Security News > 2025 > January

Six vulnerabilities in ubiquitous rsync tool announced and fixed in a day
2025-01-17 15:49

Turns out tool does both file transfers and security fixes fast Don't panic. Yes, there were a bunch of CVEs affecting potentially hundreds of thousands of users found in rsync in early December –...

How Russian hackers went after NGOs’ WhatsApp accounts
2025-01-17 15:26

Star Blizzard, a threat actor tied to the Russian Federal Security Service (FSB), was spotted attempting to compromise targets’ WhatsApp accounts through a clever phishing campaign. The campaign...

Microsoft starts force upgrading Windows 11 22H2, 23H3 devices
2025-01-17 14:55

​Microsoft has started the forced rollout of Windows 11 24H2 to eligible, non-managed systems running the Home and Pro editions of Windows 11 22H2 and 23H2. [...]

Critical Flaws in WGS-804HPT Switches Enable RCE and Network Exploitation
2025-01-17 14:08

Cybersecurity researchers have disclosed three security flaws in Planet Technology's WGS-804HPT industrial switches that could be chained to achieve pre-authentication remote code execution on...

Python-Based Bots Exploiting PHP Servers Fuel Gambling Platform Proliferation
2025-01-17 13:06

Cybersecurity researchers have exposed a new campaign that targets web servers running PHP-based applications to promote gambling platforms in Indonesia. "Over the past two months, a significant...

Social Engineering to Disable iMessage Protections
2025-01-17 12:05

I am always interested in new phishing tricks, and watching them spread across the ecosystem. A few days ago I started getting phishing SMS messages with a new twist. They were standard messages...

Medusa ransomware group claims attack on UK's Gateshead Council
2025-01-17 10:30

Pastes allegedly stolen documents on leak site with £600K demand Another year and yet another UK local authority has been pwned by a ransomware crew. This time it's Gateshead Council in North East...

How to Bring Zero Trust to Wi-Fi Security with a Cloud-based Captive Portal?
2025-01-17 10:21

Recent data breaches have highlighted the critical need to improve guest Wi-Fi infrastructure security in modern business environments. Organizations face increasing pressure to protect their...

U.S. Sanctions North Korean IT Worker Network Supporting WMD Programs
2025-01-17 10:07

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and four entities for their alleged involvement in illicit revenue generation schemes for the...

New 'Sneaky 2FA' Phishing Kit Targets Microsoft 365 Accounts with 2FA Code Bypass
2025-01-17 10:07

Cybersecurity researchers have detailed a new adversary-in-the-middle (AitM) phishing kit that's capable of Microsoft 365 accounts with an aim to steal credentials and two-factor authentication...