Security News > 2025 > April

Tycoon2FA phishing kit targets Microsoft 365 with new tricks
2025-04-12 15:16

Phishing-as-a-service (PhaaS) platform Tycoon2FA, known for bypassing multi-factor authentication on Microsoft 365 and Gmail accounts, has received updates that improve its stealth and evasion...

AI-hallucinated code dependencies become new supply chain risk
2025-04-12 14:19

A new class of supply chain attacks named 'slopsquatting' has emerged from the increased use of generative AI tools for coding and the model's tendency to "hallucinate" non-existent package names. [...]

LLMs can't stop making up software dependencies and sabotaging everything
2025-04-12 11:14

Hallucinated package names fuel 'slopsquatting' The rise of LLM-powered code generation tools is reshaping how developers write software - and introducing new risks to the software supply chain in...

Microsoft total recalls Recall totally to Copilot+ PCs
2025-04-11 23:13

Redmond hopes you’ve forgotten or got over why everyone hated it the first time After temporarily shelving its controversial Windows Recall feature amid a wave of backlash, Microsoft is back at it...

Microsoft Defender will isolate undiscovered endpoints to block attacks
2025-04-11 19:13

Microsoft is testing a new Defender for Endpoint capability that will block traffic to and from undiscovered endpoints to thwart attackers' lateral network movement attempts. [...]

Fortinet Warns Attackers Retain FortiGate Access Post-Patching via SSL-VPN Symlink Exploit
2025-04-11 17:55

Fortinet has revealed that threat actors have found a way to maintain read-only access to vulnerable FortiGate devices even after the initial access vector used to breach the devices was patched....

Hackers exploit old FortiGate vulnerabilities, use symlink trick to retain limited access to patched devices
2025-04-11 17:46

A threat actor that has been using known old FortiOS vulnerabilities to breach FortiGate devices for years has also been leveraging a clever trick to maintain undetected read-only access to them...

Microsoft starts final Windows Recall testing before rollout
2025-04-11 17:13

​Microsoft is gradually rolling out the AI-powered Windows Recall feature to Insiders in the Release Preview channel before making it generally available to all Windows users with Copilot+ PCs. [...]

Western Sydney University discloses security breaches, data leak
2025-04-11 16:29

Western Sydney University (WSU) announced two security incidents that exposed personal information belonging to members of its community. [...]

Fortinet: Hackers retain access to patched FortiGate VPNs using symlinks
2025-04-11 16:08

Fortinet warns that threat actors use a post-exploitation technique that helps them maintain read-only access to previously compromised FortiGate VPN devices even after the original attack vector...