Security News > 2025 > April

Hackers abuse OAuth 2.0 workflows to hijack Microsoft 365 accounts
2025-04-24 20:24

Russian threat actors have been abusing legitimate OAuth 2.0 authentication workflows to hijack Microsoft 365 accounts of employees of organizations related to Ukraine and human rights. [...]

New Linux Rootkit
2025-04-24 19:35

Interesting: The company has released a working rootkit called “Curing” that uses io_uring, a feature built into the Linux kernel, to stealthily perform malicious activities without being caught...

Lazarus hackers breach six companies in watering hole attacks
2025-04-24 19:13

In a recent espionage campaign, the infamous North Korean threat group Lazarus targeted multiple organizations in the software, IT, finance, and telecommunications sectors in South Korea. [...]

Microsoft fixes machine learning bug flagging Adobe emails as spam
2025-04-24 19:02

Microsoft says it mitigated a known issue in one of its machine learning (ML) models that mistakenly flagged Adobe emails in Exchange Online as spam. [...]

Microsoft mystery folder fix might need a fix of its own
2025-04-24 18:01

This one weird trick can stop Windows updates dead in their tracks Turns out Microsoft's latest patch job might need a patch of its own, again. This time, the culprit is a mysterious inetpub...

Frederick Health data breach impacts nearly 1 million patients
2025-04-24 16:19

​A ransomware attack in January at Frederick Health Medical Group, a major healthcare provider in Maryland, has led to a data breach affecting nearly one million patients. [...]

Assassin's Creed maker faces GDPR complaint for forcing single-player gamers online
2025-04-24 15:59

Collecting data from solo players is a Far Cry from being necessary, says noyb For anyone who's ever been frustrated by the need to go online to play a single-player video game, the European...

Microsoft now pays up to $30,000 for some AI vulnerabilities
2025-04-24 15:06

Microsoft announced an increase in bug bounty payouts to $30,000 for AI vulnerabilities found in Dynamics 365 and Power Platform services and products. [...]

Interlock ransomware claims DaVita attack, leaks stolen data
2025-04-24 14:59

The Interlock ransomware gang has claimed the cyberattack on DaVita kidney dialysis firm and leaked data allegedly stolen from the organization. [...]

Yale New Haven Health data breach affects 5.5 million patients
2025-04-24 14:12

Yale New Haven Health (YNHHS) is warning that threat actors stole the personal data of 5.5 million patients in a cyberattack earlier this month. [...]