Security News > 2025 > March

China-linked FamousSparrow APT group resurfaces with enhanced capabilities
2025-03-26 15:00

ESET investigated suspicious activity on the network of a trade group in the United States that operates in the financial sector. While helping the affected entity remediate the compromise, they...

Microsoft fixes printing issues caused by January Windows updates
2025-03-26 14:30

Microsoft has fixed a known issue causing some USB printers to start printing random text after installing Windows updates released since late January 2025. [...]

If you think you’re immune to phishing attempts, you’re wrong!
2025-03-26 14:11

Security consultant Troy Hunt, the creator of the Have I Been Pwned (HIBP) service, has revealed that he got tricked by a clever phishing email, and that the attacker gained access to his...

RedCurl cyberspies create ransomware to encrypt Hyper-V servers
2025-03-26 14:06

A threat actor named 'RedCurl,' known for stealthy corporate espionage operations since 2018, is now using a ransomware encryptor designed to target Hyper-V virtual machines. [...]

Whitepaper: Voice of Security 2025
2025-03-26 14:00

Discover insights from 900 security leaders across the globe in IDC’s Voice of Security 2025 survey, sponsored by Tines in partnership with AWS. Understand the biggest challenges facing security...

EncryptHub Exploits Windows Zero-Day to Deploy Rhadamanthys and StealC Malware
2025-03-26 13:53

The threat actor known as EncryptHub exploited a recently-patched security vulnerability in Microsoft Windows as a zero-day to deliver a wide range of malware families, including backdoors and...

RedCurl Shifts from Espionage to Ransomware with First-Ever QWCrypt Deployment
2025-03-26 13:43

The Russian-speaking hacking group called RedCurl has been linked to a ransomware campaign for the first time, marking a departure in the threat actor's tradecraft. The activity, observed by...

Microsoft: Recent Windows updates cause Remote Desktop issues
2025-03-26 12:19

Microsoft says that some customers might experience Remote Desktop and RDS connection issues after installing recent Windows updates released since January 2025. [...]

Malicious npm Package Modifies Local 'ethers' Library to Launch Reverse Shell Attacks
2025-03-26 12:00

Cybersecurity researchers have discovered two malicious packages on the npm registry that are designed to infect another locally installed package, underscoring the continued evolution of software...

New npm attack poisons local packages with backdoors
2025-03-26 12:00

Two malicious packages were discovered on npm (Node package manager) that covertly patch legitimate, locally installed packages to inject a persistent reverse shell backdoor. [...]