025 > January

SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix
2025-01-23 16:36

Big organizations and governments are main users of these gateways SonicWall is warning customers of a critical vulnerability that was potentially already exploited as a zero-day.…

SonicWall warns of SMA1000 RCE flaw exploited in zero-day attacks
2025-01-23 15:45

SonicWall is warning about a pre-authentication deserialization vulnerability in SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), with reports that it has...

Meta's pay-or-consent model under fire from EU consumer group
2025-01-23 15:30

Company 'strongly disagrees' with law infringement allegations Meta has again come under fire for its pay-or-consent model in the EU.…

#EU
Stealthy 'Magic Packet' malware targets Juniper VPN gateways
2025-01-23 15:26

A malicious campaign has been specifically targeting Juniper edge devices, many acting as VPN gateways, with malware dubbed J-magic that starts a reverse shell only if it detects a "magic packet"...

Tesla EV charger hacked twice on second day of Pwn2Own Tokyo
2025-01-23 15:24

​Security researchers hacked Tesla's Wall Connector electric vehicle charger twice on the second day of the Pwn2Own Automotive 2025 hacking contest. [...]

Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits
2025-01-23 15:13

An exhaustive evaluation of three firewall models from Palo Alto Networks has uncovered a host of known security flaws impacting the devices' firmware as well as misconfigured security features....

Beware: Fake CAPTCHA Campaign Spreads Lumma Stealer in Multi-Industry Attacks
2025-01-23 15:00

Cybersecurity researchers are calling attention to a new malware campaign that leverages fake CAPTCHA verification checks to deliver the infamous Lumma information stealer. "The campaign is...

Third Interdisciplinary Workshop on Reimagining Democracy (IWORD 2024)
2025-01-23 14:58

Last month, Henry Farrell and I convened the Third Interdisciplinary Workshop on Reimagining Democracy (IWORD 2024) at Johns Hopkins University’s Bloomberg Center in Washington DC. This is a...

New Research: The State of Web Exposure 2025
2025-01-23 14:56

Are your websites leaking sensitive data? New research reveals that 45% of third-party apps access user info without proper authorization, and 53% of risk exposures in Retail are due to the...

Custom Backdoor Exploiting Magic Packet Vulnerability in Juniper Routers
2025-01-23 14:55

Enterprise-grade Juniper Networks routers have become the target of a custom backdoor as part of a campaign dubbed J-magic. According to the Black Lotus Labs team at Lumen Technologies, the...