Security News > 2025 > April

Majority of Browser Extensions Can Access Sensitive Enterprise Data, New Report Finds
2025-04-15 13:25

Everybody knows browser extensions are embedded into nearly every user’s daily workflow, from spell checkers to GenAI tools. What most IT and security people don’t know is that browser extensions’...

Malicious PyPI Package Targets MEXC Trading API to Steal Credentials and Redirect Orders
2025-04-15 13:20

Cybersecurity researchers have disclosed a malicious package uploaded to the Python Package Index (PyPI) repository that's designed to reroute trading orders placed on the MEXC cryptocurrency...

ActiveX blocked by default in Microsoft 365 because remote code execution is bad, OK?
2025-04-15 12:25

Stopping users shooting themselves in the foot with last century's tech Microsoft has twisted the knife into ActiveX once again, setting Microsoft 365 to disable all controls without so much as a prompt.…

Where it Hertz: Customer data driven off in Cleo attacks
2025-04-15 11:31

Car hire biz takes your privacy seriously, though Car hire giant Hertz has confirmed that customer information was stolen during the zero-day data raids on Cleo file transfer products last year.…

Critical flaws fixed in Nagios Log Server
2025-04-15 10:41

The Nagios Security Team has fixed three critical vulnerabilities affecting popular enterprise log management and analysis platform Nagios Log Server. About the flaws The vulnerabilities,...

Crypto Developers Targeted by Python Malware Disguised as Coding Challenges
2025-04-15 09:10

The North Korea-linked threat actor assessed to be behind the massive Bybit hack in February 2025 has been linked to a malicious campaign that targets developers to deliver new stealer malware...

EU gives staff 'burner phones, laptops' for US visits
2025-04-15 07:36

That would put America on the same level as China for espionage The European Commission is giving staffers visiting the US on official business burner laptops and phones to avoid espionage...

Why shorter SSL/TLS certificate lifespans matter
2025-04-15 06:00

Digital certificates are the unsung heroes of the internet, silently verifying that the websites, apps, and services you use are legit and your data is safe. For years, we’ve leaned on...

Cybercriminal groups embrace corporate structures to scale, sustain operations
2025-04-15 05:30

In this Help Net Security interview, Sandy Kronenberg, CEO of Netarx, discusses how cybercriminal groups are adopting corporate structures and employee incentives to scale operations, retain...

94% of firms say pentesting is essential, but few are doing it right
2025-04-15 05:00

Organizations are fixing less than half of all exploitable vulnerabilities, with just 21% of GenAI app flaws being resolved, according to Cobalt. Big firms take longer to fix pentest issues 94% of...