Security News > 2025 > April

Ex-NSA cyber-boss: AI will soon be a great exploit coder
2025-04-30 23:31

For now it's a potential bug-finder and friend to defenders RSAC Former NSA cyber-boss Rob Joyce thinks today's artificial intelligence is dangerously close to becoming a top-tier vulnerability...

WordPress plugin disguised as a security tool injects backdoor
2025-04-30 21:05

A new malware campaign targeting WordPress sites employs a malicious plugin disguised as a security tool to trick users into installing and trusting it. [...]

WhatsApp unveils 'Private Processing' for cloud-based AI features
2025-04-30 19:01

WhatsApp has announced the introduction of 'Private Processing,' a new technology that enables users to utilize advanced AI features by offloading tasks to privacy-preserving cloud servers. [...]

Ex-CISA chief decries cuts as Trump demands loyalty above all else
2025-04-30 18:58

Cybersecurity is national security, says Jen Easterly RSAC America's top cyber-defense agency is "being undermined" by personnel and budget cuts under the Trump administration, some of which are...

Maryland man pleads guilty to outsourcing US govt work to North Korean dev in China
2025-04-30 18:03

Feds say $970K scheme defrauded 13+ companies A Maryland man has pleaded guilty to fraud after landing a job with a contractor working on US government software, and then outsourcing the work to a...

SonicWall warns of more VPN flaws exploited in attacks
2025-04-30 17:23

Cybersecurity company SonicWall has warned customers that several vulnerabilities impacting its Secure Mobile Access (SMA) appliances are now being actively exploited in attacks. [...]

Commvault says recent breach didn't impact customer backup data
2025-04-30 16:20

Commvault, a leading provider of data protection solutions, says a nation-state threat actor who breached its Azure environment didn't gain access to customer backup data. [...]

FBI shares massive list of 42,000 LabHost phishing domains
2025-04-30 16:01

The FBI has shared 42,000 phishing domains tied to the LabHost cybercrime platform, one of the largest global phishing-as-a-service (PhaaS) platforms that was dismantled in April 2024. [...]

Researchers Demonstrate How MCP Prompt Injection Can Be Used for Both Attack and Defense
2025-04-30 15:59

As the field of artificial intelligence (AI) continues to evolve at a rapid pace, new research has found how techniques that render the Model Context Protocol (MCP) susceptible to prompt injection...

FBI steps in amid rash of politically charged swattings
2025-04-30 15:10

No specific law against it yet, but that's set to change A spate of high-profile swatting incidents in the US recently forced the FBI into action with its latest awareness campaign about the...