Security News > 2025 > April

GCP Cloud Composer Bug Let Attackers Elevate Access via Malicious PyPI Packages
2025-04-22 14:06

Cybersecurity researchers have detailed a now-patched vulnerability in Google Cloud Platform (GCP) that could have enabled an attacker to elevate their privileges in the Cloud Composer workflow...

Perforce Puppet update accelerates vulnerability remediation
2025-04-22 13:59

Perforce Software announced its latest platform update for Puppet Enterprise Advanced, designed to streamline DevSecOps practices and fortify enterprise security postures. This release...

PoC exploit for critical Erlang/OTP SSH bug is public (CVE-2025-32433)
2025-04-22 12:06

There are now several public proof-of-concept (PoC) exploits for a maximum-severity vulnerability in the Erlang/OTP SSH server (CVE-2025-32433) unveiled last week. “All users running an SSH server...

5 Major Concerns With Employees Using The Browser
2025-04-22 11:00

As SaaS and cloud-native work reshape the enterprise, the web browser has emerged as the new endpoint. However, unlike endpoints, browsers remain mostly unmonitored, despite being responsible for...

Phishers Exploit Google Sites and DKIM Replay to Send Signed Emails, Steal Credentials
2025-04-22 10:50

In what has been described as an "extremely sophisticated phishing attack," threat actors have leveraged an uncommon approach that allowed bogus emails to be sent via Google's infrastructure and...

Microsoft Secures MSA Signing with Azure Confidential VMs Following Storm-0558 Breach
2025-04-22 07:38

Microsoft on Monday announced that it has moved the Microsoft Account (MSA) signing service to Azure confidential virtual machines (VMs) and that it's also in the process of migrating the Entra ID...

The legal blind spot of shadow IT
2025-04-22 06:00

Shadow IT isn’t just a security risk, it’s a legal one. When teams use unsanctioned tools, they can trigger compliance violations, expose sensitive data, or break contracts. Let’s look at where...

Email authentication simplified: How PowerDMARC makes DMARC effortless
2025-04-22 05:30

Email is still the top way attackers get into organizations. Now, big players like Google, Yahoo, and Microsoft are cracking down. They’re starting to require email authentication, specifically...

The C-suite gap that’s putting your company at risk
2025-04-22 05:00

New research from EY US shows that cyber attacks are creating serious financial risks. C-suite leaders don’t always agree on how exposed their companies are or where the biggest threats come from....

What school IT admins are up against, and how to help them win
2025-04-22 04:30

School IT admins are doing tough, important work under difficult conditions. From keeping Wi-Fi stable during exams to locking down systems from phishing emails, their job is part technician, part...