Security News > 2025 > April

Securing the invisible: Supply chain security trends
2025-04-30 04:30

Adversaries are infiltrating upstream software, hardware, and vendor relationships to quietly compromise downstream targets. Whether it’s a malicious update injected into a CI/CD pipeline, a rogue...

Why cyber resilience must be part of every organization’s DNA
2025-04-30 04:00

As AI brings about excitement and transformative potential, the report reveals that organizations are forging ahead with innovations despite increased security concerns, according to LevelBlue’s...

Grinex exchange suspected rebrand of sanctioned Garantex crypto firm
2025-04-29 20:21

A new cryptocurrency exchange named Grinex is believed to be a rebrand of Garantex, a Russian cryptocurrency exchange whose domains were seized by the U.S. authorities and an admin arrested. [...]

Microsoft: Windows Server hotpatching to require subscription
2025-04-29 19:47

Microsoft has announced that it will soon introduce paid subscriptions for Windows Server 2025 hotpatching, a service that enables admins to install security updates without restarting. [...]

Hackers ramp up scans for leaked Git tokens and secrets
2025-04-29 19:02

Threat actors are intensifying internet-wide scanning for Git configuration files that can reveal sensitive secrets and authentication tokens used to compromise cloud services and source code...

France ties Russian APT28 hackers to 12 cyberattacks on French orgs
2025-04-29 18:57

Today, the French foreign ministry blamed the APT28 hacking group linked to Russia's military intelligence service (GRU) for targeting or breaching a dozen French entities over the last four years. [...]

Watch out for any Linux malware sneakily evading syscall-watching antivirus
2025-04-29 18:51

Google dumped io_uring after $1M in bug bounties A proof-of-concept program has been released to demonstrate a so-called monitoring "blind spot" in how some Linux antivirus and other endpoint...

44% of the zero-days exploited in 2024 were in enterprise solutions
2025-04-29 18:12

In 2024, threat actors exploited 75 zero-days – i.e., vulnerabilities previously unknown to vendors, thus without a readily available patch – in a wide variety of attacks. Of these, 33...

Apple 'AirBorne' flaws can lead to zero-click AirPlay RCE attacks
2025-04-29 17:32

​A set of security vulnerabilities in Apple's AirPlay Protocol and AirPlay Software Development Kit (SDK) exposed unpatched third-party and Apple devices to various attacks, including remote code...

WhatsApp Launches Private Processing to Enable AI Features While Protecting Message Privacy
2025-04-29 17:22

Popular messaging app WhatsApp on Tuesday unveiled a new technology called Private Processing to enable artificial intelligence (AI) capabilities in a privacy-preserving manner. "Private...