Security News > 2025 > March

EncryptHub linked to MMC zero-day attacks on Windows systems
2025-03-25 16:51

A threat actor known as EncryptHub has been linked to Windows zero-day attacks exploiting a Microsoft Management Console vulnerability patched this month. [...]

Review: The Developer’s Playbook for Large Language Model Security
2025-03-25 16:00

With the adoption of large language models (LLMs) across industries, security teams often play catch-up. Many organizations are integrating GenAI into customer interactions, software development,...

Browser-in-the-Browser attacks target CS2 players' Steam accounts
2025-03-25 15:52

A new phishing campaign targets Counter-Strike 2 players utilizing Browser-in-the-Browser (BitB) attacks that display a realistic window that mimics Steam's login page. [...]

Microsoft’s new AI agents take on phishing, patching, alert fatigue
2025-03-25 15:51

Microsoft is rolling out a new generation of AI agents in Security Copilot, built to help with some of the most time-consuming security challenges, such as phishing, data protection, and identity...

Europol Warns Criminal Networks Are Embracing AI, Making Fraud Smarter and Harder to Detect
2025-03-25 15:13

“The same qualities that make AI revolutionary – accessibility, adaptability and sophistication – also make it a powerful tool for criminal networks,” Europol says.

The vCISO Academy: Transforming MSPs and MSSPs into cybersecurity powerhouses
2025-03-25 14:00

By now, it’s no secret—cyber threats are on the rise, and the need for strong cybersecurity is greater than ever. Globally small and medium-sized businesses (SMBs) are prime targets for...

New Android malware uses Microsoft’s .NET MAUI to evade detection
2025-03-25 13:52

New Android malware campaigns use Microsoft's cross-platform framework .NET MAUI while disguising as legitimate services to evade detection. [...]

Researchers Uncover ~200 Unique C2 Domains Linked to Raspberry Robin Access Broker
2025-03-25 13:39

A new investigation has unearthed nearly 200 unique command-and-control (C2) domains associated with a malware called Raspberry Robin. "Raspberry Robin (also known as Roshtyak or Storm-0856) is a...

Infosec pro Troy Hunt HasBeenPwned in Mailchimp phish
2025-03-25 12:28

16,000 stolen records pertain to former and active mail subscribers Infosec veteran Troy Hunt of HaveIBeenPwned fame is notifying thousands of people after phishers scooped up his Mailchimp mailing list.…

Chinese Hackers Breach Asian Telecom, Remain Undetected for Over 4 Years
2025-03-25 11:54

A major telecommunications company located in Asia was allegedly breached by Chinese state-sponsored hackers who spent over four years inside its systems, according to a new report from incident...