Security News > 2025 > April

Identifying the cyber risks that matter
2025-04-16 19:01

From noise to clarity: Why CISOs are shifting to adversarial exposure validation Partner content A vast majority of security teams are overwhelmed by the large number of security alerts and...

Apple fixes two zero-days exploited in targeted iPhone attacks
2025-04-16 18:06

Apple released emergency security updates to patch two zero-day vulnerabilities that were used in an "extremely sophisticated attack" against specific targets' iPhones. [...]

CVE program gets last-minute funding from CISA – and maybe a new home
2025-04-16 16:54

Feds extend vulnerability nerve-center contract at 11th hour In an 11th-hour reprieve, the US government last night agreed to continue funding the globally used Common Vulnerabilities and...

New Windows Task Scheduler Bugs Let Attackers Bypass UAC and Tamper with Logs
2025-04-16 16:18

Cybersecurity researchers have detailed four different vulnerabilities in a core component of the Windows task scheduling service that could be exploited by local attackers to achieve privilege...

CVE Program Almost Unfunded
2025-04-16 15:19

Mitre’s CVE’s program—which provides common naming and other informational resources about cybersecurity vulnerabilities—was about to be cancelled, as the US Department of Homeland Security failed...

Google begins unifying search country domains to Google.com
2025-04-16 14:47

Google has announced that it's retiring separate country code top-level domain names like google.co.uk or google.com.br and redirecting users to Google.com. [...]

Law firm 'didn't think' data theft was a breach, says ICO. Now it's nursing a £60K fine
2025-04-16 14:45

DPP Law is appealing against data watchdog's conclusions A law firm is appealing against a £60,000 fine from the UK's data watchdog after 32 GB of personal information was stolen from its systems.…

Jira Down: Atlassian users experiencing degraded performance
2025-04-16 14:38

Atlassian users are experiencing degraded performance amid an 'active incident' affecting multiple Jira products since morning hours today. Jira, Jira Service Management, Jira Work Management and...

41% of Attacks Bypass Defenses: Adversarial Exposure Validation Fixes That
2025-04-16 14:02

Your dashboards say you're secure—but 41% of threats still get through. Picus Security's Adversarial Exposure Validation uncovers what your stack is missing with continuous attack simulations and...

Cozy Bear targets EU diplomats with wine-tasting invites (again)
2025-04-16 13:33

APT29 (aka Cozy Bear, aka Midnight Blizzard) is, once again, targeting European diplomats with fake invitations to wine-tasting events, Check Point researchers have shared. Cozy Bear uses...

#EU