Security News > 2025 > January

Zscaler CISO on balancing security and user convenience in hybrid work environments
2025-01-30 05:30

In this Help Net Security interview, Sean Cordero, CISO at Zscaler, talks about securing hybrid work and the new challenges it presents to cybersecurity teams. He discusses how hybrid work has...

ExtensionHound: Open-source tool for Chrome extension DNS forensics
2025-01-30 05:00

Traditional monitoring tools reveal only traffic from the Chrome process, leaving security teams uncertain about which extension is responsible for a suspicious DNS query. ExtensionHound solves...

89% of AI-powered APIs rely on insecure authentication mechanisms
2025-01-30 04:30

APIs have emerged as the predominant attack surface over the past year, with AI being the biggest driver of API security risks, according to Wallarm. “Based on our findings, what is clear is that...

How to use Hide My Email to protect your inbox from spam
2025-01-30 04:00

Hide My Email is a service that comes with iCloud+, Apple’s subscription-based service. It allows users to generate one-time-use or reusable email addresses that forward messages to their personal...

Wacom says crooks probably swiped customer credit cards from its online checkout
2025-01-30 01:11

Digital canvas slinger indicates dot-com was skimmed for over a month Graphics tablet maker Wacom has warned customers their credit card details may well have been stolen by miscreants while they...

New Aquabotv3 botnet malware targets Mitel command injection flaw
2025-01-30 00:55

A new variant of the Mirai-based botnet malware Aquabot has been observed actively exploiting CVE-2024-41710, a command injection vulnerability in Mitel SIP phones. [...]

Solana Pump.fun tool DogWifTool compromised to drain wallets
2025-01-30 00:33

DogWifTools has disclosed on its official Discord channel that its software has been compromised by a supply chain attack that impacted its Windows client, infecting users with malware. [...]

Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek
2025-01-30 00:31

Oh someone's in DeepShi... China-based AI biz DeepSeek may have developed competitive, cost-efficient generative models, but its cybersecurity chops are another story.…

North Koreans clone open source projects to plant backdoors, steal credentials
2025-01-29 23:29

Stealing crypto is so 2024. Supply-chain attacks leading to data exfil pays off better? North Korea's Lazarus Group compromised hundreds of victims across the globe in a massive secret-stealing...

DeepSeek Chatbot Beats OpenAI on App Store Leaderboard
2025-01-29 22:20

The Chinese firm said training the model cost just $5.6 million. Alibaba Cloud followed with a new generative AI model, while Microsoft alleges DeepSeek ‘distilled’ OpenAI’s work.