Security News > 2025 > March

Malwoverview: First response tool for threat hunting
2025-03-26 05:30

Malwoverview is an open-source threat hunting tool designed for the initial triage of malware samples, URLs, IP addresses, domains, malware families, IOCs, and hashes. “Malwoverview is simple and...

How does your data end up on the dark web?
2025-03-26 05:00

The dark web is a hidden corner of the internet where people can remain anonymous. It’s often confused with the deep web, but they’re not quite the same thing. The deep web is just everything...

New Security Flaws Found in VMware Tools and CrushFTP — High Risk, PoC Released
2025-03-26 04:20

Broadcom has issued security patches to address a high-severity security flaw in VMware Tools for Windows that could lead to an authentication bypass. Tracked as CVE-2025-22230, the vulnerability...

After Detecting 30B Phishing Attempts, Microsoft Adds Even More AI to Its Security Copilot
2025-03-25 21:04

Microsoft is partnering with top firms to launch new AI security tools, boosting breach analysis, threat detection, and AI model protection across cloud platforms.

CrushFTP warns users to patch unauthenticated access flaw immediately
2025-03-25 20:11

CrushFTP warned customers of an unauthenticated HTTP(S) port access vulnerability and urged them to patch their servers immediately. [...]

Cloudflare R2 service outage caused by password rotation error
2025-03-25 19:47

Cloudflare has announced that its R2 object storage and dependent services experienced an outage lasting 1 hour and 7 minutes, causing 100% write and 35% read failures globally. [...]

Broadcom warns of authentication bypass in VMware Windows Tools
2025-03-25 19:17

Broadcom released security updates today to fix a high-severity authentication bypass vulnerability in VMware Tools for Windows. [...]

New Windows zero-day leaks NTLM hashes, gets unofficial patch
2025-03-25 18:22

Free unofficial patches are available for a new Windows zero-day vulnerability that can let remote attackers steal NTLM credentials by tricking targets into viewing malicious files in Windows...

There are 10,000 reasons to doubt Oracle Cloud's security breach denial
2025-03-25 17:35

Customers come forward claiming info was swiped from prod Oracle Cloud's denial of a digital break-in is now in clear dispute. A infosec researcher working on validating claims that the cloud...

Ingress-nginx vulnerabilities can lead to Kubernetes cluster takeover
2025-03-25 16:53

Wiz researchers have unearthed several critical vulnerabilities affecting Ingress NGINX Controller for Kubernetes (ingress-nginx) that may allow attackers to take over Kubernetes clusters. “Based...