Security News > 2025 > March

Phishing-as-a-service operation uses DNS-over-HTTPS for evasion
2025-03-28 16:33

A newly discovered phishing-as-a-service (PhaaS) operation that researchers call Morphing Meerkat, has been using the DNS over HTTPS (DoH) protocol to evade detection. [...]

Microsoft fixes button that restores classic Outlook client
2025-03-28 16:14

Microsoft resolved an issue that caused the new Outlook email client to crash when users clicked a button designed to switch back to classic Outlook. [...]

New Ubuntu Linux security bypasses require manual mitigations
2025-03-28 15:14

Three security bypasses have been discovered in Ubuntu Linux's unprivileged user namespace restrictions, which could be enable a local attacker to exploit vulnerabilities in kernel components. [...]

Oracle Health breach compromises patient data at US hospitals
2025-03-28 14:13

A breach at Oracle Health impacts multiple US healthcare organizations and hospitals after a threat actor stole patient data from legacy servers. [...]

Researchers Uncover 46 Critical Flaws in Solar Power Systems From Sungrow, Growatt, and SMA
2025-03-28 13:21

Cybersecurity researchers have disclosed 46 new security flaws in products from three solar power system vendors, Sungrow, Growatt, and SMA, that could be exploited by a bad actor to seize control...

Cardiff's children's chief confirms data leak 2 months after cyber risk was 'escalated'
2025-03-28 12:28

Department director admits Welsh capital's council still trying to get heads around threat of dark web leaks Cardiff City Council's director of children's services says data was leaked or stolen...

CoffeeLoader Uses GPU-Based Armoury Packer to Evade EDR and Antivirus Detection
2025-03-28 11:57

Cybersecurity researchers are calling attention to a new sophisticated malware called CoffeeLoader that's designed to download and execute secondary payloads. The malware, according to Zscaler...

Microsoft fixes Remote Desktop issues caused by Windows updates
2025-03-28 11:41

Microsoft has fixed a known issue that caused problems with Remote Desktop and RDS connections after installing Windows updates released since January 2025. [...]

Cloudflare open sources OPKSSH to bring Single Sign-On to SSH
2025-03-28 11:29

OPKSSH (OpenPubkey SSH) makes it easy to authenticate to servers over SSH using OpenID Connect (OIDC), allowing developers to ditch manually configured SSH keys in favor of identity provider-based...

AIs as Trusted Third Parties
2025-03-28 11:01

This is a truly fascinating paper: “Trusted Machine Learning Models Unlock Private Inference for Problems Currently Infeasible with Cryptography.” The basic idea is that AIs can act as trusted...

#AI