Security News > 2025 > April

Claims assistance firm fined for cold-calling people who put themselves on opt-out list
2025-04-25 09:29

Third-party data supplier also in hot water with Brit regulator over consent issues Britain's data privacy watchdog has slapped a fine of £90k ($120k) on a business that targeted people with...

Rack Ruby vulnerability could reveal secrets to attackers (CVE-2025-27610)
2025-04-25 09:26

Researchers have uncovered three serious vulnerabilities in Rack, a server interface used by most Ruby web app frameworks (Ruby on Rails, Sinatra, Hanami, Roda, and others). Two of the flaws –...

Researchers Identify Rack::Static Vulnerability Enabling Data Breaches in Ruby Servers
2025-04-25 08:57

Cybersecurity researchers have disclosed three security flaws in the Rack Ruby web server interface that, if successfully exploited, could enable attackers to gain unauthorized access to files,...

DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025-0282 in Japan Attacks
2025-04-25 08:43

Cybersecurity researchers are warning about a new malware called DslogdRAT that's installed following the exploitation of a now-patched security flaw in Ivanti Connect Secure (ICS). The malware,...

Microsoft announces fix for CPU spikes when typing in Outlook
2025-04-25 08:10

Microsoft says it will soon fix a known issue causing CPU spikes when typing messages in recent versions of its classic Outlook email client. [...]

Darcula adds AI to its DIY phishing kits to help would-be vampires bleed victims dry
2025-04-25 06:18

Because coding phishing sites from scratch is a real pain in the neck Darcula, a cybercrime outfit that offers a phishing-as-a-service kit to other criminals, this week added AI capabilities to...

Flexible working models fuel surge in device theft
2025-04-25 05:30

76% of respondents have been impacted by incidents of device theft in the past two years, with incidents more common in organizations with more flexible working models, according to Kensington....

Exposure validation emerges as critical cyber defense component
2025-04-25 05:00

Organizations have implemented various aspects of threat exposure validation, including security control validation (51%) and filtering threat exposures based on the effectiveness of security...

13 core principles to strengthen AI cybersecurity
2025-04-25 04:45

The new ETSI TS 104 223 specification for securing AI provides reliable and actionable cybersecurity guidance aimed at protecting end users. Adopting a whole-lifecycle approach, the framework...

Top must-visit companies at RSAC 2025
2025-04-25 04:30

RSAC 2025 Conference is taking place at the Moscone Center in San Francisco from April 28 – May 1. With hundreds of booths, countless product demos, and nonstop buzz, navigating RSAC can be...