Security News > 2025 > February

Only 3% of organizations have a dedicated budget for SaaS security
2025-02-03 04:30

Mid-market organizations are grappling with managing the large volume of SaaS applications, both sanctioned and unsanctioned, with actual numbers often exceeding expectations, according to Cloud...

How to use iCloud Private Relay for enhanced privacy
2025-02-03 04:00

iCloud Private Relay, included with an iCloud+ subscription, enhances your privacy while browsing the web in Safari. When this feature is enabled, the traffic leaving your iPhone is encrypted and...

Medical monitoring machines spotted stealing patient data, users warned to pull the plug ASAP
2025-02-03 02:02

PLUS: MGM settles breach suits; AWS doesn't trust you with security defaults; A new .NET backdoor; and more Infosec in brief The United States Food and Drug Administration has told medical...

What does it mean to build in security from the ground up?
2025-02-02 17:26

As if secure design is the only bullet point in a list of software engineering best practices Systems Approach As my Systems Approach co-author Bruce Davie and I think through what it means to...

PyPI adds project archiving system to stop malicious updates
2025-02-02 15:32

The Python Package Index (PyPI) has announced the introduction of 'Project Archival,' a new system that allows publishers to archive their projects, indicating to the users that no updates are to...

Gilmore Girls fans nabbed as Eurocops dismantle two major cybercrime forums
2025-02-02 13:19

Nulled and Cracked had a Lorelai-cal rise - until Operation Talent stepped in Law enforcement officers across Europe assembled again to collectively disrupt major facilitators of cybercrime, with...

Week in review: Apple 0-day used to target iPhones, DeepSeek’s popularity exploited by scammers
2025-02-02 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Apple zero-day vulnerability exploited to target iPhone users (CVE-2025-24085) Apple has shipped a...

Google says hackers abuse Gemini AI to empower their attacks
2025-02-01 17:14

Multiple state-sponsored groups are experimenting with the AI-powered Gemini assistant from Google to increase productivity and to conduct research on potential infrastructure for attacks or for...

U.S. and Dutch Authorities Dismantle 39 Domains Linked to BEC Fraud Network
2025-02-01 08:14

U.S. and Dutch law enforcement agencies have announced that they have dismantled 39 domains and their associated servers as part of efforts to disrupt a network of online marketplaces originating...

BeyondTrust Zero-Day Breach Exposed 17 SaaS Customers via Compromised API Key
2025-02-01 06:40

BeyondTrust has revealed it completed an investigation into a recent cybersecurity incident that targeted some of the company's Remote Support SaaS instances by making use of a compromised API...