Security News > 2025 > April

Week in review: LLM package hallucinations harm supply chains, Nagios Log Server flaws fixed
2025-04-20 08:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Apple plugs zero-day holes used in targeted iPhone attacks (CVE-2025-31200, CVE-2025-31201) Apple...

APT29 Deploys GRAPELOADER Malware Targeting European Diplomats Through Wine-Tasting Lures
2025-04-20 04:58

The Russian state-sponsored threat actor known as APT29 has been linked to an advanced phishing campaign that's targeting diplomatic entities across Europe with a new variant of WINELOADER and a...

Widespread Microsoft Entra lockouts tied to new security feature rollout
2025-04-19 22:04

Windows administrators from numerous organizations report widespread account lockouts triggered by false positives in the rollout of a new Microsoft Entra ID's "leaked credentials" detection app...

New Android malware steals your credit cards for NFC relay attacks
2025-04-19 15:17

A new malware-as-a-service (MaaS) platform named 'SuperCard X' has emerged, targeting Android devices via NFC relay attacks that enable point-of-sale and ATM transactions using compromised payment...

Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux Systems
2025-04-19 15:11

Cybersecurity researchers have uncovered three malicious packages in the npm registry that masquerade as a popular Telegram bot library but harbor SSH backdoors and data exfiltration capabilities....

Critical Erlang/OTP SSH RCE bug now has public exploits, patch now
2025-04-19 14:05

Public exploits are now available for a critical Erlang/OTP SSH vulnerability tracked as CVE-2025-32433, allowing unauthenticated attackers to remotely execute code on impacted devices. [...]

Hacking US crosswalks to talk like Zuck is as easy as 1234
2025-04-19 13:03

AI-spoofed Mark joins fellow billionaires as the voice of the street – here's how it was probably done Video Crosswalk buttons in various US cities were hijacked over the past week or so to –...

Google Gemini AI is getting ChatGPT-like Scheduled Actions feature
2025-04-19 12:01

Google Gemini is testing a ChatGPT-like scheduled tasks feature called "Scheduled Actions," which will allow you to create tasks that Gemini will execute later. [...]

ASUS Confirms Critical Flaw in AiCloud Routers; Users Urged to Update Firmware
2025-04-19 08:52

ASUS has disclosed a critical security flaw impacting routers with AiCloud enabled that could permit remote attackers to perform unauthorized execution of functions on susceptible devices. The...

Friday Squid Blogging: Live Colossal Squid Filmed
2025-04-18 21:02

A live colossal squid was filmed for the first time in the ocean. It’s only a juvenile: a foot long. As usual, you can also use this squid post to talk about the security stories in the news that...