Security News > 2025 > February

CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active Exploitation
2025-02-26 04:33

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday placed two security flaws impacting Microsoft Partner Center and Synacor Zimbra Collaboration Suite (ZCS) to its Known...

Incoming deputy boss of Homeland Security says America's top cyber-agency needs to be reined in
2025-02-26 02:31

Plus: New figurehead of DOGE emerges and they aren't called Elon During confirmation hearings in the US Senate Tuesday for the role of deputy director of the Dept of Homeland Security, the nominee...

Drug-screening biz DISA took a year to disclose security breach affecting millions
2025-02-26 00:05

If there's something nasty on your employment record, extortion scum could come calling DISA Global Solutions, a company that provides drug and alcohol testing, background checks, and other...

Have I Been Pwned adds 284M accounts stolen by infostealer malware
2025-02-25 22:07

​The Have I Been Pwned data breach notification service has added over 284 million accounts stolen by information stealer malware and found on a Telegram channel. [...]

Xi know what you did last summer: China was all up in Republicans' email, says book
2025-02-25 21:39

Of course, Microsoft is in the mix, isn't it Chinese spies reportedly broke into the US Republication National Committee's Microsoft-powered email and snooped around for months before being caught.…

MITRE Caldera security suite scores perfect 10 for insecurity
2025-02-25 20:47

Is a trivial remote-code execution hole in every version part of the training, or? The smart cookie who discovered a perfect 10-out-of-10-severity remote code execution (RCE) bug in MITRE's...

Firefox continues Manifest V2 support as Chrome disables MV2 ad-blockers
2025-02-25 20:28

Mozilla has renewed its promise to continue supporting Manifest V2 extensions alongside Manifest V3, giving users the freedom to use the extensions they want in their browser. [...]

Microsoft fixes Entra ID authentication issue caused by DNS change
2025-02-25 20:17

Microsoft has fixed an issue that caused Entra ID DNS authentication failures when using the company's Seamless SSO and Microsoft Entra Connect Sync. [...]

GitVenom attacks abuse hundreds of GitHub repos to steal crypto
2025-02-25 19:45

A malware campaign dubbed GitVenom uses hundreds of GitHub repositories to trick users into downloading info-stealers, remote access trojans (RATs), and clipboard hijackers to steal crypto and...

Windows 10 KB5052077 update fixes broken SSH connections
2025-02-25 19:24

​​Microsoft has released the optional KB5052077 preview cumulative update for Windows 10 22H2 with nine bug fixes and changes, including a fix for a longstanding known issue that breaks SSH...