Security News > 2025 > April

Microsoft now pays up to $30,000 for some AI vulnerabilities
2025-04-24 15:06

Microsoft announced an increase in bug bounty payouts to $30,000 for AI vulnerabilities found in Dynamics 365 and Power Platform services and products. [...]

Interlock ransomware claims DaVita attack, leaks stolen data
2025-04-24 14:59

The Interlock ransomware gang has claimed the cyberattack on DaVita kidney dialysis firm and leaked data allegedly stolen from the organization. [...]

Yale New Haven Health data breach affects 5.5 million patients
2025-04-24 14:12

Yale New Haven Health (YNHHS) is warning that threat actors stole the personal data of 5.5 million patients in a cyberattack earlier this month. [...]

Lazarus Hits 6 South Korean Firms via Cross EX, Innorix Flaws and ThreatNeedle Malware
2025-04-24 14:11

At least six organizations in South Korea have been targeted by the prolific North Korea-linked Lazarus Group as part of a campaign dubbed Operation SyncHole. The activity targeted South Korea's...

Microsoft fixes bug causing incorrect 0x80070643 WinRE errors
2025-04-24 13:54

Microsoft says it resolved a known issue causing erroneous 0x80070643 installation failure errors when deploying the April 2025 Windows Recovery Environment (WinRE) updates. [...]

159 CVEs Exploited in Q1 2025 — 28.3% Within 24 Hours of Disclosure
2025-04-24 12:58

As many as 159 CVE identifiers have been flagged as exploited in the wild in the first quarter of 2025, up from 151 in Q4 2024. "We continue to see vulnerabilities being exploited at a fast pace...

Linux io_uring PoC Rootkit Bypasses System Call-Based Threat Detection Tools
2025-04-24 12:58

Cybersecurity researchers have demonstrated a proof-of-concept (PoC) rootkit dubbed Curing that leverages a Linux asynchronous I/O mechanism called io_uring to bypass traditional system call...

Automating Zero Trust in Healthcare: From Risk Scoring to Dynamic Policy Enforcement Without Network Redesign
2025-04-24 12:56

The Evolving Healthcare Cybersecurity Landscape  Healthcare organizations face unprecedented cybersecurity challenges in 2025. With operational technology (OT) environments increasingly targeted...

Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028)
2025-04-24 12:05

If your organization is using Commvault Command Center for your data protection, backup creation, configuration and restoration needs, you should check whether your on-premise installation has...

Linux 'io_uring' security blindspot allows stealthy rootkit attacks
2025-04-24 12:00

A significant security gap in Linux runtime security caused by the 'io_uring' interface allows rootkits to operate undetected on systems while bypassing advanced Enterprise security software. [...]