Security News > 2025 > February

Spain arrests suspected hacker of US and Spanish military agencies
2025-02-05 15:37

The Spanish police have arrested a suspected hacker in Alicante for allegedly conducting 40 cyberattacks targeting critical public and private organizations, including the Guardia Civil, the...

How attackers abuse S3 Bucket Namesquatting — And How to Stop Them
2025-02-05 15:00

AWS S3 bucket names are global with predictable names that can be exploited in "S3 bucket namesquatting" attacks to access or hijack S3 buckets. In this article, Varonis explains how these attacks...

#S3
Cross-Platform JavaScript Stealer Targets Crypto Wallets in New Lazarus Group Campaign
2025-02-05 14:55

The North Korea-linked Lazarus Group has been linked to an active campaign that leverages fake LinkedIn job offers in the cryptocurrency and travel sectors to deliver malware capable of infecting...

Swap EOL Zyxel routers, upgrade Netgear ones!
2025-02-05 14:11

There will be no patches for EOL Zyxel routers under attack via CVE-2024-40891, the company has confirmed. Meanwhile, Netgear has issued patches for critical flaws affecting its routers and...

US cranks up espionage charges against ex-Googler accused of trade secrets heist
2025-02-05 13:33

Mountain View clocked onto the scheme with days to spare A Chinese national faces a substantial stint in prison and heavy fines if found guilty of several additional charges related to economic...

Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts
2025-02-05 13:03

Cybercriminals are increasingly leveraging legitimate HTTP client tools to facilitate account takeover (ATO) attacks on Microsoft 365 environments. Enterprise security company Proofpoint said it...

How to Add Fingerprint Authentication to Your Windows 11 Computer
2025-02-05 13:00

You can easily add a fingerprint reader to your computer if one isn't already built in.

Silent Lynx Using PowerShell, Golang, and C++ Loaders in Multi-Stage Cyberattacks
2025-02-05 12:46

A previously undocumented threat actor known as Silent Lynx has been linked to cyber attacks targeting various entities in Kyrgyzstan and Turkmenistan. "This threat group has previously targeted...

New Veeam Flaw Allows Arbitrary Code Execution via Man-in-the-Middle Attack
2025-02-05 12:16

Veeam has released patches to address a critical security flaw impacting its Backup software that could allow an attacker to execute arbitrary code on susceptible systems. The vulnerability,...

On Generative AI Security
2025-02-05 12:03

Microsoft’s AI Red Team just published “Lessons from Red Teaming 100 Generative AI Products.” Their blog post lists “three takeaways,” but the eight lessons in the report itself are more useful:...