Security News > 2025 > April

Widely available AI tools signal new era of malicious bot activity
2025-04-18 04:30

Rise in accessible AI tools significantly lowered the barrier to entry for cyber attackers, enabling them to create and deploy malicious bots at scale, according to Thales. Automated bot traffic...

CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File Download
2025-04-18 04:29

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a medium-severity security flaw impacting Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog,...

Critical Erlang/OTP SSH pre-auth RCE is 'Surprisingly Easy' to exploit, patch now
2025-04-17 21:34

A critical vulnerability in the Erlang/OTP SSH, tracked as CVE-2025-32433, has been disclosed that allows for unauthenticated remote code execution on vulnerable devices. [...]

Entertainment services giant Legends International discloses data breach
2025-04-17 20:51

Entertainment venue management firm Legends International warns it suffered a data breach in November 2024, which has impacted employees and people who visited venues under its management. [...]

Windows NTLM hash leak flaw exploited in phishing attacks on governments
2025-04-17 19:20

A Windows vulnerability that exposes NTLM hashes using .library-ms files is now actively exploited by hackers in phishing campaigns targeting government entities and private companies. [...]

Krebs throws himself on the grenade, resigns from SentinelOne after Trump revokes clearances
2025-04-17 18:56

Illegitimi non carborundum? Nice password, Mr Ex-CISA Chris Krebs, the former head of the US Cybersecurity and Infrastructure Security Agency (CISA) and a longtime Trump target, has resigned from...

‘No AI Agents are Allowed.’ EU Bans Use of AI Assistants in Virtual Meetings
2025-04-17 17:30

In a presentation delivered this month by the European Commission, a meeting etiquette slide stated “No AI Agents are allowed.”

Chrome extensions with 6 million installs have hidden tracking code
2025-04-17 16:50

A set of 57 Chrome extensions with 6,000,000 users have been discovered with very risky capabilities, such as monitoring browsing behavior, accessing cookies for domains, and potentially executing...

Age Verification Using Facial Scans
2025-04-17 16:38

Discord is testing the feature: “We’re currently running tests in select regions to age-gate access to certain spaces or user settings,” a spokesperson for Discord said in a statement. “The...

Apple Patches Two Zero-Days Used in ‘Extremely Sophisticated’ Attacks
2025-04-17 15:54

Find out the specifics of these iOS and macOS vulnerabilities, as well as which Apple devices were impacted.