Security News > 2025 > April

Three Reasons Why the Browser is Best for Stopping Phishing Attacks
2025-04-23 11:00

Phishing attacks remain a huge challenge for organizations in 2025. In fact, with attackers increasingly leveraging identity-based techniques over software exploits, phishing arguably poses a...

Russian Hackers Exploit Microsoft OAuth to Target Ukraine Allies via Signal and WhatsApp
2025-04-23 10:49

Multiple suspected Russia-linked threat actors are "aggressively" targeting individuals and organizations with ties to Ukraine and human rights with an aim to gain unauthorized access to Microsoft...

Ex-NSA chief warns AI devs: Don’t repeat infosec’s early-day screwups
2025-04-23 10:34

Bake in security now or pay later, says Mike Rogers AI engineers should take a lesson from the early days of cybersecurity and bake safety and security into their models during development, rather...

Attackers phish OAuth codes, take over Microsoft 365 accounts
2025-04-23 10:23

Suspected Russian threat actors are using OAuth-based phishing attacks to get targets to grant them access to their Microsoft 365 (M365) accounts. “The primary tactics observed involve the...

America's cyber defenses are being dismantled from the inside
2025-04-23 08:27

The CVE system nearly dying shows that someone has lost the plot Opinion We almost lost the Common Vulnerabilities and Exposures (CVE) database system, but that's only the tip of the iceberg of...

Microsoft fixes Remote Desktop freezes caused by Windows updates
2025-04-23 07:59

​Microsoft has resolved a known issue causing Remote Desktop sessions to freeze on Windows Server 2025 and Windows 11 24H2 devices. [...]

Microsoft fixes Windows Server 2025 blue screen, install issues
2025-04-23 07:33

Microsoft has fixed several known issues that caused Blue Screen of Death (BSOD) and installation issues on Windows Server 2025 systems with a high core count. [...]

Ripple's xrpl.js npm Package Backdoored to Steal Private Keys in Major Supply Chain Attack
2025-04-23 07:17

The Ripple cryptocurrency npm JavaScript library named xrpl.js has been compromised by unknown threat actors as part of a software supply chain attack designed to harvest and exfiltrate users'...

When confusion becomes a weapon: How cybercriminals exploit economic turmoil
2025-04-23 06:00

It begins with a simple notification: “Markets in Free Fall.” Within moments, the headlines multiply: new tariffs, emergency actions, plummeting consumer confidence. Across boardrooms and break...

SWE-agent: Open-source tool uses LLMs to fix issues in GitHub repositories
2025-04-23 05:30

By connecting powerful language models like GPT-4o and Claude Sonnet 3.5 to real-world tools, the open-source tool SWE-agent allows them to autonomously perform complex tasks: from fixing bugs in...