Security News > 2025 > March

CrushFTP CEO's feisty response to VulnCheck's CVE for critical make-me-admin bug
2025-03-27 13:20

Screenshot shows company head unhappy, claiming 'real CVE is pending' CrushFTP's CEO is not happy with VulnCheck after the CVE numbering authority (CNA) released an unofficial ID for the critical...

APT36 Spoofs India Post Website to Infect Windows and Android Users with Malware
2025-03-27 12:31

An advanced persistent threat (APT) group with ties to Pakistan has been attributed to the creation of a fake website masquerading as India's public sector postal system as part of a campaign...

Dozens of solar inverter flaws could be exploited to attack power grids
2025-03-27 12:00

Dozens of vulnerabilities in products from three leading makers of solar inverters, Sungrow, Growatt, and SMA, could be exploited to control devices or execute code remotely on the vendor's cloud...

New Report Explains Why CASB Solutions Fail to Address Shadow SaaS and How to Fix It
2025-03-27 11:25

Whether it’s CRMs, project management tools, payment processors, or lead management tools - your workforce is using SaaS applications by the pound. Organizations often rely on traditional CASB...

CrushFTP: Patch critical vulnerability ASAP! (CVE-2025-2825)
2025-03-27 11:12

CrushFTP has fixed a critical vulnerability (CVE-2025-2825) in its enterprise file transfer solution that could be exploited by remote, unauthenticated attackers to access vulnerable...

A Taxonomy of Adversarial Machine Learning Attacks and Mitigations
2025-03-27 11:00

NIST just released a comprehensive taxonomy of adversarial machine learning attacks and countermeasures.

UK's first permanent facial recognition cameras installed in South London
2025-03-27 10:27

As if living in Croydon wasn't bad enough The Metropolitan Police has confirmed its first permanent installation of live facial recognition (LFR) cameras is coming this summer and the lucky...

Top 3 MS Office Exploits Hackers Use in 2025 – Stay Alert!
2025-03-27 10:00

Hackers have long used Word and Excel documents as delivery vehicles for malware, and in 2025, these tricks are far from outdated. From phishing schemes to zero-click exploits, malicious Office...

Ransomwared NHS software supplier nabs £3M discount from ICO for good behavior
2025-03-27 09:30

Data stolen included checklist for medics on how to get into vulnerable people's homes The UK's data protection watchdog is dishing out a £3.07 million ($3.95 million) fine to Advanced Computer...

Which Top Cybersecurity Role of 2024 Was Featured in 64,000+ Job Postings?
2025-03-27 08:22

IT and security workforce management firm CyberSN surveyed job listings from 2022 to 2024. Yes, decreases in demand for some job titles may be related to AI.