Security News > 2025 > February

Ransomware payments fell by 35% in 2024, totalling $813,550,000
2025-02-05 20:34

Payments to ransomware actors decreased 35% year-over-year in 2024, totaling $813.55 million, down from $1.25 billion recorded in 2023. [...]

DOGE latest: Citrix supremo has 'read-only' access to US Treasury payment system
2025-02-05 19:30

CEO of Cloud Software a 'special government employee' probing through IT for Elon Musk's DOGE The US Treasury has revealed Tom Krause – the chief exec of Citrix and Netscaler owner Cloud Software...

Musky minion granted 'read-only' access to federal payment systems
2025-02-05 19:30

Nothing to see here, just a 'special government employee' doing his job The US Treasury Department has assured Congress that a "special government employee" associated with Elon Musk's Department...

CISA orders agencies to patch Linux kernel bug exploited in attacks
2025-02-05 18:58

​CISA has ordered federal agencies to secure their systems within three weeks against a high-severity Linux kernel flaw actively exploited in attacks. [...]

Hackers spoof Microsoft ADFS login pages to steal credentials
2025-02-05 18:41

A help desk phishing campaign targets an organization's Microsoft Active Directory Federation Services (ADFS) using spoofed login pages to steal credentials and bypass multi-factor authentication...

AMD fixes bug that lets hackers load malicious microcode patches
2025-02-05 18:30

​AMD has released mitigation and firmware updates to address a high-severity vulnerability that can be exploited to load malicious CPU microcode on unpatched devices. [...]

CISA tags Microsoft .NET and Apache OFBiz bugs as exploited in attacks
2025-02-05 16:45

The US Cybersecurity & Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies and large organizations to apply...

21% of CISOs Have Been Pressured Not to Report a Compliance Issue, Research Finds
2025-02-05 16:44

CISOs face growing boardroom pressure, compliance challenges, and cyber threats. Discover key insights from Splunk’s latest report on cybersecurity leadership.

Cybercrime gang exploited VeraCore zero-day vulnerabilities for years (CVE-2025-25181, CVE-2024-57968)
2025-02-05 16:42

XE Group, a cybercriminal outfit that has been active for over a decade, has been quietly exploiting zero-day vulnerabilities (CVE-2025-25181, CVE-2024-57968) in VeraCore software, a popular...

Netgear fixes critical bugs as Five Eyes warn about break-ins at the edge
2025-02-05 16:27

International security squads all focus on stopping baddies busting in through routers, IoT kit etc Netgear is advising customers to upgrade their firmware after it patched two critical...