Security News > 2025 > March

New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint
2025-03-03 17:33

A newly uncovered ClickFix phishing campaign is tricking victims into executing malicious PowerShell commands that deploy the Havok post-exploitation framework for remote access to compromised...

Hackers Exploit AWS Misconfigurations to Launch Phishing Attacks via SES and WorkMail
2025-03-03 17:26

Threat actors are targeting Amazon Web Services (AWS) environments to push out phishing campaigns to unsuspecting targets, according to findings from Palo Alto Networks Unit 42. The cybersecurity...

Online crime-as-a-service skyrockets with 24,000 users selling attack tools
2025-03-03 17:00

The growth of AI-based technology has introduced new challenges, making remote identity verification systems more vulnerable to attacks, according to iProov. Innovative and easily accessible tools...

UK watchdog probes TikTok and Reddit over child privacy concerns
2025-03-03 16:22

On Monday, the United Kingdom's privacy watchdog announced that it is investigating TikTok, Reddit, and Imgur because of privacy concerns about how they are processing children's data. [...]

Cybersecurity not the hiring-'em-like-hotcakes role it once was
2025-03-03 16:10

Ghost positions, HR AI no help – biz should talk to infosec staff and create 'realistic' job outline, say experts Analysis It's a familiar refrain in the security industry that there is a massive...

Innovation vs. security: Managing shadow AI risks
2025-03-03 16:00

In this Help Net Security video, Tim Morris, Chief Security Advisor at Tanium, shares practical best practices to help organizations balance innovation and security while leveraging AI. Morris...

Microsoft links recent Microsoft 365 outage to buggy update
2025-03-03 14:37

​Microsoft says a coding issue is behind a now-resolved Microsoft 365 outage over the weekend that affected Outlook and Exchange Online authentication. [...]

Hackers Use ClickFix Trick to Deploy PowerShell-Based Havoc C2 via SharePoint Sites
2025-03-03 14:00

Cybersecurity researchers are calling attention to a new phishing campaign that employs the ClickFix technique to deliver an open-source command-and-control (C2) framework called Havoc. "The...

U.K. ICO Investigates TikTok, Reddit, and Imgur Over Children's Data Protection Practices
2025-03-03 13:56

The U.K.'s Information Commissioner's Office (ICO) has opened an investigation into online platforms TikTok, Reddit, and Imgur to assess the steps they are taking to protect children between the...

Hackers Exploit Paragon Partition Manager Driver Vulnerability in Ransomware Attacks
2025-03-03 13:56

Threat actors have been exploiting a security vulnerability in Paragon Partition Manager's BioNTdrv.sys driver in ransomware attacks to escalate privileges and execute arbitrary code. The zero-day...