Security News > 2025 > April

Microsoft blocks ActiveX by default in Microsoft 365, Office 2024
2025-04-15 16:57

Microsoft announced it will begin disabling all ActiveX controls in Windows versions of Microsoft 365 and Office 2024 applications later this month. [...]

UK’s Cyber Crime Down in 2024: Better ‘Cyber Hygiene Among Small Businesses
2025-04-15 16:41

A UK government survey of 2024 data shows phishing remains the top cyber threat, ransomware cases doubled, and fewer boards include cyber experts despite steady attack rates.

Slopsquatting
2025-04-15 16:02

As AI coding assistants invent nonexistent software libraries to download and use, enterprising attackers create and upload libraries with those names—laced with malware, of course.

Microsoft: Exchange 2016 and 2019 reach end of support in six months
2025-04-15 15:07

​Microsoft warned that Exchange 2016 and Exchange 2019 will reach the end of support six months from now, on October 14. [...]

Hertz data breach: Customers in US, EU, UK, Australia and Canada affected
2025-04-15 14:21

American car rental company Hertz has suffered a data breach linked to last year’s exploitation of Cleo zero-day vulnerabilities by a ransomware gang. The breach resulted in information of an...

Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool
2025-04-15 14:06

The China-linked threat actor known as UNC5174 has been attributed to a new campaign that leverages a variant of a known malware dubbed SNOWLIGHT and a new open-source tool called VShell to infect...

Chinese snoops use stealth RAT to backdoor US orgs – still active last week
2025-04-15 14:00

Let the espionage and access resale campaigns begin (again) A cyberspy crew or individual with ties to China's Ministry of State Security has infected global organizations with a remote access...

Google adds Android auto-reboot to block forensic data extractions
2025-04-15 13:54

Google is rolling out a new security mechanism on Android devices that will automatically reboot locked, unused devices after three consecutive days of inactivity, restoring memory to an encrypted...

Critical Apache Roller Vulnerability (CVSS 10.0) Enables Unauthorized Session Persistence
2025-04-15 13:44

A critical security vulnerability has been disclosed in the Apache Roller open-source, Java-based blogging server software that could allow malicious actors to retain unauthorized access even...

Microsoft warns of CPU spikes when typing in classic Outlook
2025-04-15 13:41

Microsoft warned Windows users of increased CPU usage when typing while using recent versions of the classic Outlook email client. [...]